You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Elasticsearch ILM滚动索引,按日期前缀+大小创建分片索引?

实现按日+大小滚动的Elasticsearch索引配置方案

1. 创建索引生命周期管理(ILM)策略

先定义触发滚动的规则,当单索引大小超过10GB时自动滚动:

PUT _ilm/policy/myindex_rollover_policy
{
  "policy": {
    "phases": {
      "hot": {
        "actions": {
          "rollover": {
            "max_size": "10gb"
          }
        }
      }
    }
  }
}

2. 创建索引模板

绑定ILM策略,指定索引前缀、别名及映射规则:

PUT _index_template/myindex_template
{
  "index_patterns": ["myindex-*"],
  "template": {
    "settings": {
      "index.lifecycle.name": "myindex_rollover_policy",
      "index.lifecycle.rollover_alias": "myindex_write",
      "index.number_of_shards": 3,
      "index.number_of_replicas": 1
    },
    "mappings": {
      "properties": {
        // 根据你的实际数据结构定义字段映射,示例:
        "timestamp": {"type": "date"},
        "content": {"type": "text"}
      }
    }
  },
  "priority": 100
}
  • index_patterns匹配所有myindex-开头的索引
  • rollover_alias是Logstash写入的入口,ILM会自动维护该别名指向当前可写索引

3. 初始化第一个可写索引

手动创建当日的第一个索引并关联别名:

PUT myindex-2024.05.20-1
{
  "aliases": {
    "myindex_write": {
      "is_write_index": true
    }
  }
}

替换日期为当前日期,后续ILM会自动生成myindex-2024.05.20-2、myindex-2024.05.21-1等格式的索引。

4. 修改Logstash输出配置

将原动态索引名改为写入别名:

output {
  elasticsearch {
    hosts => ["http://your-es-host:9200"]
    index => "myindex_write"
    // 如有认证需求,添加以下配置
    // user => "elastic"
    // password => "your-password"
  }
}

此后Logstash持续写入别名指向的索引,达到10GB阈值时ILM自动创建新索引并切换别名。

5. 验证配置

  • 查看ILM策略:GET _ilm/policy/myindex_rollover_policy
  • 查看索引模板:GET _index_template/myindex_template
  • 查看别名状态:GET _alias/myindex_write
  • 监控索引大小,确认达到10GB时是否触发滚动

注意事项

  • 确保Elasticsearch版本在6.6及以上(支持ILM)
  • 可根据需求在ILM策略中添加warm/cold阶段,实现数据归档或删除逻辑

内容的提问来源于stack exchange,提问作者user411906

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 03:50:28