Question about ILM

53 views
Skip to first unread message

Maria Juárez

unread,
Feb 2, 2023, 2:17:41 PM2/2/23
to Wazuh mailing list
I would like to ask what is an ILM? and is it related to Legacy templates? Is possible to assign an ILM to a Legacy template?

Julio Gasco

unread,
Feb 3, 2023, 8:18:12 AM2/3/23
to Wazuh mailing list
HI Maju,

ILM ( Index Lifecycle Management) Defines the lifecycle of your indices, You can set up policies that move your indices across different states.
For Example you can set indices in Hot State for 30 days, then move them to cold state where they can have a smaller amount of replicas, and after 60 days you Delete them.

This can be set In the index Management menu:
ev1.JPG
With setting an ILM policy you avoid your indices from filling up your wazuh-indexer server.
Rememeber that indices have the data visible in Wazuh-Dashboard, but the alerts history is retained also in the wazuh-manager (if required) so deleting the indeces does not mean loosing the data forever. It just won´t be available for visualization in Wazuh-dashboard.

You can apply ILM policies both to legacy teamplates as to compaund templates.

In the following documentation you will find some policies examples
You can always use the graphical editor when creating a new ILM instead of creating the full JSON manually.

Additionally you can find more information on ILM in the below link:

Let me know if this helps,
Regards!
Reply all
Reply to author
Forward
0 new messages