# Applying My First Index Template

**URL:** <https://discuss.elastic.co/t/applying-my-first-index-template/196967>\
**Category:** Elasticsearch\
**Created:** [August 27, 2019, 3:19pm UTC](https://discuss.elastic.co/t/applying-my-first-index-template/196967 "2019-08-27T15:19:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![redapplesonly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/redapplesonly/32/57700_2.png) [@redapplesonly](https://discuss.elastic.co/u/redapplesonly)\
**Post date:** [August 27, 2019, 3:19pm UTC](https://discuss.elastic.co/t/applying-my-first-index-template/196967/1 "2019-08-27T15:19:28Z")

</div>

Hi everyone,

I’m trying to apply my first ElasticSearch Index Template, and am having some issues. I think I’m both a little confused about the process of wedding a Template to an Index, and about the exact syntax of the template itself.

The mission: My ElasticSearch receives network data from a Logstash server. Within the raw data are IP addresses, which ES currently interprets to be text strings. I need an Index Template to transform those strings into proper “ip” data structures.

My plan was this:

- Reconfigure Logstash to send data into a new index called “MyIndex.” But do not start Logstash yet.
- Create a new Index Template called “my\_template” in ES. Make sure template “my\_template” specifies that it is to be used with “MyIndex” (See below)
- Start Logstash

I’m not clear how ES understands which templates get applied to what Indices, but I think that’s done with a line in the template itself.

Speaking of, here’s the Index Template I cobbled together:

```
curl -X PUT "localhost:9200/_template/my_template" -H 'Content-Type: application/json' -d'
{
    "template": "MyIndex",
    "order": 1,
        "settings": {
            "index": {
            "refresh_interval": "5s"
            }
        },
    "mappings": {
        "default": {
            "_all": {
                "norms": false,
                "enabled": true
                },
                "properties": {
                    "Packet.L3.Src": { "type": "ip"},
                    "Packet.L3.Dst": { "type": "ip"}
            }
        }
    }
}'

```

As you can see, all I really want it to do is interpret the data fields “Packet.L3.Src” and “Packet.L3.Dst” as IP addresses. Also, note that first line within the outer brackets: **"template": "MyIndex"**. I assume this is how ES understands that this template is to be applied to Index “MyIndex.”

As a safety check, I ran the above template through a JSON validator. ([here](https://jsonlint.com/)) Everything looked good on that front.

So I should be ready to rock-n-roll now. However, when I cut-n-paste the template into ES, I get the following error (I’ve included newlines for better readability):

```
{"error":
	{"root_cause":
		[{"type":"mapper_parsing_exception",
		"reason":"Root mapping definition has unsupported parameters:  
		[default : {_all={norms=false, enabled=true}, 
		properties={Packet.L3.Src={type=ip}, Packet.L3.Dst={type=ip}}}]"}],
		"type":"mapper_parsing_exception",
		"reason":"Failed to parse mapping [_doc]: 
		Root mapping definition has unsupported parameters:  
		[default : 
			{_all={norms=false, enabled=true}, 
			properties={Packet.L3.Src={type=ip}, Packet.L3.Dst={type=ip}}}]",
			"caused_by":
			{"type":"mapper_parsing_exception",
			"reason":"Root mapping definition has unsupported parameters:  
			[default : {_all={norms=false, enabled=true}, 
			properties={Packet.L3.Src={type=ip}, Packet.L3.Dst={type=ip}}}]"
}
}
,"status":400 } 

```

I’m not sure what this means, but when I see things like “parsing exception,” I assume I have a syntax error that is throwing off the parsing of my template. Like, maybe I have a comma at the end of a line where I shouldn’t… or vice versa…? I don’t know.

_ **FULL DISCLOSURE:** _ I’ve been working on this issue in the ES Forum, and posted an earlier part of my issues was posted [here](https://discuss.elastic.co/t/non-integer-data-types-in-my-data-how-to-make-a-visualization/196375/10).

Anyway, I’m hoping someone can point out the error of my ways. Any advice is appreciated!

---

<div class="post-metadata">

**Author:** ![redapplesonly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/redapplesonly/32/57700_2.png) [@redapplesonly](https://discuss.elastic.co/u/redapplesonly)\
**Post date:** [August 29, 2019, 5:45pm UTC](https://discuss.elastic.co/t/applying-my-first-index-template/196967/2 "2019-08-29T17:45:16Z")

</div>

Does anyone have any thoughts? My development project is dead in the water until I can push past this issue. Thanks...!

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [August 31, 2019, 10:03am UTC](https://discuss.elastic.co/t/applying-my-first-index-template/196967/3 "2019-08-31T10:03:50Z")

</div>

There's a few things going on here. You did not specify what version of Elasticsearch you are using, but I'm going to assume you are on version 7. There have been a few changes to how index templates and mappings are defined in recent versions. Some of the syntax you are using does not work in 7 any more:

- Instead of `template` you need to set `index_patterns`. By the way, this is how Elasticsearch matches a template to an index. Whenever you create a new index, Elasticsearch will try to find any index template with an `index-patterns` pattern that matches the name of that new index.
- [Document types have gone away](https://www.elastic.co/guide/en/elasticsearch/reference/current/removal-of-types.html). You no longer need to (and no longer can) provide `default` in the mapping.
- [`_all` went away too](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/breaking_60_mappings_changes.html#_the_literal__all_literal_meta_field_is_now_disabled_by_default).

Applying these changes to your index template, the correct request to create your index template would be:

```auto
PUT /_template/my_template
{
  "index_patterns": "MyIndex",
  "order": 1,
  "settings": {
    "index": {
      "refresh_interval": "5s"
    }
  },
  "mappings": {
    "properties": {
      "Packet.L3.Src": {
        "type": "ip"
      },
      "Packet.L3.Dst": {
        "type": "ip"
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![redapplesonly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/redapplesonly/32/57700_2.png) [@redapplesonly](https://discuss.elastic.co/u/redapplesonly)\
**Post date:** [September 3, 2019, 9:26pm UTC](https://discuss.elastic.co/t/applying-my-first-index-template/196967/4 "2019-09-03T21:26:24Z")

</div>

Thanks Abdon, I missed your note because of the holiday in the US. I'll be in the office tomorrow and will deep dive on your notes. Thank you for replying! I hadn't realized I'd gotten so many wires crossed...

Much appreciated,  
-Pete

---

<div class="post-metadata">

**Author:** ![redapplesonly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/redapplesonly/32/57700_2.png) [@redapplesonly](https://discuss.elastic.co/u/redapplesonly)\
**Post date:** [September 4, 2019, 5:49pm UTC](https://discuss.elastic.co/t/applying-my-first-index-template/196967/5 "2019-09-04T17:49:33Z")

</div>

Many thanks to Abdon! Yes, you were entirely correct. I am on ES version 7.3.0, and hadn't realized I was cross-pollinating solutions from different ES versions. I must have found the core of my solution in an old Google search, then added in elements from more modern documentation. Good catch, you've saved my project!

Much appreciated,  
-P

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2019, 5:49pm UTC](https://discuss.elastic.co/t/applying-my-first-index-template/196967/6 "2019-10-02T17:49:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
