# About index template upon output from logstash to elasticsearch

**URL:** <https://discuss.elastic.co/t/about-index-template-upon-output-from-logstash-to-elasticsearch/1982>\
**Category:** Logstash\
**Created:** [June 5, 2015, 2:52am UTC](https://discuss.elastic.co/t/about-index-template-upon-output-from-logstash-to-elasticsearch/1982 "2015-06-05T02:52:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![zkun](https://avatars.discourse-cdn.com/v4/letter/z/8797f3/32.png) [@zkun](https://discuss.elastic.co/u/zkun)\
**Post date:** [June 5, 2015, 2:52am UTC](https://discuss.elastic.co/t/about-index-template-upon-output-from-logstash-to-elasticsearch/1982/1 "2015-06-05T02:52:05Z")

</div>

Hi guys, recently I'm trying to setup multiple indices in ES for log storage of different services. And I noticed that I might need to set field value types for them respectively, which involves applying different templates accordingly.  
The thing I'm trying to figure out now is the difference between elasticsearch-template.json in logstash, and \_template in elasticsearch, as both are "template". If I would achieve my goal, which template should I tune on?  
I'd also much like to grab any idea on ways to add template into ES. Is there any choice apart from curl put RESTful api? That cmd is crude and ugly enough.

---

<div class="post-metadata">

**Author:** ![zkun](https://avatars.discourse-cdn.com/v4/letter/z/8797f3/32.png) [@zkun](https://discuss.elastic.co/u/zkun)\
**Post date:** [June 5, 2015, 8:58am UTC](https://discuss.elastic.co/t/about-index-template-upon-output-from-logstash-to-elasticsearch/1982/2 "2015-06-05T08:58:16Z")

</div>

Any voice regarding this is appreciated\>

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 6, 2015, 10:30am UTC](https://discuss.elastic.co/t/about-index-template-upon-output-from-logstash-to-elasticsearch/1982/3 "2015-06-06T10:30:12Z")

</div>

> The thing I'm trying to figure out now is the difference between elasticsearch-template.json in logstash, and \_template in elasticsearch, as both are "template". If I would achieve my goal, which template should I tune on?

Either one. Well, you should never modify the original elasticsearch-template.json that's distributed as part of Logstash (make a copy of it and modify _that_ file), but whether you want Logstash to manage your templates for you or if you prefer doing it outside of Logstash is a matter of taste.

> I'd also much like to grab any idea on ways to add template into ES. Is there any choice apart from curl put RESTful api? That cmd is crude and ugly enough.

[As documented](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html#config) you can also place the index template files in a subdirectory of the ES configuration directory, but this needs to be done on all cluster nodes.

---

<div class="post-metadata">

**Author:** ![zkun](https://avatars.discourse-cdn.com/v4/letter/z/8797f3/32.png) [@zkun](https://discuss.elastic.co/u/zkun)\
**Post date:** [June 8, 2015, 6:56am UTC](https://discuss.elastic.co/t/about-index-template-upon-output-from-logstash-to-elasticsearch/1982/4 "2015-06-08T06:56:02Z")

</div>

Thanks so much Magnus!~

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:38am UTC](https://discuss.elastic.co/t/about-index-template-upon-output-from-logstash-to-elasticsearch/1982/5 "2017-07-06T05:38:13Z")

</div>


