# Shipping logs to s3 after end of index lifecycle

**URL:** <https://discuss.elastic.co/t/shipping-logs-to-s3-after-end-of-index-lifecycle/240238>\
**Category:** Elasticsearch\
**Tags:** ilm-index-lifecycle-management\
**Created:** [July 8, 2020, 12:08am UTC](https://discuss.elastic.co/t/shipping-logs-to-s3-after-end-of-index-lifecycle/240238 "2020-07-08T00:08:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramiriskis](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@ramiriskis](https://discuss.elastic.co/u/ramiriskis)\
**Post date:** [July 8, 2020, 12:08am UTC](https://discuss.elastic.co/t/shipping-logs-to-s3-after-end-of-index-lifecycle/240238/1 "2020-07-08T00:08:56Z")

</div>

Hi! My team has a managed elastic instance and we are currently shipping our logs to it. The created indices go through the log life cycle process (hot, warm, cold) as specified in the docs.

My issue is that instead of deleting them after the end of this life cycle, I would like to ship them to an AWS s3 instance for indefinite storage. Would this be possible to do from the Elastic/Kibana platform? When in the life cycle of the indices is not important to me (they can be sent out as soon as they get to elastic) but I would like to use the platform for this purpose. Any suggestions?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 8, 2020, 12:14am UTC](https://discuss.elastic.co/t/shipping-logs-to-s3-after-end-of-index-lifecycle/240238/2 "2020-07-08T00:14:22Z")

</div>

That's not something that ILM does at this stage. It might be worth creating a GitHub issue as a feature request so we can gauge support for it.

---

<div class="post-metadata">

**Author:** ![ramiriskis](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@ramiriskis](https://discuss.elastic.co/u/ramiriskis)\
**Post date:** [July 8, 2020, 12:17am UTC](https://discuss.elastic.co/t/shipping-logs-to-s3-after-end-of-index-lifecycle/240238/3 "2020-07-08T00:17:14Z")

</div>

Thank you for the quick answer! Would you know if there are other kibana or filebeat tools that would allow me to do this? I will create a Github issue unless there's any workaround for this. Willing to look at any alternatives within the stack.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 8, 2020, 12:18am UTC](https://discuss.elastic.co/t/shipping-logs-to-s3-after-end-of-index-lifecycle/240238/4 "2020-07-08T00:18:05Z")

</div>

You might be able to do something with Logstash, but it's nothing out-of-the-box.

---

<div class="post-metadata">

**Author:** ![ramiriskis](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@ramiriskis](https://discuss.elastic.co/u/ramiriskis)\
**Post date:** [July 8, 2020, 12:18am UTC](https://discuss.elastic.co/t/shipping-logs-to-s3-after-end-of-index-lifecycle/240238/5 "2020-07-08T00:18:25Z")

</div>

Got it, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2020, 12:18am UTC](https://discuss.elastic.co/t/shipping-logs-to-s3-after-end-of-index-lifecycle/240238/6 "2020-08-05T00:18:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
