# Updating ILM / rollover aliases on existing {auditbeat, metricbeat, packetbeat ...} via API

**URL:** <https://discuss.elastic.co/t/updating-ilm-rollover-aliases-on-existing-auditbeat-metricbeat-packetbeat-via-api/210758>\
**Category:** Beats\
**Tags:** ilm-index-lifecycle-management\
**Created:** [December 5, 2019, 6:06pm UTC](https://discuss.elastic.co/t/updating-ilm-rollover-aliases-on-existing-auditbeat-metricbeat-packetbeat-via-api/210758 "2019-12-05T18:06:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![EricJohnson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericjohnson/32/53592_2.png) [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Post date:** [December 5, 2019, 6:06pm UTC](https://discuss.elastic.co/t/updating-ilm-rollover-aliases-on-existing-auditbeat-metricbeat-packetbeat-via-api/210758/1 "2019-12-05T18:06:09Z")

</div>

Greetings.

I'm interested in modifying the default ILM policy for all of my \*beat processes using the API. We need to prevent hard drives from filling up - especially after version updates. We do not want to do this over Kibana because we will have _many_ instances of ES running all over world and we need to automate the process.

I can successfully do it from scratch for a brand new index over the API. But if I try to apply a common scheme to all existing filebeat\* indices it doesn't seem to pick up the update.

Steps...

I PUT the lifecycle policy in:

> PUT /\_ilm/policy/beat\_default\_lifecycle\_policy  
> {  
> "policy": {  
> "phases": {  
> "hot": {  
> "min\_age": "0ms",  
> "actions": {  
> "rollover": {  
> "max\_size": "5gb"  
> },  
> "set\_priority": {  
> "priority": 100  
> }  
> }  
> },  
> "delete": {  
> "min\_age": "7d",  
> "actions": {  
> "delete": {}  
> }  
> }  
> }  
> }  
> }

Then apply the policy to index patterns for filebeat\*:

> PUT \_template/filebeat\_rollover\_template  
> {  
> "index\_patterns": ["filebeat\*"],  
> "settings": {  
> "number\_of\_shards": 1,  
> "number\_of\_replicas": 1,  
> "index.lifecycle.name": "beat\_default\_lifecycle\_policy",  
> "index.lifecycle.rollover\_alias": "filebeat"  
> }  
> }

The indices don't change their settings. Looking at the index _filebeat-7.4.2-2019.12.02-000001_  
says:

> "index.lifecycle.rollover\_alias": "filebeat-7.4.2"

while the index _filebeat-7.5.0-2019.12.03-000001_ shows

> "index.lifecycle.rollover\_alias": "filebeat-7.5.0"

How can I successfully update all of these rollover\_alias settings?

Thank you!

Eric

---

<div class="post-metadata">

**Author:** ![EricJohnson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericjohnson/32/53592_2.png) [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Post date:** [December 5, 2019, 9:08pm UTC](https://discuss.elastic.co/t/updating-ilm-rollover-aliases-on-existing-auditbeat-metricbeat-packetbeat-via-api/210758/3 "2019-12-05T21:08:23Z")

</div>

Another way, perhaps, to ask this question is:

How can we change the ILM settings for our \*beats by using only the API? That would work too.

Thanks again.

---

<div class="post-metadata">

**Author:** ![EricJohnson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericjohnson/32/53592_2.png) [@EricJohnson](https://discuss.elastic.co/u/EricJohnson)\
**Post date:** [December 5, 2019, 10:11pm UTC](https://discuss.elastic.co/t/updating-ilm-rollover-aliases-on-existing-auditbeat-metricbeat-packetbeat-via-api/210758/4 "2019-12-05T22:11:12Z")

</div>

See:

[Solution](https://discuss.elastic.co/t/how-to-apply-ilm-to-entire-matching-index-pattern/210784)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2020, 12:11am UTC](https://discuss.elastic.co/t/updating-ilm-rollover-aliases-on-existing-auditbeat-metricbeat-packetbeat-via-api/210758/5 "2020-01-03T00:11:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
