如何配置Elasticsearch ILM滚动索引,按日期前缀+大小创建分片索引?
实现按日+大小滚动的Elasticsearch索引配置方案
1. 创建索引生命周期管理(ILM)策略
先定义触发滚动的规则,当单索引大小超过10GB时自动滚动:
PUT _ilm/policy/myindex_rollover_policy { "policy": { "phases": { "hot": { "actions": { "rollover": { "max_size": "10gb" } } } } } }
2. 创建索引模板
绑定ILM策略,指定索引前缀、别名及映射规则:
PUT _index_template/myindex_template { "index_patterns": ["myindex-*"], "template": { "settings": { "index.lifecycle.name": "myindex_rollover_policy", "index.lifecycle.rollover_alias": "myindex_write", "index.number_of_shards": 3, "index.number_of_replicas": 1 }, "mappings": { "properties": { // 根据你的实际数据结构定义字段映射,示例: "timestamp": {"type": "date"}, "content": {"type": "text"} } } }, "priority": 100 }
index_patterns匹配所有myindex-开头的索引rollover_alias是Logstash写入的入口,ILM会自动维护该别名指向当前可写索引
3. 初始化第一个可写索引
手动创建当日的第一个索引并关联别名:
PUT myindex-2024.05.20-1 { "aliases": { "myindex_write": { "is_write_index": true } } }
替换日期为当前日期,后续ILM会自动生成myindex-2024.05.20-2、myindex-2024.05.21-1等格式的索引。
4. 修改Logstash输出配置
将原动态索引名改为写入别名:
output { elasticsearch { hosts => ["http://your-es-host:9200"] index => "myindex_write" // 如有认证需求,添加以下配置 // user => "elastic" // password => "your-password" } }
此后Logstash持续写入别名指向的索引,达到10GB阈值时ILM自动创建新索引并切换别名。
5. 验证配置
- 查看ILM策略:
GET _ilm/policy/myindex_rollover_policy - 查看索引模板:
GET _index_template/myindex_template - 查看别名状态:
GET _alias/myindex_write - 监控索引大小,确认达到10GB时是否触发滚动
注意事项
- 确保Elasticsearch版本在6.6及以上(支持ILM)
- 可根据需求在ILM策略中添加warm/cold阶段,实现数据归档或删除逻辑
内容的提问来源于stack exchange,提问作者user411906
相关产品推荐
相关产品推荐

