# \#ilm-index-lifecycle-management

**URL:** https://discuss.elastic.co/tag/ilm-index-lifecycle-management/28.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [ILM unable to delete old index since upgrade to 8.19.20](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 8:58am UTC](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601 "2026-09-23T08:58:47Z")

</div>

Morning Team, Since upgrading to 8.19.20, I've started getting these errors: policy \[.fleet-actions-results-ilm-policy\] for index \[.ds-.fleet-actions-results-2026.05.02-000014\] on an error step due to a transient error…

---

## [Hot/Warm/Cold phases being ignored. Data goes directly to Cold](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910)

<div class="topic-metadata">

**Author:** [@Alberto\_Martinez](https://discuss.elastic.co/u/Alberto_Martinez)\
**Replies:** 7\
**Last updated:** [September 15, 2026, 12:41pm UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910 "2026-09-15T12:41:27Z")

</div>

Hello, As the title says, all my streams share a common ILM policy but somehow it is ignored. All nodes are capable of hot/warm/cold. It is a recent setup and we don't have separate roles yet. Any pointer to wha…

---

## [Kibana Dev Tools Console does not execute full \_bulk request](https://discuss.elastic.co/t/kibana-dev-tools-console-does-not-execute-full-bulk-request/390219)

<div class="topic-metadata">

**Author:** [@Abdullah\_Hamza](https://discuss.elastic.co/u/Abdullah_Hamza)\
**Replies:** 1\
**Last updated:** [September 7, 2026, 4:30am UTC](https://discuss.elastic.co/t/kibana-dev-tools-console-does-not-execute-full-bulk-request/390219 "2026-09-07T04:30:33Z")

</div>

Description: When running a valid Elasticsearch Bulk API request in Kibana Dev Tools Console, the console does not appear to process all NDJSON operations as a single request. Example: POST /logs/\_bulk {"create":{}} {"@t…

---

## [Moving index using custom attribute](https://discuss.elastic.co/t/moving-index-using-custom-attribute/386492)

<div class="topic-metadata">

**Author:** [@doniyey](https://discuss.elastic.co/u/doniyey)\
**Replies:** 3\
**Last updated:** [May 26, 2026, 7:59am UTC](https://discuss.elastic.co/t/moving-index-using-custom-attribute/386492 "2026-05-26T07:59:27Z")

</div>

Hello everyone, I am working on a project with elasticsearch 9.4.1, where the goal is to move a specific data stream (ds) to a dedicated cold node for that data stream. Here are the nodes I have prepared: ip …

---

## [Need Help: Date-wise Index Creation with Application Using Built-in Elasticsearch and Static Index Name](https://discuss.elastic.co/t/need-help-date-wise-index-creation-with-application-using-built-in-elasticsearch-and-static-index-name/386007)

<div class="topic-metadata">

**Author:** [@Shubham\_Khodpe](https://discuss.elastic.co/u/Shubham_Khodpe)\
**Replies:** 6\
**Last updated:** [May 20, 2026, 1:24pm UTC](https://discuss.elastic.co/t/need-help-date-wise-index-creation-with-application-using-built-in-elasticsearch-and-static-index-name/386007 "2026-05-20T13:24:00Z")

</div>

\## Environment Details ### Elasticsearch (self-managed cluster on AWS) 4 Data Nodes (1 TB each) 2 Master Nodes Daily data ingestion around 300 GB (without replica) and approximately 600 GB with 1 replica Data source is…

---

## [ILM Indices Blocking Master Queue - All Operations Timeout](https://discuss.elastic.co/t/ilm-indices-blocking-master-queue-all-operations-timeout/385725)

<div class="topic-metadata">

**Author:** [@Anup\_Kumar](https://discuss.elastic.co/u/Anup_Kumar)\
**Replies:** 5\
**Last updated:** [April 2, 2026, 8:40am UTC](https://discuss.elastic.co/t/ilm-indices-blocking-master-queue-all-operations-timeout/385725 "2026-04-02T08:40:02Z")

</div>

Our ES cluster has blocked master queue for 12+ days. All cluster state change operations timeout after 30s, including: Index open operations Index delete operations ILM move commands ILM stop/start commands …

