# Winlogbeat configuration for index rollover

**URL:** <https://discuss.elastic.co/t/winlogbeat-configuration-for-index-rollover/359163>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 9, 2024, 10:18am UTC](https://discuss.elastic.co/t/winlogbeat-configuration-for-index-rollover/359163 "2024-05-09T10:18:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![a.gavric](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@a.gavric](https://discuss.elastic.co/u/a.gavric)\
**Post date:** [May 9, 2024, 10:18am UTC](https://discuss.elastic.co/t/winlogbeat-configuration-for-index-rollover/359163/1 "2024-05-09T10:18:06Z")

</div>

Hello Everyone we have been testing a configuration for Winlogbeat for windows event log ingestion and with the out of the box configuration of about 60 machines we have noticed that we have over 70GB of data per month now we have 3 month retention and i create an ILM policy that deletes all indexes older than 3 months but what i have also noticed as behavior is that once the index is deleted Winlogbeat re-ingests old data (im assuming that is by design) and would just like some advise on how to approach the configuration to limit the old data being ingested

Version used is Winlogbeat-oss-07.12

configuration is below:

```auto

winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h

  - name: System

  - name: Security

  - name: ForwardedEvents
    tags: [forwarded]

  - name: Windows PowerShell
    event_id: 400, 403, 600, 800

  - name: Microsoft-Windows-PowerShell/Operational
    event_id: 4103, 4104, 4105, 4106

# ====================== Elasticsearch template settings =======================

setup.template.settings:
  index.number_of_shards: 1
  #index.codec: best_compression
  #_source.enabled: false

setup.template.name: "winlogbeat"
setup.template.pattern: "winlogbeat-*"

output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["{{ elasticsearch_server }}:9200"]
  index: "winlogbeat-%{[agent.version]}-%{+yyyy.MM}"
  # Protocol - either `http` (default) or `https`.
  protocol: "https"

```

Any assistance would be most appreciated

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 9, 2024, 1:05pm UTC](https://discuss.elastic.co/t/winlogbeat-configuration-for-index-rollover/359163/2 "2024-05-09T13:05:15Z")

</div>

> [@a.gavric](#):
>
> what i have also noticed as behavior is that once the index is deleted Winlogbeat re-ingests old data (im assuming that is by design)

No, this is not how it is designed. Winlogbeat use a local file to persist its state in the form of [bookmarks](https://learn.microsoft.com/en-us/windows/win32/wes/bookmarking-events). If you stop the Winlogbeat service you can inspect this [file](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-winlogbeat-options.html#_registry_file).

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 9, 2024, 1:06pm UTC](https://discuss.elastic.co/t/winlogbeat-configuration-for-index-rollover/359163/3 "2024-05-09T13:06:45Z")

</div>

> [@a.gavric](#):
>
> advise on how to approach the configuration to limit the old data being ingested

If you have new clients coming online and want to prevent them from sending older data then add the `ignore_older` option into each event log reader. You already have it there for the `Application` reader.
