पाठ 20 / 25

Aliases, ILM and Data Streams

Stable names and automatic housekeeping.

Managing indices over time

An alias is a stable name that points at one or more indices; applications use the alias, so you can swap the underlying index atomically with _aliases actions. For time-series data (logs, metrics, events), index lifecycle management (ILM) policies roll over to a new index when the current one reaches a size, age or document count, then move older indices through phases (hot, warm, cold, frozen) and finally delete them. Data streams package this pattern: an index template with data_stream enabled, append-only writes requiring an @timestamp field, and hidden backing indices that roll over automatically. Newer versions also offer a simpler data stream lifecycle as an alternative to ILM; check the docs for your version.

An ILM policy and a data stream template

Kibana Dev Tools console syntax; send the same requests with curl or a client library.

PUT /_ilm/policy/logs-30d
{
  "policy": {
    "phases": {
      "hot": {
        "actions": {
          "rollover": { "max_primary_shard_size": "50gb", "max_age": "1d" }
        }
      },
      "delete": {
        "min_age": "30d",
        "actions": { "delete": {} }
      }
    }
  }
}

PUT /_index_template/app-logs
{
  "index_patterns": [ "app-logs*" ],
  "data_stream": {},
  "template": {
    "settings": { "index.lifecycle.name": "logs-30d" },
    "mappings": {
      "properties": {
        "@timestamp": { "type": "date" },
        "level":      { "type": "keyword" },
        "message":    { "type": "text" }
      }
    }
  }
}

# the first write creates the data stream
POST /app-logs/_doc
{ "@timestamp": "2026-10-01T12:00:00Z", "level": "error", "message": "payment timeout" }

Notebooks on a shelf

You write in today's notebook (the write index). When it is full or a day old you start a new one, older notebooks move to cheaper shelves, and after 30 days they are shredded. The alias is the label "current logs" on the shelf.

त्वरित जाँच: Which field must every document in a data stream have?

  • _routing
  • @timestamp
  • id
  • version
Answer

@timestamp — Data streams are designed for time-series, append-only data.