---

## [Is it possible to Downsamp to a list of keyword values!](https://discuss.elastic.co/t/is-it-possible-to-downsamp-to-a-list-of-keyword-values/385393)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 1\
**Last updated:** [March 15, 2026, 3:37am UTC](https://discuss.elastic.co/t/is-it-possible-to-downsamp-to-a-list-of-keyword-values/385393 "2026-03-15T03:37:21Z")

</div>

Hello everyone, I have a time series data stream (TSDS) set up with downsampling configured via ILM (e.g. downsample to 1d intervals daily). The index template is correctly marked with time\_series\_dimension. My data in…

---

## [Downsampling only works one time](https://discuss.elastic.co/t/downsampling-only-works-one-time/375708)

<div class="topic-metadata">

**Author:** [@bstinchcomb](https://discuss.elastic.co/u/bstinchcomb)\
**Replies:** 1\
**Last updated:** [March 13, 2026, 2:43pm UTC](https://discuss.elastic.co/t/downsampling-only-works-one-time/375708 "2026-03-13T14:43:22Z")

</div>

Hello, I am running into an issue with elasticsearch where downsampling will only run a single time, and then subsequent runs seems to just create an empty index. I have tried several different docker versions and still …

---

## [Clarification about frozen data on k8s](https://discuss.elastic.co/t/clarification-about-frozen-data-on-k8s/385397)

<div class="topic-metadata">

**Author:** [@Cario](https://discuss.elastic.co/u/Cario)\
**Replies:** 0\
**Last updated:** [March 10, 2026, 3:51pm UTC](https://discuss.elastic.co/t/clarification-about-frozen-data-on-k8s/385397 "2026-03-10T15:51:13Z")

</div>

Hello everyone, I am new to the forum and basically self-taught, so I apologize in advance if I lack some basic knowledge. Thank you for your understanding. The elastic cluster works on a k8s cluster as pods, but readi…

---

## [Same \_id ends up duplicated across rollover indices behind a write alias — can this be prevented via template/ILM?](https://discuss.elastic.co/t/same-id-ends-up-duplicated-across-rollover-indices-behind-a-write-alias-can-this-be-prevented-via-template-ilm/385348)

<div class="topic-metadata">

**Author:** [@juan\_ma\_tejada](https://discuss.elastic.co/u/juan_ma_tejada)\
**Replies:** 1\
**Last updated:** [March 4, 2026, 7:34pm UTC](https://discuss.elastic.co/t/same-id-ends-up-duplicated-across-rollover-indices-behind-a-write-alias-can-this-be-prevented-via-template-ilm/385348 "2026-03-04T19:34:01Z")

</div>

Hi all, I’m indexing documents into Elasticsearch using a deterministic \_id (SHA1 of email + normalized\_context). I write to an alias that uses ILM rollover, so over time it creates backing indices like: data-000073 …

---

## [Filebeat re-ingesting old logs after pod restart (ECK on GKE) - ignore\_older not working](https://discuss.elastic.co/t/filebeat-re-ingesting-old-logs-after-pod-restart-eck-on-gke-ignore-older-not-working/384328)

<div class="topic-metadata">

**Author:** [@Marwan\_Ghonem](https://discuss.elastic.co/u/Marwan_Ghonem)\
**Replies:** 2\
**Last updated:** [January 2, 2026, 3:27pm UTC](https://discuss.elastic.co/t/filebeat-re-ingesting-old-logs-after-pod-restart-eck-on-gke-ignore-older-not-working/384328 "2026-01-02T15:27:52Z")

</div>

Problem Filebeat is repeatedly re-ingesting old logs (4-15 days old) causing previously deleted indices to be recreated. Environment Filebeat version: 7.10.1 ADeployment: ECK (Elastic Cloud on Kubernetes) DaemonS…

---

## [ILM policy for indices from APM server](https://discuss.elastic.co/t/ilm-policy-for-indices-from-apm-server/384133)

<div class="topic-metadata">

**Author:** [@Narek\_Martirosyan](https://discuss.elastic.co/u/Narek_Martirosyan)\
**Replies:** 2\
**Last updated:** [December 19, 2025, 7:48am UTC](https://discuss.elastic.co/t/ilm-policy-for-indices-from-apm-server/384133 "2025-12-19T07:48:45Z")

</div>

Hi, I’m running Elasticsearch 9.0.3 managed by ECK on AKS, and I’m seeing persistent high JVM heap usage on my warm nodes. Cluster topology 3 × master nodes 2 × hot data nodes 2 × warm data nodes Persistent…

