Replies: 1 comment 8 replies
-
That is older documentation for what the index used to be called. The steps are generally all the same. Check updated directions here: https://github.com/cisagov/LME/blob/main/docs/markdown/maintenance/index-management.md 2 sections here -- one for creating a new policy to manage your wazuh logs -- and one for managing the existing policy that comes with elastic (logs that come in from elastic agents) Ultimately, it will be the same concept. You're setting or editing a policy and then in that policy to move your index to the next stage after a certain amount of time or size. Completely up to you when you want to delete indexes based on these settings. |
Beta Was this translation helpful? Give feedback.
-
I was attempting to follow the guidance on adjusting retention. I don't have the lme_ilm_policy in my index lifecycle policies. Is that a problem with my instance or is the documentation out of date?
https://github.com/cisagov/LME/blob/main/docs/markdown/logging-guidance/retention.md
Beta Was this translation helpful? Give feedback.
All reactions