# Sanity check on ILM

**URL:** <https://discuss.elastic.co/t/sanity-check-on-ilm/259306>\
**Category:** Elasticsearch\
**Created:** [December 21, 2020, 10:01pm UTC](https://discuss.elastic.co/t/sanity-check-on-ilm/259306 "2020-12-21T22:01:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [December 21, 2020, 10:01pm UTC](https://discuss.elastic.co/t/sanity-check-on-ilm/259306/1 "2020-12-21T22:01:47Z")

</div>

I have spent the last 3 weeks off and on trying to get ILM to work. I have datastreams going but one client I am using (syslog-ng) does not yet know about datastreams and uses `index` in the `_bulk` rather than `create`.

I found the documentation tantalizingly incomplete. It seems that the authors made assumption about what was obvious that were clearly wrong in my case. Common problem with technical documentation.

The curicial bit of information that I lacked was the link between the rollover alias and the alias set on the initial creation of the index with ` "is_write_index": true` and that this is what you use to write to the index.

Assuming that I have this all right! It seems to be working as expected.

So here is my howto for an sanity check and for anyone else as stupid as me who tries to set up ILM from scratch. I found this [this](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html#ilm-gs-alias-bootstrap) link most useful but it still requires some joining of dots...

1. create your index and bootstrap the write/rollover alias:

```auto
curl -X PUT "localhost:9200/timeseries-000001?pretty" -H 'Content-Type: application/json' -d'
{
  "aliases": {
    “timeseries-write": {
      "is_write_index": true
    }
  }
}

```

I could not find any way of doing this in kibana but the following steps can be...

1. create the lifecycle policy (say timeseries-policy)
2. create the index template with these `settings`

```auto
{
  "index": {
    "lifecycle": {
      "name": “timeseries-policy",
      "rollover_alias": “timeseries-write"
    }
  }
}

```

1. start writing to timeseries-write

Improvement or corrections solitited

---

<div class="post-metadata">

**Author:** ![andreidan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreidan/32/78167_2.png) [@andreidan](https://discuss.elastic.co/u/andreidan)\
**Post date:** [December 22, 2020, 1:29pm UTC](https://discuss.elastic.co/t/sanity-check-on-ilm/259306/2 "2020-12-22T13:29:15Z")

</div>

Thanks for using Elasticsearch. I believe the steps you highlighted are correct, with the only note to execute step 3 (creating the index template) before step 1 (creating the index with the alias and `is_write_index`configuration) in order for the `index.lifecycle.name` and `index.lifecycle.rollover_alias` settings to be configured automatically when you create the index (executing the steps in the order you posted would render the `timeseries-000001` index as unmanaged by ILM as the said `index.lifecycle...` settings are not configured for the index, but only for future indices that match the template index pattern).  
Otherwise, with the steps order you provided, there needs to be an extra step to associate the `timeseries-policy` and the rollover alias with the `timeseries-000001` index using the [update indices settings API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-update-settings.html).

The order of steps should be:

1. create index lifecycle policy
2. create index template that configures the `lifecycle.name` and `lifecycle.rollover_alias` settings
3. create the index with the alias configuration

We recognised some of the challenges associated with alias management and the `is_write_index` configuration and we developed [data streams](https://www.elastic.co/guide/en/elasticsearch/reference/current/set-up-a-data-stream.html) which I see you are already using for other indices.

---

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [December 31, 2020, 1:26am UTC](https://discuss.elastic.co/t/sanity-check-on-ilm/259306/3 "2020-12-31T01:26:50Z")

</div>

with regard to order: absolutely! of course you need to create the template first! My bad.

I tried to edit the original to fix this but I got a permission error when I tried to save.

R

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 28, 2021, 1:26am UTC](https://discuss.elastic.co/t/sanity-check-on-ilm/259306/4 "2021-01-28T01:26:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
