# Logstash not getting rolled over

**URL:** <https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022>\
**Category:** Elasticsearch\
**Created:** [February 11, 2022, 7:43pm UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022 "2022-02-11T19:43:36Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jwilfreds](https://avatars.discourse-cdn.com/v4/letter/j/ea5d25/32.png) [@jwilfreds](https://discuss.elastic.co/u/jwilfreds)\
**Post date:** [February 11, 2022, 7:43pm UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022/1 "2022-02-11T19:43:36Z")

</div>

The logstash file is not getting rolled over. the setup was set for 5 MB and the lifecyle policy added to it. But it grew to 100 GB. No one noticed it until we started getting the server utilization alerts. How do I create a new index ? can i stop the logstash file and delete it ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 11, 2022, 9:40pm UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022/2 "2022-02-11T21:40:39Z")

</div>

By file you do you mean index?

---

<div class="post-metadata">

**Author:** ![jwilfreds](https://avatars.discourse-cdn.com/v4/letter/j/ea5d25/32.png) [@jwilfreds](https://discuss.elastic.co/u/jwilfreds)\
**Post date:** [February 14, 2022, 8:33am UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022/3 "2022-02-14T08:33:28Z")

</div>

Yes, indexes.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 14, 2022, 8:35am UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022/4 "2022-02-14T08:35:36Z")

</div>

Righto, then you will need to share your policy and an explain on it.

---

<div class="post-metadata">

**Author:** ![jwilfreds](https://avatars.discourse-cdn.com/v4/letter/j/ea5d25/32.png) [@jwilfreds](https://discuss.elastic.co/u/jwilfreds)\
**Post date:** [February 14, 2022, 12:31pm UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022/5 "2022-02-14T12:31:09Z")

</div>

This is the policy we have.

```auto
{
  "policy": "logstash-policy",
  "phase_definition": {
    "min_age": "0ms",
    "actions": {
      "rollover": {
        "max_size": "80gb",
        "max_age": "7d"
      }
    }
  },
  "version": 4,
  "modified_date_in_millis": 1643893745244
}

```

========================

It was earlier set to roll over at 5 GB. Roll over did not happen. when i checked it was around 78 GB and i changed the max size to 80 GB. But still did not happen.

I also see the error:  
illegal\_argument\_exception: index.lifecycle.rollover\_alias [logstash] does not point to index [logstash]

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 15, 2022, 12:14am UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022/6 "2022-02-15T00:14:37Z")

</div>

Where is that error?  
What does an explain on the policy show?

---

<div class="post-metadata">

**Author:** ![jwilfreds](https://avatars.discourse-cdn.com/v4/letter/j/ea5d25/32.png) [@jwilfreds](https://discuss.elastic.co/u/jwilfreds)\
**Post date:** [February 16, 2022, 11:08am UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022/7 "2022-02-16T11:08:54Z")

</div>

This below is the error:

> [@jwilfreds](#):
>
> **illegal\_argument\_exception: index.lifecycle.rollover\_alias [logstash] does not point to index [logstash]**

This is the logstash\_Policy code:

```auto
PUT _ilm/policy/logstash-policy
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "rollover": {
            "max_age": "7d",
            "max_size": "80gb"
          }
        }
      },
      "delete": {
        "min_age": "90d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![jwilfreds](https://avatars.discourse-cdn.com/v4/letter/j/ea5d25/32.png) [@jwilfreds](https://discuss.elastic.co/u/jwilfreds)\
**Post date:** [February 16, 2022, 2:47pm UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022/8 "2022-02-16T14:47:40Z")

</div>

Hi pls find the explain output:

```auto
[xxxxxxxxxx ~]$ curl -X GET "localhost:9200/logstash*/_ilm/explain?pretty"
{
  "indices" : {
    "logstash" : {
      "index" : "logstash",
      "managed" : true,
      "policy" : "logstash-policy",
      "lifecycle_date_millis" : 1614378182107,
      "age" : "354.68d",
      "phase" : "hot",
      "phase_time_millis" : 1645022884107,
      "action" : "rollover",
      "action_time_millis" : 1614378281319,
      "step" : "check-rollover-ready",
      "step_time_millis" : 1645022884107,
      "is_auto_retryable_error" : true,
      "failed_step_retry_count" : 25531,
      "phase_execution" : {
        "policy" : "logstash-policy",
        "phase_definition" : {
          "min_age" : "0ms",
          "actions" : {
            "rollover" : {
              "max_size" : "80gb",
              "max_age" : "7d"
            }
          }
        },
        "version" : 4,
        "modified_date_in_millis" : 1643893745244
      }
    }
  }
}
[xxxxxxxxxxxxxx ~]$

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2022, 2:48pm UTC](https://discuss.elastic.co/t/logstash-not-getting-rolled-over/297022/9 "2022-03-16T14:48:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
