# Aliases, ILM and Data Streams — Elasticsearch

Source: https://www.skillbyai.com/en/elasticsearch/o-lifecycle

> Stable names and automatic housekeeping.

## Managing indices over time

An **alias** is a stable name that points at one or more indices; applications use the alias, so you can swap the underlying index atomically with `_aliases` actions. For time-series data (logs, metrics, events), **index lifecycle management (ILM)** policies roll over to a new index when the current one reaches a size, age or document count, then move older indices through phases (hot, warm, cold, frozen) and finally delete them. **Data streams** package this pattern: an index template with `data_stream` enabled, append-only writes requiring an `@timestamp` field, and hidden backing indices that roll over automatically. Newer versions also offer a simpler data stream lifecycle as an alternative to ILM; check the docs for your version.

## An ILM policy and a data stream template

Kibana Dev Tools console syntax; send the same requests with curl or a client library.

```http
PUT /_ilm/policy/logs-30d
{
  "policy": {
    "phases": {
      "hot": {
        "actions": {
          "rollover": { "max_primary_shard_size": "50gb", "max_age": "1d" }
        }
      },
      "delete": {
        "min_age": "30d",
        "actions": { "delete": {} }
      }
    }
  }
}

PUT /_index_template/app-logs
{
  "index_patterns": [ "app-logs*" ],
  "data_stream": {},
  "template": {
    "settings": { "index.lifecycle.name": "logs-30d" },
    "mappings": {
      "properties": {
        "@timestamp": { "type": "date" },
        "level":      { "type": "keyword" },
        "message":    { "type": "text" }
      }
    }
  }
}

# the first write creates the data stream
POST /app-logs/_doc
{ "@timestamp": "2026-10-01T12:00:00Z", "level": "error", "message": "payment timeout" }
```

## Notebooks on a shelf

You write in today's notebook (the write index). When it is full or a day old you start a new one, older notebooks move to cheaper shelves, and after 30 days they are shredded. The alias is the label "current logs" on the shelf.

**Quiz:** Which field must every document in a data stream have?

- [ ] _routing
- [x] @timestamp
- [ ] id
- [ ] version

*Answer:* @timestamp. Data streams are designed for time-series, append-only data.
