# Apparently I need to edit a Filebeat 'data stream template'. Such a thing does not exist!

**URL:** <https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495>\
**Category:** Elasticsearch\
**Created:** [August 6, 2024, 6:39pm UTC](https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495 "2024-08-06T18:39:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [August 6, 2024, 6:39pm UTC](https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495/1 "2024-08-06T18:39:28Z")

</div>

We're using Filebeat 8.14.3 to index network logs. We'd like to enable the \_size field for all Filebeat data streams. ([My previous thread on this topic](https://discuss.elastic.co/t/adding-size-field-to-index-template/363884)).

Here's the attempt to enable the "\_size" field:

```auto
PUT /_index_template/filebeat-8.14.3
{
  "index_patterns": ["filebeat-8.14.3-*"],
  "template": {
    "mappings": {
      "_size": {
        "enabled": true
      }
    }
  }
}

```

Here's the error message:

```auto
"composable template [filebeat-8.14.3] with index patterns [filebeat-8.14.3-*], priority [null] and no data stream configuration would cause data streams [filebeat-8.14.3] to no longer match a data stream template"

```

But what is a data stream template? The [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html) explains the relationship between an index template and a data stream, but I can't find any clear reference to a 'data stream template'. As it stands, I'm editing the index template for a specific version of filebeat, so the existence of a data stream template would make sense; new data streams would inherit settings from that template. But there is no such entity to be found! Data streams: yes. Index templates: yes. Data stream templates: no.

What am I missing here?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 7, 2024, 5:09am UTC](https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495/2 "2024-08-07T05:09:59Z")

</div>

A data stream template is an index template that includes the `data_stream` object.

> **[Set up a data stream | Elasticsearch Guide \[8.14\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/set-up-a-data-stream.html#create-index-template)**

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [August 7, 2024, 3:47pm UTC](https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495/3 "2024-08-07T15:47:15Z")

</div>

> [@TimV](#):
>
> data\_stream

OK that's a great start. Thank you.

---

<div class="post-metadata">

**Author:** ![Tom\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tom_n/32/136135_2.png) [@Tom\_N](https://discuss.elastic.co/u/Tom_N)\
**Post date:** [August 21, 2024, 2:43am UTC](https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495/4 "2024-08-21T02:43:03Z")

</div>

Hi @artschooldropout, did you have any luck with fixing this error?

I originally had a data stream setup with filebeat, migrating from the default index to data stream.

However, when I reconfigured and setup my filebeat again, I got a similar error to you

```auto
composable template [filebeat-7.17.22] with index patterns [filebeat-7.17.22-*], priority [150] and no data stream configuration would cause data streams [filebeat-7.17.22] to no longer match a data stream

```

I assumed for me, this is caused because I use the default index template, but changed it in Kibana when I tried to migrate to a data stream. I might need to specify the index template to use

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [August 24, 2024, 10:33am UTC](https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495/5 "2024-08-24T10:33:32Z")

</div>

@Tom_N alas, no. I posted in Reddit, and was told that this is not possible: [see here](https://www.reddit.com/r/elasticsearch/comments/1es9iez/change_datastream_mapping_to_enable_size_field/)

---

<div class="post-metadata">

**Author:** ![Tom\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tom_n/32/136135_2.png) [@Tom\_N](https://discuss.elastic.co/u/Tom_N)\
**Post date:** [August 24, 2024, 3:04pm UTC](https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495/6 "2024-08-24T15:04:47Z")

</div>

I see. Thank you for the reply!