---

## [ILM vs routing for growing vector database with separate clients](https://discuss.elastic.co/t/ilm-vs-routing-for-growing-vector-database-with-separate-clients/383962)

<div class="topic-metadata">

**Author:** [@Pablito77](https://discuss.elastic.co/u/Pablito77)\
**Replies:** 5\
**Last updated:** [December 10, 2025, 5:56pm UTC](https://discuss.elastic.co/t/ilm-vs-routing-for-growing-vector-database-with-separate-clients/383962 "2025-12-10T17:56:39Z")

</div>

Hello, I use elasticsearch as a vector db for 1024 dim vectors. My initial setup would be around 20 million vectors, but it may increase to 100 milion vectors over time. However i always prefilter the vector search to a…

---

## [Using the frozen tier with Elastic Cloud and ILM policies](https://discuss.elastic.co/t/using-the-frozen-tier-with-elastic-cloud-and-ilm-policies/383342)

<div class="topic-metadata">

**Author:** [@javierE](https://discuss.elastic.co/u/javierE)\
**Replies:** 4\
**Last updated:** [November 19, 2025, 4:25pm UTC](https://discuss.elastic.co/t/using-the-frozen-tier-with-elastic-cloud-and-ilm-policies/383342 "2025-11-19T16:25:41Z")

</div>

Hi all, I’m evaluating the frozen tier functionality in Elastic Cloud deployment, aiming to keep around ten years of historical data available for occasional analysis and compliance purposes. Given that we plan to ret…

---

## [ILMs in cluster not performing rollover when conditions are met](https://discuss.elastic.co/t/ilms-in-cluster-not-performing-rollover-when-conditions-are-met/383369)

<div class="topic-metadata">

**Author:** [@Natalia\_Mellino](https://discuss.elastic.co/u/Natalia_Mellino)\
**Replies:** 9\
**Last updated:** [November 18, 2025, 6:30pm UTC](https://discuss.elastic.co/t/ilms-in-cluster-not-performing-rollover-when-conditions-are-met/383369 "2025-11-18T18:30:29Z")

</div>

Hello! We have an Elasticsearch cluster running 8.19.3 version (master, hot, cold and coordinating nodes) and we’re seeing some issues regarding our ILM policies. We are using data streams so we’ve configured several IL…

---

## [Not able to delete indices which are in closed state using ILM](https://discuss.elastic.co/t/not-able-to-delete-indices-which-are-in-closed-state-using-ilm/383443)

<div class="topic-metadata">

**Author:** [@Elastic04](https://discuss.elastic.co/u/Elastic04)\
**Replies:** 7\
**Last updated:** [November 14, 2025, 3:51pm UTC](https://discuss.elastic.co/t/not-able-to-delete-indices-which-are-in-closed-state-using-ilm/383443 "2025-11-14T15:51:02Z")

</div>

I am not able to delete indices which are in closed state using ILM. Is there any other way to do it?

---

## [Requesting feedback on benchmark results: Hot vs Frozen(Cache) vs Frozen(No-Cache)](https://discuss.elastic.co/t/requesting-feedback-on-benchmark-results-hot-vs-frozen-cache-vs-frozen-no-cache/382169)

<div class="topic-metadata">

**Author:** [@dipayans](https://discuss.elastic.co/u/dipayans)\
**Replies:** 0\
**Last updated:** [September 23, 2025, 1:34pm UTC](https://discuss.elastic.co/t/requesting-feedback-on-benchmark-results-hot-vs-frozen-cache-vs-frozen-no-cache/382169 "2025-09-23T13:34:38Z")

</div>

Hi everyone, I recently ran a set of benchmark tests to evaluate performance across Hot tier and Frozen tier searchable snapshots (with and without cache). I’d really appreciate feedback from the community to understand…

---

## [Can ES support the modification of the shard role for the ilm history index?](https://discuss.elastic.co/t/can-es-support-the-modification-of-the-shard-role-for-the-ilm-history-index/381951)

<div class="topic-metadata">

**Author:** [@EricTowns](https://discuss.elastic.co/u/EricTowns)\
**Replies:** 8\
**Last updated:** [September 18, 2025, 4:06am UTC](https://discuss.elastic.co/t/can-es-support-the-modification-of-the-shard-role-for-the-ilm-history-index/381951 "2025-09-18T04:06:00Z")

