# Alter the template for system indices

**URL:** <https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 3, 2019, 6:00am UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883 "2019-06-03T06:00:16Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [June 3, 2019, 6:00am UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883/1 "2019-06-03T06:00:16Z")

</div>

Hi,

We want to reduce the amount of shards that each .security\_audit\_log template is generating on a daily basis. At the moment it is creating 5 shards each day and we want to reduce it to 1 primary and 1 replica.

Does the process of updating templates differ from a normal index when compared to system index? Or do we just run a PUT request and replace the values that we want to set?

Thanks

---

<div class="post-metadata">

**Author:** ![wangqinghuan](https://avatars.discourse-cdn.com/v4/letter/w/d26b3c/32.png) [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Post date:** [June 3, 2019, 7:55am UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883/2 "2019-06-03T07:55:53Z")

</div>

Yes, both are same. You can browse all index templates containing system and user teplates in Cerebro, and modify index templates.

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [June 3, 2019, 8:42am UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883/3 "2019-06-03T08:42:17Z")

</div>

I have to assume you are using ES \<7.0.

The setting you are looking for is documented on the same page where security auditing is documented itself.

[https://www.elastic.co/guide/en/elasticsearch/reference/6.8/auditing-settings.html#index-audit-settings](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/auditing-settings.html#index-audit-settings)

You can change the index settings like shards and replica with those settings.

Just FYI, take note that shipping those audit logs directly in an index from ES itself is no longer a thing in \>=7.0  
See [https://www.elastic.co/guide/en/elasticsearch/reference/7.0/breaking-changes-7.0.html#remove-audit-index-output](https://www.elastic.co/guide/en/elasticsearch/reference/7.0/breaking-changes-7.0.html#remove-audit-index-output)  
It's now audit log file per node + filebeat to ship it out to your monitoring/auditing cluster.  
Just keep in mind for your upgrade to 7.

---

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [June 3, 2019, 11:31am UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883/4 "2019-06-03T11:31:28Z")

</div>

Thank you,

However, if i update the template i effectively overwrite it yes? Is there a way i can mess up the predefined settings for the existing template? I would like to keep the existing template to 95%, just that i want to change how many shards each index creates.

---

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [June 4, 2019, 2:39pm UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883/5 "2019-06-04T14:39:56Z")

</div>

Anyone?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 4, 2019, 3:18pm UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883/6 "2019-06-04T15:18:20Z")

</div>

Hi @victor.nilsson

Please be patient in waiting for responses to your question and refrain from  
pinging multiple times asking for a response. This is a community forum, it may take time for someone to reply to your question. For more information please refer to the [Community Code of Conduct](https://www.elastic.co/community/codeofconduct) specifically the section "Be patient".

I'm sure someone will be able to offer some valuable feedback soon 🙂

---

<div class="post-metadata">

**Author:** ![wangqinghuan](https://avatars.discourse-cdn.com/v4/letter/w/d26b3c/32.png) [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Post date:** [June 5, 2019, 1:13am UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883/7 "2019-06-05T01:13:05Z")

</div>

Hi  
Just modify number\_of\_shards and keep others unchanged.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1dbd61feda043ff837f122ae696219d557be857e.png)

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 5, 2019, 4:09am UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883/8 "2019-06-05T04:09:05Z")

</div>

The supported option is to follow @martinr_ubi's advice above.

Set the number of shards and replicas under `xpack.security.audit.index.settings` in your `elasticsearch.yml`  
You _can_ edit the template, but we cannot guarantee that your updates will be retained when you upgrade.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2019, 4:09am UTC](https://discuss.elastic.co/t/alter-the-template-for-system-indices/183883/9 "2019-07-03T04:09:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
