# Rollovr dosen't work

**URL:** <https://discuss.elastic.co/t/rollovr-dosent-work/58216>\
**Category:** Elasticsearch\
**Created:** [August 17, 2016, 7:31am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216 "2016-08-17T07:31:51Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 17, 2016, 7:31am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/1 "2016-08-17T07:31:51Z")

</div>

Hi Community,

I've tried to setup a rollover into a new index:

```
curl -XPUT http://HOST/rollover- -d'
 {
     "mappings": {
       "syslog": {
         "_all": {
           "enabled": true,
           "omit_norms": true
         },
         "dynamic_templates": [
          {
            "message_field": {
              "mapping": {
                "fielddata": {
                  "format": "disabled"
                },
                "index": "analyzed",
                "omit_norms": true,
                "type": "string"
              },
              "match": "message",
              "match_mapping_type": "string"
            }
          },
          {
            "string_fields": {
              "mapping": {
                "fielddata": {
                  "format": "disabled"
                },
                "index": "analyzed",
                "omit_norms": true,
                "type": "string",
                "fields": {
                  "raw": {
                    "ignore_above": 256,
                    "index": "not_analyzed",
                    "type": "string"
                  }
                }
              },
              "match": "*",
              "match_mapping_type": "string"
            }
          }
        ],
  
 
        "properties": {
           "@timestamp": {
             "type": "date",
             "format": "strict_date_optional_time||epoch_millis"
           },
           "@version": {
             "type": "string",
             "index": "not_analyzed"
           },
           "conditions": {
            "properties": {
              "[max_age: 1h]": {
                "type": "boolean"
              }
            }
           },
           "bytes": {
             "type": "long"
           },
           "client_address": {
             "type": "ip"
           },
           "duration": {
             "type": "long"
           },
           "geoip": {
            "properties": {
              "coordinates": {
                "type": "float"
              },
              "ip": {
                "type": "ip"
              },
              "latitude": {
                "type": "float"
              },
              "location": {
                "type": "geo_point"
              },
              "longitude": {
                "type": "float"
              }
            }
          },
          "new_index": {
            "type": "string",
            "norms": {
              "enabled": false
            },
            "fielddata": {
              "format": "disabled"
            },
            "fields": {
              "raw": {
                "type": "string",
                "index": "not_analyzed",
                "ignore_above": 256
              }
            }
          },
          "old_index": {
            "type": "string",
            "norms": {
              "enabled": false
            },
            "fielddata": {
              "format": "disabled"
            },
            "fields": {
              "raw": {
                "type": "string",
                "index": "not_analyzed",
                "ignore_above": 256
              }
            }
          },
          "rolled_over": {
            "type": "boolean"
          }
 }
 }
 }
 }'

```

This Index do not a rollover...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 17, 2016, 7:33am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/2 "2016-08-17T07:33:11Z")

</div>

> [@bastianhoss](#):
>
> This Index do not a rollover...

What do you mean?  
What version are you on?  
What do your logs say?

Please, provide more information so we can help!

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 17, 2016, 7:51am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/3 "2016-08-17T07:51:00Z")

</div>

What do you mean?  
The Index do not perform a rollover after 1h.

What version are you on?  
"version" : {  
"number" : "2.3.4",  
"lucene\_version" : "5.5.0"

What do your logs say?  
Nothing in there...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 17, 2016, 7:58am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/4 "2016-08-17T07:58:28Z")

</div>

There is no rollover functionality in Elasticsearch 2.3.4, so I am not sure I understand what you are expecting to happen. If you are looking to create hourly indices, this is controlled through the ingestion pipeline, e.g. Logstash.

There is however a new rollover feature available in the upcoming Elasticsearch 5.0 release. If this is what you are referring to you can read more about it in [this blog post](https://www.elastic.co/blog/managing-time-based-indices-efficiently).

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 17, 2016, 8:00am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/5 "2016-08-17T08:00:53Z")

</div>

I'm not sure...

The default Index logstash- performs a daily rollover...