</div>

My ES cluster is currently running out of disk space. The new disks are still being purchased. I want to try my best to preserve my data, so I'm using the method of deleting replicas to cope with the current situation. T…

---

## [Logstash unable to reach Elasticsearch](https://discuss.elastic.co/t/logstash-unable-to-reach-elasticsearch/381852)

<div class="topic-metadata">

**Author:** [@piyush\_hn](https://discuss.elastic.co/u/piyush_hn)\
**Replies:** 5\
**Last updated:** [September 13, 2025, 5:35pm UTC](https://discuss.elastic.co/t/logstash-unable-to-reach-elasticsearch/381852 "2025-09-13T17:35:56Z")

</div>

Hi All, I am new to elastic stack and set it up on two instances on AWS. My main objective of this demonstration is to show that we can forward the application/machine logs to kibana dashboard. One EC2 instance is ru…

---

## [\`.tasks\` index maintenance](https://discuss.elastic.co/t/tasks-index-maintenance/381487)

<div class="topic-metadata">

**Author:** [@taskstask](https://discuss.elastic.co/u/taskstask)\
**Replies:** 0\
**Last updated:** [September 1, 2025, 1:14pm UTC](https://discuss.elastic.co/t/tasks-index-maintenance/381487 "2025-09-01T13:14:59Z")

</div>

Our .tasks index grows quite large (about 250GB a month), and I’m seeking an alternative to us manually deleting it once in a while. I have two questions: Is it still true that it’s always safe to delete this index? (…

---

## [No such indices in ElasticSearch](https://discuss.elastic.co/t/no-such-indices-in-elasticsearch/381434)

<div class="topic-metadata">

**Author:** [@levi19](https://discuss.elastic.co/u/levi19)\
**Replies:** 0\
**Last updated:** [August 29, 2025, 4:01am UTC](https://discuss.elastic.co/t/no-such-indices-in-elasticsearch/381434 "2025-08-29T04:01:31Z")

</div>

We are currently running an Elasticsearch & Kibana (8.14.3) cluster with: 3 master nodes and 6 data nodes Also, we are using Metricbeat ver 8.14.3 for monitoring the cluster ( we are enabled xpack.monitoring featur…

---

## [Lifecycle Policy](https://discuss.elastic.co/t/lifecycle-policy/381211)

<div class="topic-metadata">

**Author:** [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)\
**Replies:** 10\
**Last updated:** [August 22, 2025, 10:08pm UTC](https://discuss.elastic.co/t/lifecycle-policy/381211 "2025-08-22T22:08:22Z")

</div>

I created a lifecycle policy in Kibana and attached it to a data stream, for example: logs-system.syslog-default However, the indices it created, such as: .ds-logs-system.syslog-default-2025.08.21-000001 are still sh…

---

## [Getting error in elasticsearch while adding the policies](https://discuss.elastic.co/t/getting-error-in-elasticsearch-while-adding-the-policies/381013)

<div class="topic-metadata">

**Author:** [@mahesh.hemke24](https://discuss.elastic.co/u/mahesh.hemke24)\
**Replies:** 0\
**Last updated:** [August 13, 2025, 4:04pm UTC](https://discuss.elastic.co/t/getting-error-in-elasticsearch-while-adding-the-policies/381013 "2025-08-13T16:04:47Z")

</div>

Getting below errors {"@timestamp":"2025-08-13T08:41:40.028Z", "log.level": "INFO", "message":"\\\[controller/5551\\\] \\\[Main.cc@176\\\] ML controller exiting", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"…

---

## [Duplicate records in Elasticsearch](https://discuss.elastic.co/t/duplicate-records-in-elasticsearch/380625)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 12\
**Last updated:** [August 10, 2025, 11:31am UTC](https://discuss.elastic.co/t/duplicate-records-in-elasticsearch/380625 "2025-08-10T11:31:09Z")

</div>

Hello I'm facing an issue with duplicate records in my index on rollover. I thought using rollover alias would let only one index to be "write" index which is supposed to not let any batch of records being indexed t…

---

## [Title: Implementing S3 Buffer Layer for Elasticsearch - Looking for Community Feedback](https://discuss.elastic.co/t/title-implementing-s3-buffer-layer-for-elasticsearch-looking-for-community-feedback/380778)

