You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Elastic/OpenSearch生命周期管理:read_write与open动作区别及选型

索引生命周期管理:open 和 read_write 动作怎么选?

针对你的需求的选择

要实现索引14天后自动删除的目标,第一阶段用read_write动作是更合理的选择——毕竟你的audit-*索引是要持续写入日志的,这个动作能确保索引正常接收写入和查询请求。

两者的核心差异

  • open动作:只负责把索引从关闭状态改成打开状态,允许读写,但不会主动设置索引的读写权限。如果索引本来就是打开的,这个动作基本没效果。
  • read_write动作:不仅会打开关闭的索引,还会明确将索引配置为读写模式,彻底排除索引被设为只读的可能。这是业务日志类索引的标准配置,能避免意外导致的写入失败。

修正后的完整策略代码

原JSON里有个语法错误(description行末尾少了逗号),下面是修复后的可用版本:

{
  "policy": {
    "policy_id": "delete_after14_days",
    "description": "index delete",
    "schema_version": 1,
    "error_notification": null,
    "default_state": "open",
    "states": [
      {
        "name": "hot",
        "actions": [
          {
            "read_write": {}
          }
        ],
        "transitions": [
          {
            "state_name": "delete",
            "conditions": {
              "min_index_age": "14d"
            }
          }
        ]
      },
      {
        "name": "delete",
        "actions": [
          {
            "delete": {}
          }
        ],
        "transitions": []
      }
    ],
    "ism_template": [
      {
        "index_patterns": [
          "audit-*"
        ],
        "priority": 0
      }
    ]
  }
}

内容的提问来源于stack exchange,提问作者dzbeda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 00:05:25