# Simple question about Index Rollover

**URL:** <https://discuss.elastic.co/t/simple-question-about-index-rollover/327999>\
**Category:** Kibana\
**Tags:** ilm-index-lifecycle-management\
**Created:** [March 18, 2023, 5:38pm UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999 "2023-03-18T17:38:41Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mark\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_s/32/98686_2.png) [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Post date:** [March 18, 2023, 5:38pm UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999/1 "2023-03-18T17:38:41Z")

</div>

I have a simple policy for index rollover every day (or every 1gb). I use an index template -\> index pattern-\>index alias (see bellow).

However it does not seem to rotate. Any ideas why (or how to test it? E.g if I send \_rollover to the index\_alias will that force the rotation even if the requirements are not met?)

Here is how I created it:

1. I first pointed logstash to the alias: index\_from\_logstash\_test\_alias
2. I created the index template: index\_template (with index pattern index\_from\_logstash\_test\_alias\* )
3. Bootstrap index with  
Bootstrap index:

```auto
PUT index_from_logstash_test_alias-000001
{
  "aliases": {
    "index_from_logstash_test_alias": {
      "is_write_index": true
    }
  }
}

```

Some more info if needed:

```auto

PUT _index_template/test_template
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "testindexpolicy",
          "rollover_alias": "index_from_logstash_test_alias"
        },
        "number_of_replicas": "0"
      }
    },
    "mappings": {
      "properties": {
        "@version": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "@timestamp": {
          "type": "date"
        },
        "app_server": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "app_server2": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        }
      }
    },
    "aliases": {
      "test-search-all": {}
    }
  },
  "index_patterns": [
    "index_from_logstash_test_alias*"
  ]
}

```

And the policy:

```auto
{
  "testindexpolicy" : {
    "version" : 1,
    "modified_date" : "2023-03-17T12:08:04.639Z",
    "policy" : {
      "phases" : {
        "hot" : {
          "min_age" : "0ms",
          "actions" : {
            "set_priority" : {
              "priority" : 100
            },
            "rollover" : {
              "max_primary_shard_size" : "1gb",
              "max_age" : "1d"
            }
          }
        }
      }
    },
    "in_use_by" : {
      "indices" : [],
      "data_streams" : [],
      "composable_templates" : [
        "test_template"
      ]
    }

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 19, 2023, 12:57am UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999/5 "2023-03-19T00:57:45Z")

</div>

> [@Mark\_S](#):
>
> `PUT index_from_logstash_test_alias-000001`

What is the output of

`GET index_from_logstash_test_alias-000001/_ilm/explain`

The other thing I see ... not sure if it is a typo

In the template

```auto
        "lifecycle": {
          "name": "Testindexpolicy", <!--- Capitialized

```

And the policy:

```auto
{
  "testindexpolicy" : { <!--- Not Capitalized

```

---

<div class="post-metadata">

**Author:** ![Mark\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_s/32/98686_2.png) [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Post date:** [March 19, 2023, 4:00pm UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999/6 "2023-03-19T16:00:36Z")

</div>

yep that was a typo...Thanks - I corrected it so not to confuse others...

But the \_ilm/explain command returned something interesting: "managed" : false"

So I double-checked the template to make sure that "rollover\_alias" is pointing towards the correct alias. And is indeed index\_from\_logstash\_test\_alias. Also the index pattern seems ok... Maybe I am missing something ?

Here is also the output from GET /\_alias/index\_from\_logstash\_test\_alias:

```auto
{
  "index_from_logstash_test_alias-000001" : {
    "aliases" : {
      "index_from_logstash_test_alias" : {
        "is_write_index" : true
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![jba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jba/32/118482_2.png) [@jba](https://discuss.elastic.co/u/jba)\
**Post date:** [March 19, 2023, 4:37pm UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999/7 "2023-03-19T16:37:12Z")

</div>

I am new to this Elastic thing so I could be wrong...

I think you should start over and deploy stuff in this order:

1. The ILM policy
2. The Index Template (with the index pattern and a reference to the policy)
3. The index itself (with the bootstrapping or maybe not)

If you are lucky, the system will see that your template has an index pattern that matches your new index, pick it, and use the referenced policy. If you are not so lucky, try adding a ridiculous high priority (999) to your template so it has a better chance of getting matched and picked.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 19, 2023, 5:51pm UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999/8 "2023-03-19T17:51:05Z")

</div>

> [@Mark\_S](#):
>
> ```auto
> "index_patterns": [
> "index_from_logstash_test_alias*"
> 
> ]
> 
> ```

change to

```auto
  "index_patterns": [
    "index_from_logstash_test_alias-*"
  ]

```

> [@Mark\_S](#):
>
> But the \_ilm/explain command returned something interesting: "managed" : false"

then try to rollover your alias

`POST index_from_logstash_test_alias/_rollover`

and then look at `_ilm/explain` ... and post the full output not just a single line.

---

<div class="post-metadata">

**Author:** ![Mark\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_s/32/98686_2.png) [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Post date:** [March 20, 2023, 8:07am UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999/9 "2023-03-20T08:07:19Z")

</div>

Good idea Stephen, thanks. However I already had (in another cluster) a similar index rotation policy that worked fine with `"index_from_logstash_test_alias*"`

So I tried this: I directly tried  
`POST index_from_logstash_test_alias/_rollover` and it worked!  
So after this \_ilm\_explain indicated that a new index is created and is managed by the policy index\_from\_logstash\_test\_alias-000002  
(yet index\_from\_logstash\_test\_alias-000001 is still not managed). So I guess the next rollover will occur automatically after one day.

I am not sure what was the problem - maybe bootstraping the first index should have been done via the template

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2023, 8:07am UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999/10 "2023-04-17T08:07:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