<div class="topic-metadata">

**Author:** [@Hadj\_Hassine\_Younes](https://discuss.elastic.co/u/Hadj_Hassine_Younes)\
**Replies:** 11\
**Last updated:** [August 7, 2025, 4:02pm UTC](https://discuss.elastic.co/t/title-implementing-s3-buffer-layer-for-elasticsearch-looking-for-community-feedback/380778 "2025-08-07T16:02:43Z")

</div>

Hi everyone, We're evaluating an S3-based buffer architecture to address circuit breaker issues and reduce costs in our ECK deployment. Would really appreciate insights from anyone who's implemented similar patterns. T…

---

## [Version 9 Frozen Indices](https://discuss.elastic.co/t/version-9-frozen-indices/380691)

<div class="topic-metadata">

**Author:** [@Tal\_Hayun](https://discuss.elastic.co/u/Tal_Hayun)\
**Replies:** 2\
**Last updated:** [August 2, 2025, 1:54pm UTC](https://discuss.elastic.co/t/version-9-frozen-indices/380691 "2025-08-02T13:54:22Z")

</div>

In version 9.0 release notes it says - "Remove the ability to read frozen indices" Does that include indices in frozen ILM phase?

---

## [Is it possible to delaying shrink and forcemerge lifecycle steps in hot tier](https://discuss.elastic.co/t/is-it-possible-to-delaying-shrink-and-forcemerge-lifecycle-steps-in-hot-tier/380634)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 3\
**Last updated:** [August 1, 2025, 12:32pm UTC](https://discuss.elastic.co/t/is-it-possible-to-delaying-shrink-and-forcemerge-lifecycle-steps-in-hot-tier/380634 "2025-08-01T12:32:01Z")

</div>

Hi All, Need some information about setting up ILM policy like below for time series data stream. "hot": { "min\_age": "0ms", "actions": { "rollover": { "max\_age": "10d", …

---

## [29th July INDEX is in UNASSIGNED status and it didn't create for 30th and 31st July](https://discuss.elastic.co/t/29th-july-index-is-in-unassigned-status-and-it-didnt-create-for-30th-and-31st-july/380621)

<div class="topic-metadata">

**Author:** [@Sangram\_Dash](https://discuss.elastic.co/u/Sangram_Dash)\
**Replies:** 6\
**Last updated:** [July 31, 2025, 3:59pm UTC](https://discuss.elastic.co/t/29th-july-index-is-in-unassigned-status-and-it-didnt-create-for-30th-and-31st-july/380621 "2025-07-31T15:59:52Z")

</div>

myapp-2025.07.29 is in UNASSIGNED status This index is not created for last two days is there a way to fix without deleteing this messed up index. \[root@elkhost5 ~\]# grep -i translog /var/log/elk/es.log \[2025-07-31T07:…

---

## [Infoblox - index username to create Dashboard](https://discuss.elastic.co/t/infoblox-index-username-to-create-dashboard/380525)

<div class="topic-metadata">

**Author:** [@wabd](https://discuss.elastic.co/u/wabd)\
**Replies:** 5\
**Last updated:** [July 31, 2025, 4:19am UTC](https://discuss.elastic.co/t/infoblox-index-username-to-create-dashboard/380525 "2025-07-31T04:19:57Z")

</div>

Hi, i am new user of the plateform, my teammate have implemented ELK and Kibana to get log from our appliances. I am creating dashboards but i have noticed that username is not indexed yet. as a consequence, i can't s…

---

## [Elasticsearch Performance Issue After Adding Second Node](https://discuss.elastic.co/t/elasticsearch-performance-issue-after-adding-second-node/380138)

<div class="topic-metadata">

**Author:** [@SalehEska](https://discuss.elastic.co/u/SalehEska)\
**Replies:** 3\
**Last updated:** [July 16, 2025, 9:07am UTC](https://discuss.elastic.co/t/elasticsearch-performance-issue-after-adding-second-node/380138 "2025-07-16T09:07:38Z")

</div>

Hello everyone, I’m currently experiencing a performance issue with my Elasticsearch cluster. Previously, I was using a single-node setup, and all queries—especially \_count—were working quickly and reliably. Recently, …

[Next page](https://discuss.elastic.co/tag/ilm-index-lifecycle-management/28.md?match_all_tags=true&page=1&tags%5B%5D=ilm-index-lifecycle-management)
