# Managing ILM policies

**URL:** <https://discuss.elastic.co/t/managing-ilm-policies/187516>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [June 26, 2019, 8:16am UTC](https://discuss.elastic.co/t/managing-ilm-policies/187516 "2019-06-26T08:16:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlessandroKP](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alessandrokp/32/45312_2.png) [@AlessandroKP](https://discuss.elastic.co/u/AlessandroKP)\
**Post date:** [June 26, 2019, 8:16am UTC](https://discuss.elastic.co/t/managing-ilm-policies/187516/1 "2019-06-26T08:16:01Z")

</div>

Hi all,  
I would like some information about index lifecycle management.  
I have some data stored in ES under indices whose names are of the form:  
my-logs-A.2019-01, my-logs-A.2019-02, my-logs-A.2019-03, ...  
my-logs-B.2019-01, my-logs-B.2019-02, my-logs-B.2019-03, ... and so on.  
Each one refers to data collected in a specific month.  
In this example I have two 'types' of data: my-logs-A and my-logs-B.  
The data enters ES through a Logstash pipeline that decides the index where to inject the documents and the template.

I know that I can manage the lifecycle of a given index by applying a certain ILM policy to the corresponding index template.  
For example, I have defined this index template:

```
    {
      "my-logs-A-template" : {
        "index_patterns" : ["my-logs-A.*],
        "settings" : {
          "index" : {
            "lifecycle" : {
              "name" : "retention_3_months"
            },
            "number_of_shards" : "1",
            "number_of_replicas" : "0"
          }
        }
      }
    }

```

and the policy called "retention\_3\_months"

```
{
  "retention_3_months" : {
    "policy" : {
      "phases" : {
        "delete" : {
          "min_age" : "90d",
          "actions" : {
            "delete" : { }
          }
        }
      }
    }
  }
}

```

This ILM policy applies to all indices of the form my-logs-A.\* and that's good.  
Now, I can create an other template for the data stored in my-logs-B.\* and assign a different ILM policy to it.

What I would like to do is to define a single template for both types of data, that is:

```
{
  "my-logs-template" : {
    "index_patterns" : [
      "my-logs-*"
    ],
    "settings" : {
		...
    }
  }
}

```

but decide which ILM policy to apply to specific index patterns based on some expression present in the index name.  
In my example, if the index name matches the pattern "my-logs-A.\*", then I need to apply policy retention\_3\_months;  
if it matches "my-logs-B.\*" then I need to apply policy retention\_6\_months.  
But the two index pattern must have the same template.

Is there a way to select which ILM to apply based on a condition, for indices having the same template?

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [June 28, 2019, 3:00pm UTC](https://discuss.elastic.co/t/managing-ilm-policies/187516/2 "2019-06-28T15:00:31Z")

</div>

This isn't currently possible, unfortunately - you'll have to use multiple templates.

However, [if multiple templates match, they are merged](https://www.elastic.co/guide/en/elasticsearch/reference/7.2/indices-templates.html#multiple-templates) - so you could have one template with most of the settings and the mapping with the pattern `my-logs-*`, and two other templates that just have the lifecycle policy name that match `my-logs-A*` and my-logs-B\*`. That would let you have the shared settings/mapping data in one template, and add onto or override that as needed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2019, 3:00pm UTC](https://discuss.elastic.co/t/managing-ilm-policies/187516/3 "2019-07-26T15:00:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
