# Logstash with ILM configuration

**URL:** <https://discuss.elastic.co/t/logstash-with-ilm-configuration/323363>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [January 17, 2023, 8:56pm UTC](https://discuss.elastic.co/t/logstash-with-ilm-configuration/323363 "2023-01-17T20:56:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Erates](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erates/32/9406_2.png) [@Erates](https://discuss.elastic.co/u/Erates)\
**Post date:** [January 17, 2023, 8:56pm UTC](https://discuss.elastic.co/t/logstash-with-ilm-configuration/323363/1 "2023-01-17T20:56:58Z")

</div>

Hi, we have an ELK stack running (I have no say in which version, which is currently 7.x) to get the logs of our applications running in a Kubernetes cluster all combined in 1 place. The applications are pushing their logs to Logstash.

Logstash's output configuration looks like this:

```auto
    output {
        elasticsearch {
            index => "my-test"
            hosts => ["${ES_HOSTS}"]
            user => "${ES_USER}"
            password => "${ES_PASSWORD}"
        }
    }

```

Logs pushed to logstash do appear in Elasticsearch and are visible in Kibana. We have a Index template configured like this:

```auto
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "kubernetes_cluster_30-days"
        }
      }
    },
    "aliases": {},
    "mappings": {}
  }
}

```

The ILM policy `kubernetes_cluster_30-days` Is configured (not on 30 days like in the name, but that's for testing) like so:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b1cb430e13dccfedc21e8d80d6001371cd06761.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f2cff543b57ed9d0d185fed69d0e22b2baf9ba95.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/3/43cb5e1cd96712a71a7c12e4a473cab34c4ebf69.png)

But I have a feeling the rollover is not happening. We've tried already to use an index with a timestamp in the name, but that doens't rollover either.

I'm sure we're doing something wrong, but we cannot find what. Can you please help us!

Kind regards!

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [January 17, 2023, 9:39pm UTC](https://discuss.elastic.co/t/logstash-with-ilm-configuration/323363/2 "2023-01-17T21:39:27Z")

</div>

is "my-test " alias to index? if not then this will not work

first you have to setup ILM  
create templete where you have to assign alias  
then create blank index with timestamp

then only ILM policy will roll over index

For example

```auto
PUT _ilm/policy/my-test
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "rollover": {
            "max_primary_shard_size": "25gb",
            "max_age": "365d"
          }
        }
      }
    }
  }
} 
GET /_cat/aliases
 
PUT _index_template/my-test
{
  "index_patterns": ["my-test-*"],
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "kubernetes_cluster_30-days",
          "rollover_alias": "my-test"
        },
        "number_of_shards": "4",
        "number_of_replicas": "1"
      }
    },
    "aliases": {},
    "mappings": {}
  }
}

#PUT <my-index-{now/d}-000001>
PUT %3Cmy-test-%7Bnow%2Fd%7D-000001%3E
{
  "aliases": {
    "my-test": {
      "is_write_index": true
    }
  }
}

```

What this will do is create a ILM, templet and blank index my-index--00001 and  
now you write to alias "my-index" which will write to latest index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2023, 9:39pm UTC](https://discuss.elastic.co/t/logstash-with-ilm-configuration/323363/3 "2023-02-14T21:39:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
