# Rotate elastic indices based on size

**URL:** <https://discuss.elastic.co/t/rotate-elastic-indices-based-on-size/94933>\
**Category:** Logstash\
**Created:** [July 28, 2017, 10:20am UTC](https://discuss.elastic.co/t/rotate-elastic-indices-based-on-size/94933 "2017-07-28T10:20:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhiroyg](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@abhiroyg](https://discuss.elastic.co/u/abhiroyg)\
**Post date:** [July 28, 2017, 10:20am UTC](https://discuss.elastic.co/t/rotate-elastic-indices-based-on-size/94933/1 "2017-07-28T10:20:26Z")

</div>

Hi,

How to achieve rotation of elastic indices based on its size using elasticsearch-output plugin ? If I use an external program like [Rollover API](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/indices-rollover-index.html), will I lose data ? Do I have to bring logstash down, do the rollover, and bring it up ?

One more doubt, for custom index names (i.e., names not starting with 'logstash-'), should we need to set 'template' setting explicitly to the path of logstash provided default template (if we don't want custom templates) ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 28, 2017, 11:18am UTC](https://discuss.elastic.co/t/rotate-elastic-indices-based-on-size/94933/2 "2017-07-28T11:18:49Z")

</div>

> [@abhiroyg](#):
>
> If I use an external program like Rollover API, will I lose data ?

No

> [@abhiroyg](#):
>
> Do I have to bring logstash down, do the rollover, and bring it up ?

No, the switching of underlying indices is handled by Elasticsearch and invisible to Logstash. Logstash should just continue indexing into the appropriate write alias.

> [@abhiroyg](#):
>
> One more doubt, for custom index names (i.e., names not starting with ‘logstash-’), should we need to set ‘template’ setting explicitly to the path of logstash provided default template (if we don’t want custom templates) ?

The default template only applies to indices names `logstash-*`. If your underlying index name follows this pattern, it should continue to apply. If you have named your index something else, you will need to define a custom index template, even if this is just a copy of the default one with changed index pattern to match the new index name.

---

<div class="post-metadata">

**Author:** ![abhiroyg](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@abhiroyg](https://discuss.elastic.co/u/abhiroyg)\
**Post date:** [July 28, 2017, 11:24am UTC](https://discuss.elastic.co/t/rotate-elastic-indices-based-on-size/94933/3 "2017-07-28T11:24:09Z")

</div>

Thank you! That resolves.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2017, 11:24am UTC](https://discuss.elastic.co/t/rotate-elastic-indices-based-on-size/94933/4 "2017-08-25T11:24:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
