# Settings for .opensearch-alerting-finding-history and .opensearch-alerting-queries indices

**URL:** <https://forum.opensearch.org/t/settings-for-opensearch-alerting-finding-history-and-opensearch-alerting-queries-indices/15076>\
**Category:** Alerting\
**Tags:** discuss, configure\
**Created:** [July 12, 2023, 3:03pm UTC](https://forum.opensearch.org/t/settings-for-opensearch-alerting-finding-history-and-opensearch-alerting-queries-indices/15076 "2023-07-12T15:03:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Phandora](https://avatars.discourse-cdn.com/v4/letter/p/ea666f/32.png) [@Phandora](https://forum.opensearch.org/u/Phandora)\
**Post date:** [July 12, 2023, 3:03pm UTC](https://forum.opensearch.org/t/settings-for-opensearch-alerting-finding-history-and-opensearch-alerting-queries-indices/15076/1 "2023-07-12T15:03:20Z")

</div>

**Versions**

OpenSearch v2.6.0

**Description**

Hi OpenSearch team,

When reviewing the cluster indices I have found the following related to alerting:

- .opensearch-alerting-finding-history-2023.07.12-1
- .opensearch-alerting-queries-000001

I have been reviewing [the documentation](https://opensearch.org/docs/2.6/observing-your-data/alerting/settings/) to configure the rollover and deletion of these indexes, but I have not found any settings related to them.

I was expecting settings similar to the ones used for `.opendistro-alerting-alert-history`:

- Related to rollover:
  - plugins.alerting.alert\_history\_rollover\_period
  - plugins.alerting.alert\_history\_max\_age
  - plugins.alerting.alert\_history\_max\_docs

- Related to the index deletion:
  - plugins.alerting.alert\_history\_retention\_period

❓ Are there any settings for managing the `.opensearch-alerting-finding-history-*` and `.opensearch-alerting-queries-*` indices?

I know I could use **ISM** for this matter, but I was expecting them to have some sort of default settings for rollover and deletion.

Best regards,  
Mayte Ariza.

---

<div class="post-metadata">

**Author:** ![pdz](https://avatars.discourse-cdn.com/v4/letter/p/51bf81/32.png) [@pdz](https://forum.opensearch.org/u/pdz)\
**Post date:** [July 14, 2023, 2:04pm UTC](https://forum.opensearch.org/t/settings-for-opensearch-alerting-finding-history-and-opensearch-alerting-queries-indices/15076/2 "2023-07-14T14:04:56Z")

</div>

Yes, you have same settings for findings indices: `plugins.alerting.alert_finding_rollover_period`  
`plugins.alerting.finding_history_max_age`  
`plugins.alerting.alert_finding_max_docs`  
`plugins.alerting.finding_history_retention_period`

“alerting-queries” indices are handled internally. Currently there are few edge cases where alerting would miss deleting unused query indices. [This PR](https://github.com/opensearch-project/alerting/pull/830) is addressing that.

---

<div class="post-metadata">

**Author:** ![Phandora](https://avatars.discourse-cdn.com/v4/letter/p/ea666f/32.png) [@Phandora](https://forum.opensearch.org/u/Phandora)\
**Post date:** [July 14, 2023, 2:58pm UTC](https://forum.opensearch.org/t/settings-for-opensearch-alerting-finding-history-and-opensearch-alerting-queries-indices/15076/3 "2023-07-14T14:58:24Z")

</div>

Thank you very much for the update! I could not find any related setting in the documentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/3/33547ea01a5b12dcca2958411d3edd97ae2ea8c1.png) [@system](https://forum.opensearch.org/u/system)\
**Post date:** [September 12, 2023, 2:59pm UTC](https://forum.opensearch.org/t/settings-for-opensearch-alerting-finding-history-and-opensearch-alerting-queries-indices/15076/4 "2023-09-12T14:59:12Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
