默认time-unit为days时ELK Curator处理月/周索引的行为咨询
Hey there, let's break down exactly how Curator handles your monthly (and weekly) indices when your company's custom wrapper locks the default time-unit to days and you can't override it.
Key Background
First, remember Curator relies on parsing the timestamp in your index names (like 2018.01 in logstash-test-monthly-2018.01) to determine an index's "age". When stuck with days as the default unit, here's the play-by-play:
Handling Monthly Indices
- Curator parses a monthly index name like
logstash-test-monthly-2018.01to the first day of the target month (e.g.,2018-01-01 00:00:00). - It calculates the total number of days between that parsed start date and the current date.
- This day count is what it uses to compare against your
countvalue in Curator actions (likedelete_indicesorclose_indices).
Example Scenario
Suppose today is 2024-06-10:
- Index
logstash-test-monthly-2024.03parses to2024-03-01, which is ~101 days old. - If your Curator config sets
count: 90(keep indices younger than 90 days), this index will be flagged for processing (deleted/closed) because 101 > 90. - Note: This creates slight imprecision vs. natural months—since months have varying days (28-31), a "3-month old" index could be 89-92 days old depending on the month.
Handling Weekly Indices
For weekly indices (e.g., logstash-test-weekly-2018.W01), the logic follows the same pattern:
- Curator parses the week identifier (like
W01) to the first day of that week (default is Monday, though this can depend on locale settings). - It calculates the total days between that start date and today, then compares to your
countvalue.
Example Scenario
If today is 2024-06-10:
- Index
logstash-test-weekly-2024.W18parses to2024-05-06(the start of week 18 in 2024), which is ~35 days old. - If your
countis 30, the index will be processed; ifcountis 40, it will be retained.
Critical Caveat
Since Curator is forced to use days as the unit, you won't get precise "natural month/week" boundary handling. For example, an index from January 31st will be considered 89 days old on April 30th (vs. 90 days for an index from January 1st), leading to inconsistent retention if you're trying to align with calendar months/weeks.
If possible, I'd recommend checking in with your team that built the custom Elasticsearch/Curator wrapper to see if they can unlock the ability to set a custom unit per filter—this would let you use months or weeks directly for these index patterns, ensuring accurate calendar-aligned management.
内容的提问来源于stack exchange,提问作者kriket

