# Use elasticsearch index rollover policy with logstash

**URL:** <https://discuss.elastic.co/t/use-elasticsearch-index-rollover-policy-with-logstash/250504>\
**Category:** Logstash\
**Tags:** ilm-index-lifecycle-management\
**Created:** [September 30, 2020, 12:53pm UTC](https://discuss.elastic.co/t/use-elasticsearch-index-rollover-policy-with-logstash/250504 "2020-09-30T12:53:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohamed\_Saeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohamed_saeed/32/75982_2.png) [@Mohamed\_Saeed](https://discuss.elastic.co/u/Mohamed_Saeed)\
**Post date:** [September 30, 2020, 12:53pm UTC](https://discuss.elastic.co/t/use-elasticsearch-index-rollover-policy-with-logstash/250504/1 "2020-09-30T12:53:04Z")

</div>

I'm using elasticsearch and logstash version `7.3.0`

I'm using logstash to output all logs to elasticsearch. Now I'm trying to use the rollover policy to delete indexes older than 3 days.

I defined policy in elasticsearch named `hamada-7.3.0`

```auto
{
    "policy": {
        "phases": {
            "hot": {
                "min_age": "0ms",
                "actions": {
                    "rollover": {
                        "max_age": "1d",
                        "max_size": "30gb"
                    }
                }
            },
            "delete": {
                "min_age": "3d",
                "actions": {
                    "delete": {}
                }
            }
        }
    }
}

```

I have an index template, here is its setting:

```auto
{
  "hamada" : {
    "order" : 1,
    "index_patterns" : [
      "hamada*"
    ],
    "settings" : {
      "index" : {
        "lifecycle" : {
          "name" : "hamada-7.3.0",
          "rollover_alias" : "hamada"
        },
...
...

```

Now I want logstash to use an index that is created using `hamada` template and is managed by `hamada-7.3.0` rollover policy

Here is my logstash output:

```auto
    output {
      elasticsearch {
        hosts => "elasticsearch-master:9200"
        template_name => "hamada"
        ilm_enabled => "true"
        ilm_policy => "hamada-7.3.0"
        ilm_rollover_alias => "hamada"
        ilm_pattern => "%{+yyyy.MM.dd}-000001"
        codec => json {
                  charset => "ISO-8859-1"
        }
      }

```

**The expected behaviour** is when logstash push to an index, it uses ilm configurations. i.e. it pushes logs to an index that follows this pattern `hamada-%{+yyyy.MM.dd}-000001` and is managed/controlled by rollover policy.

**What actually happens** , the created index is named `hamada`. There is no data or number in the name. and the policy is not applied to it.

**So** how can I create an index using rollover policy and index template using logstash?

---

<div class="post-metadata">

**Author:** ![Mohamed\_Saeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohamed_saeed/32/75982_2.png) [@Mohamed\_Saeed](https://discuss.elastic.co/u/Mohamed_Saeed)\
**Post date:** [October 4, 2020, 1:13pm UTC](https://discuss.elastic.co/t/use-elasticsearch-index-rollover-policy-with-logstash/250504/2 "2020-10-04T13:13:01Z")

</div>

We tried the following config and it worked

```auto
    output {
      elasticsearch {
        hosts => "elasticsearch-master:9200"
        ilm_enabled => "true"
        ilm_policy => "hamada-7.3.0"
        ilm_rollover_alias => "hamada-7.3.0"
        codec => json {
                  charset => "ISO-8859-1"
        }
      }
    }

```

I tried it before and it didn't work. Now it is working. I don't know what was the problem actually!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2020, 1:13pm UTC](https://discuss.elastic.co/t/use-elasticsearch-index-rollover-policy-with-logstash/250504/3 "2020-11-01T13:13:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
