# Question regarding rollover indices aliasing

**URL:** <https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543>\
**Category:** Elasticsearch\
**Created:** [April 6, 2017, 10:20pm UTC](https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543 "2017-04-06T22:20:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ESCoder](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@ESCoder](https://discuss.elastic.co/u/ESCoder)\
**Post date:** [April 6, 2017, 10:20pm UTC](https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543/1 "2017-04-06T22:20:26Z")

</div>

Hi,

I went through the following blog post

> **[And the big one said "Rollover" — Managing Elasticsearch time-based indices...](https://www.elastic.co/blog/managing-time-based-indices-efficiently)**
>
> Introducing the new Rollover Pattern, and the APIs which support it, which is a simpler, more efficient way of managing time-based indices in Elasticsearch.

and used the same calls to create indices, add data and rollover indices

after executing rollover indices it created another new index as max\_docs condition was hit.

And active-logs alias now points to the new index active-logs-2 index whereas search-logs alias points to both active-logs-1 and active-logs-2 indices.

How did it determine one alias was used for indexing and the other one for searching? I didnt specify any parameters indicating about search or index.

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 8, 2017, 11:20pm UTC](https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543/2 "2017-04-08T23:20:50Z")

</div>

The first json post in that blog post has;

```auto
"aliases": {
    "active-logs": {},
    "search-logs": {}
  }

```

That's where it's established.

---

<div class="post-metadata">

**Author:** ![ESCoder](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@ESCoder](https://discuss.elastic.co/u/ESCoder)\
**Post date:** [April 10, 2017, 1:47pm UTC](https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543/3 "2017-04-10T13:47:55Z")

</div>

so, by default the first alias is assumed to be used for indexing and the second one for searching?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 11, 2017, 12:24am UTC](https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543/4 "2017-04-11T00:24:23Z")

</div>

No, that's just an example of assigning multiple aliases.

---

<div class="post-metadata">

**Author:** ![ESCoder](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@ESCoder](https://discuss.elastic.co/u/ESCoder)\
**Post date:** [April 11, 2017, 2:07pm UTC](https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543/5 "2017-04-11T14:07:05Z")

</div>

after rollover was done I executed the following end point

GET [http://localhost:9200/\_cat/aliases?v](http://localhost:9200/_cat/aliases?v)  
and the output was

![](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8b4dc6ae9ab06a3b44ba511c1d760899c9637614.png)

why is "active-logs" alias pointing to only "active-logs-000002" whereas "search-logs" alias is pointing to both "active-logs-1" and "active-logs-000002"?

how did it determine "active-logs" alias was used for indexing? I did not specify that "active-logs" alias is used for indexing and "search-logs" is used for searching in the above list of calls.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 11, 2017, 11:01pm UTC](https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543/6 "2017-04-11T23:01:39Z")

</div>

> [@ESCoder](#):
>
> why is "active-logs" alias pointing to only "active-logs-000002" whereas "search-logs" alias is pointing to both "active-logs-1" and "active-logs-000002"?

Did you run the last `POST` command in the blog that updates the aliases?

> [@ESCoder](#):
>
> how did it determine "active-logs" alias was used for indexing? I did not specify that "active-logs" alias is used for indexing and "search-logs" is used for searching in the above list of calls.

It doesn't. These are simply abstractions to make it easier.

Rather than the system that sends the logs to ES having to know that the current active index is `active-logs-000001` and then after the rollover is now called `active-logs-000002`, you use these as abstractions to that all it needs to do is write to `active-logs`.

---

<div class="post-metadata">

**Author:** ![ESCoder](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@ESCoder](https://discuss.elastic.co/u/ESCoder)\
**Post date:** [April 13, 2017, 2:33pm UTC](https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543/7 "2017-04-13T14:33:51Z")

</div>

> Did you run the last `POST` command in the blog that updates the aliases?

did you mean this code? then no, I didn't. POST active-logs/\_rollover is the last command I ran.

```
POST _aliases
{
  "actions": [
    {
      "remove": {
        "index": "active-logs-1",
        "alias": "search-logs"
      }
    },
    {
      "add": {
        "index": "inactive-logs-1",
        "alias": "search-logs"
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2017, 2:35pm UTC](https://discuss.elastic.co/t/question-regarding-rollover-indices-aliasing/81543/8 "2017-05-11T14:35:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
