# .monitoring-es indexes blow up, have no policies associated?

**URL:** <https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186>\
**Category:** Elasticsearch\
**Created:** [August 29, 2022, 3:39pm UTC](https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186 "2022-08-29T15:39:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![wrobitza\_aveq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrobitza_aveq/32/105113_2.png) [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Post date:** [August 29, 2022, 3:39pm UTC](https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186/1 "2022-08-29T15:39:21Z")

</div>

I've enabled Stack Monitoring in Kibana, just for the purpose of trying it out. Now, after a couple of days, I see that my stack is using a lot of disk memory.

I was able to delete the individual `.es-monitoring*` indices that used up this space, but I would like to modify the policy that creates them in the first place, so that they are only kept for one day or 1GB at most.

What I see from [this topic](https://discuss.elastic.co/t/huge-monitoring-es-indexes/285102/10) is not really helpful; it says I can safely delete these indices. But I don't want to do that manually. I also notice that for APM, for instance, there are index lifecycle policies that I can modify, but for monitoring, I don't see any.

What can I do to prevent these large indices?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 29, 2022, 3:48pm UTC](https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186/2 "2022-08-29T15:48:12Z")

</div>

HI @wrobitza_aveq Welcome to the community

> [@wrobitza\_aveq](#):
>
> I've enabled Stack Monitoring in Kibana, just for the purpose of trying it out. Now, after a couple of days, I see that my stack is using a lot of disk memory.

Is this Self Managed or in Elastic Cloud

If Self Managed How did you do enable monitoring / Which Method? Metricbeat / Self Monitoring?

And how did you determine that ILM is not enabled for those indices? (just validating)

---

<div class="post-metadata">

**Author:** ![wrobitza\_aveq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrobitza_aveq/32/105113_2.png) [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Post date:** [August 29, 2022, 4:27pm UTC](https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186/3 "2022-08-29T16:27:08Z")

</div>

This is self-managed. I enabled it by going to Management » Stack Monitoring and following the GUI wizard there.

There are no ILM policies visible when I click on the index in Index Management. Other indices like the ones from APM (e.g., traces) show the ILM policies.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/2/92e86023b89523373a37e6db138588f8dc165f71.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 29, 2022, 4:44pm UTC](https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186/4 "2022-08-29T16:44:39Z")

</div>

> [@wrobitza\_aveq](#):
>
> This is self-managed. I enabled it by going to Management » Stack Monitoring and following the GUI wizard there.

That is the issue... "Self Monitoring" Will be deprecated at some point / soon (this is part of the reason why 🙂 ), it is just the "quick" way to set up monitoring.

If you had used metricbeat etc... then there would be policies... although metricbeat take a bit more work but then it is like any other index and it will have an ILM policy etc.

There is no simple why to add ILM to those indices...

---

<div class="post-metadata">

**Author:** ![wrobitza\_aveq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrobitza_aveq/32/105113_2.png) [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Post date:** [August 29, 2022, 5:30pm UTC](https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186/5 "2022-08-29T17:30:34Z")

</div>

That's good to know. I didn't notice that when enabling the feature a week ago. Maybe the deprectation message needs to be more prominent?

In any case, I ran:

```auto
PUT /_cluster/settings
{
  "persistent": {
    "xpack.monitoring.elasticsearch.collection.enabled": false
  }
}

```

and:

```auto
PUT /_cluster/settings
{
  "persistent": {
    "xpack.monitoring.collection.enabled": false
  }
}

```

and stopped monitoring for now.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 29, 2022, 5:42pm UTC](https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186/6 "2022-08-29T17:42:07Z")

</div>

Yes perhaps... I think it is in the GUI and the [Docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/collecting-monitoring-data.html) pretty prominently.

Not sure what version you are on but I got the deprecation warning with the setting

```auto
PUT /_cluster/settings
{
  "persistent": {
    "xpack.monitoring.collection.enabled": true
  }
}

#! [xpack.monitoring.collection.enabled] setting was deprecated in Elasticsearch and will be removed in a future release.
{
  "acknowledged": true,
  "persistent": {
    "xpack": {
      "monitoring": {
        "collection": {
          "enabled": "true"
        }
      }
    }
  },
  "transient": {}
}

```

---

<div class="post-metadata">

**Author:** ![wrobitza\_aveq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrobitza_aveq/32/105113_2.png) [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Post date:** [August 29, 2022, 5:55pm UTC](https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186/7 "2022-08-29T17:55:41Z")

</div>

> Yes perhaps... I think it is in the GUI and the [Docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/collecting-monitoring-data.html) pretty prominently.

Indeed. In contrast to Legacy APM (standalone server) though, the ILM policies are not present, which caused the whole confusion from my side.

And I did get the same messages on 8.3.3 running these commands!

So I guess I will check out Metricbeat in the future. Thanks for your quick help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2022, 5:56pm UTC](https://discuss.elastic.co/t/monitoring-es-indexes-blow-up-have-no-policies-associated/313186/8 "2022-09-26T17:56:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
