# Adding \_size field to index template

**URL:** <https://discuss.elastic.co/t/adding-size-field-to-index-template/363884>\
**Category:** Elasticsearch\
**Created:** [July 26, 2024, 7:20pm UTC](https://discuss.elastic.co/t/adding-size-field-to-index-template/363884 "2024-07-26T19:20:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [July 26, 2024, 7:20pm UTC](https://discuss.elastic.co/t/adding-size-field-to-index-template/363884/1 "2024-07-26T19:20:34Z")

</div>

I'm running ES 8.13.4, attempting to add the \_size field to an index template.

I have successfully installed the \_size plugin on all nodes on the cluster, confirmed by issuing `GET /_cat/plugins `

When I issue:

```auto
PUT /_index_template/filebeat-8.14.3/
{
  "mappings": {
    "_size": {
      "enabled": true
    }
  }
} 

```

I get the following response:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "x_content_parse_exception",
        "reason": "[2:3] [index_template] unknown field [mappings]"
      }
    ],
    "type": "x_content_parse_exception",
    "reason": "[2:3] [index_template] unknown field [mappings]"
  },
  "status": 400
}

```

As a bonus question, how do I make changes like this survive Filebeat updates? It seems like a new index template is created whenever Filebeat is updated. Is there a....template for templates?

---

<div class="post-metadata">

**Author:** ![michaelcizmar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaelcizmar/32/45942_2.png) [@michaelcizmar](https://discuss.elastic.co/u/michaelcizmar)\
**Post date:** [July 27, 2024, 12:04pm UTC](https://discuss.elastic.co/t/adding-size-field-to-index-template/363884/2 "2024-07-27T12:04:19Z")

</div>

```auto
PUT /_index_template/filebeat-8.14.3
{
  "index_patterns": ["filebeat-8.14.3-*"],
  "template": {
    "mappings": {
      "_size": {
        "enabled": true
      },
// your other mappings
    }
  }
}

```

See: [Create or update index template API | Elasticsearch Guide [8.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates-v1.html)

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [August 1, 2024, 4:54pm UTC](https://discuss.elastic.co/t/adding-size-field-to-index-template/363884/3 "2024-08-01T16:54:17Z")

</div>

Thank you. My current mapping for that template is 27k lines long. So... download my current mapping, stick this in there somewhere and PUT it in again?