What do you mean by \> is controlled through the ingestion pipeline

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 17, 2016, 8:04am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/6 "2016-08-17T08:04:06Z")

</div>

The Elasticsearch output in Logstash can be configured to send events to an index name based on the event timestamp. When events for a new date/time period arrives these will therefore automatically be written to a new index which is then created in Elasticsearch. This is therefore managed through Logstash, not Elasticsearch.

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 17, 2016, 11:23am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/7 "2016-08-17T11:23:11Z")

</div>

I've tried this option in logstash ouput cfg:

index =\> "index-%{+YYYY.MM.dd}"

But all my static mappings disapers...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 17, 2016, 11:41am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/8 "2016-08-17T11:41:01Z")

</div>

The default Logstash index template only applies to indices named `logstash-*`, so you need to modify this or create your own if you change the index name. The mapping template for ES 2.x can be found [here](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es2x.json).

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 17, 2016, 1:57pm UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/9 "2016-08-17T13:57:47Z")

</div>

Using this templat dosen't work...

syslog\_filter:  
else if [program] == "elastic-wsa" {  
grok {  
patterns\_dir =\> ["/etc/logstash/conf.d/patterns"]  
match =\> [  
"message" ,"%{WORD:message\_type}: %{NUMBER:log\_time} %{NUMBER:duration} %{IP:client\_address} %{WORD:transaction\_result\_code}/%{NUMBER:http\_result\_code} %{NUMBER:bytes:int} %{WORD:http\_metod} %{PROTOCOL:url\_protocol}%{DOMAIN:url\_domain}%{REFERER:url\_referer} %{NOTSPACE:user} %{NOTSPACE:requested\_server} %{NOTSPACE:response\_mime\_type} %{NOT\_HYPHEN:acl\_decision\_tag}-%{NOT\_HYPHEN:access\_or\_decryption\_policy}-%{NOT\_HYPHEN:identity\_policy\_group}-%{NOT\_HYPHEN:outbound\_maleware\_scanning\_policy\_group}-%{NOT\_HYPHEN:data\_security\_policy\_group}-%{NOT\_HYPHEN:external\_dlp\_policy\_group}-%{NOT\_HYPHEN:routing\_policy\_group} \<%{NOT\_COMMA:url\_category},%{NOT\_COMMA:wbrs},%{NOT\_COMMA:webroot\_verdict},%{NOT\_COMMA:spyname},%{NOT\_COMMA:trr},%{NOT\_COMMA:threat\_id},%{NOT\_COMMA:trace\_id},%{NOT\_COMMA:mcafee\_verdict},%{NOT\_COMMA:mcafee\_filenmae},%{NOT\_COMMA:mcafee\_scan\_error\_code},%{NOT\_COMMA:mcafee\_detection\_type},%{NOT\_COMMA:mcafee\_virus\_type},%{NOT\_COMMA:mcafee\_virus\_name},%{NOT\_COMMA:sophos\_verdict},%{NOT\_COMMA:sophos\_scan\_return\_code},%{NOT\_COMMA:sophos\_file\_location},%{NOT\_COMMA:sophos\_threat\_name},%{NOT\_COMMA:data\_security},%{NOT\_COMMA:data\_loss\_prevention},%{NOT\_COMMA:requested\_side\_url\_verdict},%{NOT\_COMMA:response\_side\_url\_verdict},%{NOT\_COMMA:unified\_inbound\_dvs\_verdict},%{NOT\_COMMA:web\_reputation\_filter\_type},%{NOT\_COMMA:avc\_application\_name},%{NOT\_COMMA:avc\_application\_type},%{NOT\_COMMA:avc\_application\_behavior},%{NOT\_COMMA:avc\_safe\_browsing\_scanning\_verdict},%{NOT\_COMMA:average\_bandwidth},%{NOT\_COMMA:throttle\_flag},%{NOT\_COMMA:type\_of\_user},%{NOT\_COMMA:unified\_outbound\_dvs\_verdict},%{NOT\_COMMA:outbound\_threat\_name}%{GREEDYDATA:message\_body}\>"  
]  
}

```
      mutate {
         #convert => ["bytes", "integer"]
         #convert => ["duration", "integer"]
         #convert => ["client_address", "ip"]
         }

      geoip {
         source => "client_address"
         target => "geoip"
         database => "/etc/logstash/conf.d/geo/GeoLiteCity.dat"
         add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
         add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
         }

      mutate {
         convert => ["[geoip][coordinates]", "float"]
         }

      }
```

