# Need Explanation ILM / DSL / closing indice and stuff

**URL:** <https://discuss.elastic.co/t/need-explanation-ilm-dsl-closing-indice-and-stuff/379232>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [June 17, 2025, 8:56am UTC](https://discuss.elastic.co/t/need-explanation-ilm-dsl-closing-indice-and-stuff/379232 "2025-06-17T08:56:56Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sebastien\_Tolron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastien_tolron/32/143697_2.png) [@Sebastien\_Tolron](https://discuss.elastic.co/u/Sebastien_Tolron)\
**Post date:** [June 17, 2025, 8:56am UTC](https://discuss.elastic.co/t/need-explanation-ilm-dsl-closing-indice-and-stuff/379232/1 "2025-06-17T08:56:56Z")

</div>

Hi ,

Hi Everyone ,

I'm trying to understand what I've done with ILM and it looks messy 😃

I need explanation and some help on good practices for that.

_ **The Setup :** _

I have an Elasticsearch cluster with 10 Data nodes. 250Gb storage per node. Version 8.18.1

I have multiple filebeats sending datas to Elasticsearch ( Around 10 filebeats ). I'll take one for my example with is : analytics-kubernetes-apps-np

Here is the filebeat configuration

```auto
                        output.elasticsearch:
                          hosts: masked
                          ssl.verification_mode : "none"
                          username: masked
                          password: "masked"
                          pipeline: kubernetes-nginx-routing
                          index: "analytics-kubernetes-apps-np-%{+yyyy.MM.dd}"
                        setup.ilm.enabled: true
                        setup.ilm.policy_name: "analytics-kubernetes-apps-np"
                        setup.ilm.rollover_alias: "analytics-kubernetes-apps-np"
                        setup.template.name: "analytics-kubernetes-apps-np"
                        setup.template.pattern: "analytics-kubernetes-apps-np-*"

```

So When I Create the filebeat, It load my index template and Create a datastream.

Here is the Lifecycle Policy

```auto
PUT _ilm/policy/analytics-kubernetes-apps-np
{
  "policy": {
    "phases": {
      "hot": {
        "min_age": "0ms",
        "actions": {
          "rollover": {
            "max_age": "1d"
          }
        }
      },
      "delete": {
        "min_age": "3d",
        "actions": {
          "delete": {
            "delete_searchable_snapshot": true
          }
        }
      }
    }
  }
}

```

So everything goes fine at this point. My ilm rollover my index and create indice every days. Data is cleaned up every 3 days.

_ **The problem :** _

This creates a lot of datasources and it is fine. Here are datasources

`https://ibb.co/dsrqDKtQ`

And this also create a lot of indices

`https://ibb.co/d47p7JWv`

I understand that theses indices are all rollover indices. But I don't understand why they are still here. There are no documents in here . And the indice is still active and open !

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/9/292cd7fc37e253b54f844b4f9cd4dad790e08b1f.png)

`https://ibb.co/QvLR5k7P`

The issue here is that the indice is still here. And it initialize shards !! So at one point I have too many shards and my cluster can't initialize more shards. It switch then to unhealthy.

I have to manually delete thoses old indices to remove some shard and make it healthy again.

Is there something I'm doing wrong ?

Thanks a lot for your support.

Regards

Sorry for the links , cant post more that one image in the post 😕
