# Migrate to datastreams withou aliases + datastreams filter

**URL:** <https://discuss.elastic.co/t/migrate-to-datastreams-withou-aliases-datastreams-filter/323401>\
**Category:** Elasticsearch\
**Tags:** datastreams\
**Created:** [January 18, 2023, 10:22am UTC](https://discuss.elastic.co/t/migrate-to-datastreams-withou-aliases-datastreams-filter/323401 "2023-01-18T10:22:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bilak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bilak/32/116075_2.png) [@bilak](https://discuss.elastic.co/u/bilak)\
**Post date:** [January 18, 2023, 10:22am UTC](https://discuss.elastic.co/t/migrate-to-datastreams-withou-aliases-datastreams-filter/323401/1 "2023-01-18T10:22:47Z")

</div>

Hello,  
I'd like to use data streams and migrate our indices to it. However currently we **don't use aliases.** Do I have to create an alias for given indices pattern (`technical-logs*`) at first and only after that I'm able to migrate to data streams?

Second question is more about filtering. When we are filtering by date we just get all indices names from ES and then we search in those indices which match the given filter (e.g. from `technical-logs-20230101` to `technical-logs-20230118`). When we switch to data streams it seems like the indices will be hidden. So the question is am I able to somehow specify in which indices should query search? Or is it all automatically being applied when I specify `@timestamp` parameter?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 18, 2023, 10:50pm UTC](https://discuss.elastic.co/t/migrate-to-datastreams-withou-aliases-datastreams-filter/323401/2 "2023-01-18T22:50:19Z")

</div>

Welcome to our community! 😃

> [@bilak](#):
>
> Do I have to create an alias for given indices pattern (`technical-logs*`) at first and only after that I'm able to migrate to data streams?

Generally you would reindex older data into the data stream so you don't need to worry about this.

> [@bilak](#):
>
> When we are filtering by date we just get all indices names from ES and then we search in those indices which match the given filter

It might be easier to provide a bit more context on how you are querying, because generally that's not what you'd do and is inefficient.

---

<div class="post-metadata">

**Author:** ![bilak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bilak/32/116075_2.png) [@bilak](https://discuss.elastic.co/u/bilak)\
**Post date:** [January 19, 2023, 8:35am UTC](https://discuss.elastic.co/t/migrate-to-datastreams-withou-aliases-datastreams-filter/323401/3 "2023-01-19T08:35:28Z")

</div>

> [@warkolm](#):
>
> Generally you would reindex older data into the data stream so you don't need to worry about this.

the question was more regarding [this topic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/set-up-a-data-stream.html#convert-index-alias-to-data-stream). Documentation tells only about migration from index alias. So if I have many indices (`technical-logs-20230101`, `technical-logs-20230102`, ...) which I want to migrate to one data stream am I able to do that without creating an alias for those indices? Currently there is no alias.

> [@warkolm](#):
>
> It might be easier to provide a bit more context on how you are querying, because generally that's not what you'd do and is inefficient.

So we have many groups of indices (`technical-logs*`, `notifications*`, `incidents*`, ...). We do a rollover daily so there is always date suffix. If we don't provide the date range, we are searching in indices with asterisk (e.g. `technical-logs*`). If we provide date range then we are trying to get all indices which are in given range (e.g. from `technical-logs-20230101` to `technical-logs-20230118` ). Now the question is if this is really necessary and if ES doesn't apply such filter automatically when we filter by `@timestamp`.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 19, 2023, 9:28am UTC](https://discuss.elastic.co/t/migrate-to-datastreams-withou-aliases-datastreams-filter/323401/4 "2023-01-19T09:28:49Z")

</div>

> [@bilak](#):
>
> the question was more regarding [this topic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/set-up-a-data-stream.html#convert-index-alias-to-data-stream)

Ah ok. I don't know to be honest. If you follow that through to [Migrate to data stream API | Elasticsearch Guide [7.17] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/indices-migrate-to-data-stream.html) it says;

> If successful, the request removes the alias and creates a data stream with the same name. The alias’s indices become hidden backing indices for the stream. The alias’s write index becomes the stream’s write index.

So my guess it doesn't do much other than some alias switching/renaming.

> [@bilak](#):
>
> Now the question is if this is really necessary and if ES doesn't apply such filter automatically when we filter by `@timestamp`.

Elasticsearch handles this transparently for you, so I wouldn't worry too much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 16, 2023, 9:29am UTC](https://discuss.elastic.co/t/migrate-to-datastreams-withou-aliases-datastreams-filter/323401/5 "2023-02-16T09:29:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