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 17, 2016, 1:58pm UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/10 "2016-08-17T13:58:19Z")

</div>

Index:

```
    {
      "template" : "rollover-*",
      "settings" : {
        "index.refresh_interval" : "5s"
      },
      "mappings" : {
        "_default_" : {
          "_all" : {"enabled" : true, "omit_norms" : true},
          "dynamic_templates" : [ {
            "message_field" : {
              "match" : "message",
              "match_mapping_type" : "string",
              "mapping" : {
                "type" : "string", "index" : "analyzed", "omit_norms" : true,
                "fielddata" : { "format" : "disabled" }
              }
            }
          }, {
            "string_fields" : {
              "match" : "*",
              "match_mapping_type" : "string",
              "mapping" : {
                "type" : "string", "index" : "analyzed", "omit_norms" : true,
                "fielddata" : { "format" : "disabled" },
                "fields" : {
                  "raw" : {"type": "string", "index" : "not_analyzed", "doc_values" : true, "ignore_above" : 256}
                }
              }
            }
          }, {
            "float_fields" : {
              "match" : "*",
              "match_mapping_type" : "float",
              "mapping" : { "type" : "float", "doc_values" : true }
            }
          }, {
            "double_fields" : {
              "match" : "*",
              "match_mapping_type" : "double",
              "mapping" : { "type" : "double", "doc_values" : true }
            }
          }, {
            "byte_fields" : {
              "match" : "*",
              "match_mapping_type" : "byte",
              "mapping" : { "type" : "byte", "doc_values" : true }
            }
          }, {
            "short_fields" : {
              "match" : "*",
              "match_mapping_type" : "short",
              "mapping" : { "type" : "short", "doc_values" : true }
            }
          }, {
            "integer_fields" : {
              "match" : "*",
              "match_mapping_type" : "integer",
              "mapping" : { "type" : "integer", "doc_values" : true }
            }
          }, {
            "long_fields" : {
              "match" : "*",
              "match_mapping_type" : "long",
              "mapping" : { "type" : "long", "doc_values" : true }
            }
          }, {
            "date_fields" : {
              "match" : "*",
              "match_mapping_type" : "date",
              "mapping" : { "type" : "date", "doc_values" : true }
            }
          }, {
            "geo_point_fields" : {
              "match" : "*",
              "match_mapping_type" : "geo_point",
              "mapping" : { "type" : "geo_point", "doc_values" : true }
            }
          } ],
          "properties" : {
            "@timestamp": { "type": "date", "doc_values" : true },
            "@version": { "type": "string", "index": "not_analyzed", "doc_values" : true },
            "geoip" : {
              "type" : "object",
              "dynamic": true,
              "properties" : {
                "ip": { "type": "ip", "doc_values" : true },
                "location" : { "type" : "geo_point", "doc_values" : true },
                "latitude" : { "type" : "float", "doc_values" : true },
                "longitude" : { "type" : "float", "doc_values" : true }
              }
            },
            "client_address": {
                 "type": "ip"
            }
          }
        }
      }
    }
```

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 17, 2016, 2:03pm UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/11 "2016-08-17T14:03:37Z")

</div>

client\_address is a string now.

geoip.location is a float now.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 18, 2016, 8:07am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/12 "2016-08-18T08:07:38Z")

</div>

Did you upload the index template? What does you output config look like?

---

<div class="post-metadata">

**Author:** ![bastianhoss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bastianhoss/32/11437_2.png) [@bastianhoss](https://discuss.elastic.co/u/bastianhoss)\
**Post date:** [August 18, 2016, 8:26am UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/13 "2016-08-18T08:26:02Z")

</div>

I've confgured a new index not realy a template:

curl -xPUT [http://host/index](http://host/index)

vs.

curl -XPUT [http://host/\_template/temp](http://host/_template/temp)

After using the corrct API the template works fine...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:26pm UTC](https://discuss.elastic.co/t/rollovr-dosent-work/58216/14 "2017-07-05T22:26:58Z")

</div>


