# Serval indices were created with different timestamp upon using new winlogbeat template

**URL:** <https://discuss.elastic.co/t/serval-indices-were-created-with-different-timestamp-upon-using-new-winlogbeat-template/288539>\
**Category:** Elasticsearch\
**Created:** [November 6, 2021, 10:03am UTC](https://discuss.elastic.co/t/serval-indices-were-created-with-different-timestamp-upon-using-new-winlogbeat-template/288539 "2021-11-06T10:03:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alaxwora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alaxwora/32/76976_2.png) [@Alaxwora](https://discuss.elastic.co/u/Alaxwora)\
**Post date:** [November 6, 2021, 10:03am UTC](https://discuss.elastic.co/t/serval-indices-were-created-with-different-timestamp-upon-using-new-winlogbeat-template/288539/1 "2021-11-06T10:03:51Z")

</div>

Hello,  
I noted serval indices were created upon using my new winlogbeat template, and I already set ILM to rollover after 30 days or upon index size reaches 10 Giga but it seems that I made a mistake.

the following screenshot shows my problem

 ![3](https://us1.discourse-cdn.com/elastic/original/3X/7/5/75d5bccfc957dfd10ae08d5538c8972e19285ee0.png)

**my winlogbeat.yml config**

```auto
output.elasticsearch.index: "test-%{[agent.version]}-%{+yyyy.MM.dd}"

setup.ilm.enabled: false
setup.template.name: "test"
setup.template.pattern: "test-*"

```

**ILM configuration**

 ![2](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ffaa0cf6099108edd553dd5ee626767a9c3ef4de.png)

**Template config**

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d573e7f4e7ab17292a658445eb66277ee8fb1b7.png)

Thank you in advance for your consideration

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 6, 2021, 4:06pm UTC](https://discuss.elastic.co/t/serval-indices-were-created-with-different-timestamp-upon-using-new-winlogbeat-template/288539/2 "2021-11-06T16:06:50Z")

</div>

> [@Alaxwora](#):
>
> ```auto
> output.elasticsearch.index: "test-%{[agent.version]}-%{+yyyy.MM.dd}"
> 
> ```

This is a reason you're getting daily indexes because you gave it a daily index name.

Did you follow the steps [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html#manage-time-series-data-without-data-streams)?

This should be pointing to the writer alias What you need to create the bootstrap index. See [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html#ilm-gs-alias-bootstrap)

Or use

`setup.ilm.rollover_alias` see below

Also you need the ILM pattern etc see [here](https://www.elastic.co/guide/en/beats/winlogbeat/current/ilm.html)

And of course these configurations need to be consistent within your winlogbeat and the template and ILM policy that you set up.

By the way I noticed you set up 21 primary shards I don't know if you're just testing but you would need to have some very extreme circumstances to use that in an effective manner.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2021, 4:07pm UTC](https://discuss.elastic.co/t/serval-indices-were-created-with-different-timestamp-upon-using-new-winlogbeat-template/288539/3 "2021-12-04T16:07:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
