# Setup.template.name with space when using setup.ilm.enabled: auto

**URL:** <https://discuss.elastic.co/t/setup-template-name-with-space-when-using-setup-ilm-enabled-auto/201657>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 30, 2019, 2:22pm UTC](https://discuss.elastic.co/t/setup-template-name-with-space-when-using-setup-ilm-enabled-auto/201657 "2019-09-30T14:22:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![McQueen2063](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mcqueen2063/32/53186_2.png) [@McQueen2063](https://discuss.elastic.co/u/McQueen2063)\
**Post date:** [September 30, 2019, 2:22pm UTC](https://discuss.elastic.co/t/setup-template-name-with-space-when-using-setup-ilm-enabled-auto/201657/1 "2019-09-30T14:22:53Z")

</div>

Hello everyone,

I wonder whether I tripped over a bug or whether I might misunderstand the documentation.  
I'm using filebeat 7.3.2 and want to use ilm, but also create indices based on my environments.

config settings:

```auto
    setup.ilm.enabled: auto
    setup.ilm.policy_name: "ilm-policy-filebeat-${cluster_name}"
    setup.ilm.rollover_alias: "filebeat-${cluster_name}"
    setup.ilm.pattern: "{+yyyy.MM.dd}-000001"
    setup.ilm.check_exists: false
    setup.ilm.overwrite: true
    output.elasticsearch:
      hosts: 'https://elasticsearch.local:443'

```

The above variable ${cluster\_name} expands to testing-europe.

In the startup log I can see this:

```auto
INFO [index-management] idxmgmt/std.go:178 Set output.elasticsearch.index to 'filebeat-testing-europe' as ILM is enabled.
2019-09-30T14:06:27.870Z INFO elasticsearch/client.go:743 Attempting to connect to Elasticsearch version 7.3.0
2019-09-30T14:06:27.915Z INFO [index-management] idxmgmt/std.go:252 Auto ILM enable success.
2019-09-30T14:06:28.410Z INFO [index-management] idxmgmt/std.go:265 ILM policy successfully loaded.
2019-09-30T14:06:28.410Z INFO [index-management] idxmgmt/std.go:394 Set setup.template.name to '{filebeat-testing-europe {+yyyy.MM.dd}-000001}' as
ILM is enabled.
2019-09-30T14:06:28.410Z INFO [index-management] idxmgmt/std.go:399 Set setup.template.pattern to 'filebeat-testing-europe-*' as ILM is enabled.
2019-09-30T14:06:28.410Z INFO [index-management] idxmgmt/std.go:433 Set settings.index.lifecycle.rollover_alias in template to {filebeat-testing-eu
rope {+yyyy.MM.dd}-000001} as ILM is enabled.
2019-09-30T14:06:28.411Z INFO [index-management] idxmgmt/std.go:437 Set settings.index.lifecycle.name in template to {ilm-policy-filebeat-testing-e
urope {"policy":{"phases":{"hot":{"actions":{"rollover":{"max_age":"30d","max_size":"50gb"}}}}}}} as ILM is enabled.
2019-09-30T14:06:28.489Z INFO template/load.go:108 Try loading template filebeat-testing-europe to Elasticsearch
2019-09-30T14:06:28.804Z INFO template/load.go:100 template with name 'filebeat-testing-europe' loaded.
2019-09-30T14:06:28.804Z INFO [index-management] idxmgmt/std.go:289 Loaded index template.
2019-09-30T14:06:28.814Z INFO [index-management] idxmgmt/std.go:298 Write alias exists already

```

It seems like the setup.template.name is a concatenation of setup.ilm.rollover\_alias and setup.ilm.pattern but with a space in between.  
This looks wrong, doesn't it?

In kibana I can see an index filebeat-testing-europe and also my ilm policy named ilm-policy-filebeat-testing-europe.  
However, there are no indices attached to the policy. Which makes somewhat sense, because filebeat decided to match on filebeat-testing-europe-\*, but the index is just named filebeat-testing-europe.  
hm...  
so... according to the docs this should just work, but it doesn't. What am I doing wrong here?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2019, 2:22pm UTC](https://discuss.elastic.co/t/setup-template-name-with-space-when-using-setup-ilm-enabled-auto/201657/2 "2019-10-28T14:22:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
