elastiflow-flow-ecs-8.0-2.3-tsds index is growing and growing although a lifecycle policy has been set (by default).
I’ve removed the current lifecycle policy from the index. When trying to add the lifecycle policy again, elasticsearch gives the error “Index has no aliases” (Policy elastiflow is configured for rollover, but index elastiflow-flow-ecs-8.0-2.3-tsds does not have an alias, which is required for rollover.).
Probably that’s why there is no rollover for the TSDS index.
When did you enable TSDS? Was it after the collector had already been started once without TSDS? If so, it is necessary to delete the non-TSDS index templates that were originally installed. See the note here…
TSDS was enabled after the installation had run for a couple of months.
Stopped flowcoll, removed the indexes and restarted flowcoll. Lets see how things will run.
Thank you for the answer. Never looked at the docs before enabling TSDS.