# Cannot get my template to work

**URL:** <https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150>\
**Category:** Logstash\
**Created:** [August 10, 2015, 7:08pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150 "2015-08-10T19:08:47Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 10, 2015, 7:08pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/1 "2015-08-10T19:08:47Z")

</div>

I am trying to do a simple test to get ES to use a template of relying on default mapping to make sure the correct mappings are applied for each data type and not analyze all fields. It does not seem to apply the template. I dropped the index and template, reloaded using the template below but nothing changes. Any idea what I am doing wrong here? Regards, Frank.

config file output:

elasticsearch  
{  
manage\_template =\> true  
template =\> "c:/elasticsearch-1.6.0/config/templates/map-test/map-test.json"  
host =\> "localhost"  
index =\> "map-test"  
workers =\> 1  
document\_type =\> "test1"  
}

my template:

{  
"template": "map-test",  
"order" : 1,  
"mappings" : {  
"properties" : {  
"test1" : {  
"pk\_col" : { "type": "string", "index": "not\_analyzed"},  
"dt\_type" : { "type": "date", "format": "yyyy MM dd HH:mm:ss:SSS", "index": "not\_analyzed" },  
"int\_type": { "type": "integer" ,"index": "not\_analyzed"},  
"float\_type" : { "type" : "float", "index": "not\_analyzed" },  
"str\_type\_analyzed" : { "type" : "string", "index" : "analyzed" },  
"str\_type\_not\_analyzed" : { "type" : "string", "index" : "not\_analyzed" }  
}  
}  
}  
}

It sees the templates per the log file:

{:timestamp=\>"2015-08-10T13:57:22.609000-0500", :message=\>"Automatic template management enabled", :manage\_template=\>"true", :level=\>:info}  
{:timestamp=\>"2015-08-10T13:57:22.765000-0500", :message=\>"Using mapping template", :template=\>{"template"=\>"map-test", "order"=\>1, "mappings"=\>{"properties"=\>{"test1"=\>{"pk\_col"=\>{"type"=\>"string", "index"=\>"not\_analyzed"}, "dt\_type"=\>{"type"=\>"date", "format"=\>"yyyy MM dd HH:mm:ss:SSS", "index"=\>"not\_analyzed"}, "int\_type"=\>{"type"=\>"integer", "index"=\>"not\_analyzed"}, "float\_type"=\>{"type"=\>"float", "index"=\>"not\_analyzed"}, "str\_type\_analyzed"=\>{"type"=\>"string", "index"=\>"analyzed"}, "str\_type\_not\_analyzed"=\>{"type"=\>"string", "index"=\>"not\_analyzed"}}}}}, :level=\>:info}

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 10, 2015, 7:32pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/2 "2015-08-10T19:32:13Z")

</div>

Without knowing more, my guess is that you are not overwriting the default template.

Your settings, as posted, will not overwrite the existing template, which is named `logstash`. See the contents of the template already in place: `curl localhost:9200/_template/logstash?pretty`

There are two ways you can address this:

1. You can overwrite the existing template by adding [`template_overwrite => true`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template_overwrite) to your elasticsearch output block
2. You can use the [`template_name`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template_name) directive to give this particular template a name other than the default `logstash`

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 10, 2015, 7:37pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/3 "2015-08-10T19:37:35Z")

</div>

When I use the template\_overwrite =\> true I get error message below

:message=\>"failed action with response of 400, dropping action: ["index", {:\_id=\>nil, :\_index=\>"map-test", :\_type=\>"test1", :\_routing=\>nil}, #\<LogStash::Event:0x75d177eb @metadata\_accessors=#\<LogStash::Util::Accessors:0x5dccf42a @store={"retry\_count"=\>0}, @lut={}\>, @cancelled=false, @data={....

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 10, 2015, 7:39pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/4 "2015-08-10T19:39:25Z")

</div>

One more thing... I want to provide a new template name. I don't want to overwrite/replace the logstash one.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 10, 2015, 7:51pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/5 "2015-08-10T19:51:35Z")

</div>

The 400 indicates a permission failure. Do you have some kind of security layer (Shield or otherwise)?

If you don't want to overwrite the `logstash` template, then what you need is to add `template_name => "myname"` to your elasticsearch output block. That will put the template under its own name.

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 10, 2015, 8:06pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/6 "2015-08-10T20:06:35Z")

</div>

Hi Aaron... thanks for helping. I got past the 400 error. Awesome!

When I look at the template I see the following which matches the template. However when goto Kibana 4 Discover it gives me a warning that this field is "analyzed" even though the template says its not. Example: "str\_type\_not\_analyzed" field.

[http://localhost:9200/\_template/maptest?pretty](http://localhost:9200/_template/maptest?pretty)

{  
"maptest" : {  
"order" : 1,  
"template" : "maptest-\*",  
"settings" : { },  
"mappings" : {  
"properties" : {  
"str\_type\_analyzed" : {  
"index" : "analyzed",  
"type" : "string"  
},  
"pk\_col" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"int\_type" : {  
"index" : "not\_analyzed",  
"type" : "integer"  
},  
"float\_type" : {  
"index" : "not\_analyzed",  
"type" : "float"  
},  
"str\_type\_not\_analyzed" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"dt\_type" : {  
"format" : "yyyy MM dd HH:mm:ss:SSS",  
"index" : "not\_analyzed",  
"type" : "date"  
}  
}  
},  
"aliases" : { }  
}  
}

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 10, 2015, 8:11pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/7 "2015-08-10T20:11:46Z")

</div>

So it looks like the template is there but not being used. Probably still using the default logstash template.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 10, 2015, 8:25pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/8 "2015-08-10T20:25:01Z")

</div>

Is Kibana sampling indices named `maptest-*`? Or is it viewing default Logstash indices?

Also, the mapping may still be tied to an older index. Did you delete and recreate the index after the template was uploaded?

Also, see this example template for ideas on how to use template mappings and wildcards:

```
{
  "template" : "logstash-*",
  "settings" : {
    "index.refresh_interval" : "5s"
  },
  "mappings" : {
    "_default_" : {
       "_all" : {"enabled" : true, "omit_norms" : true},
       "dynamic_templates" : [ {
         "message_field" : {
           "match" : "message",
           "match_mapping_type" : "string",
           "mapping" : {
             "type" : "string", "index" : "analyzed", "omit_norms" : true
           }
         }
       }, {
         "string_fields" : {
           "match" : "*",
           "match_mapping_type" : "string",
           "mapping" : {
             "type" : "string", "index" : "analyzed", "omit_norms" : true,
               "fields" : {
                 "raw" : {"type": "string", "index" : "not_analyzed", "doc_values" : true, "ignore_above" : 256}
               }
           }
         }
       }, {
         "float_fields" : {
           "match" : "*",
           "match_mapping_type" : "float",
           "mapping" : { "type" : "float", "doc_values" : true }
         }
       }, {
         "double_fields" : {
           "match" : "*",
           "match_mapping_type" : "double",
           "mapping" : { "type" : "double", "doc_values" : true }
         }
       }, {
         "byte_fields" : {
           "match" : "*",
           "match_mapping_type" : "byte",
           "mapping" : { "type" : "byte", "doc_values" : true }
         }
       }, {
         "short_fields" : {
           "match" : "*",
           "match_mapping_type" : "short",
           "mapping" : { "type" : "short", "doc_values" : true }
         }
       }, {
         "integer_fields" : {
           "match" : "*",
           "match_mapping_type" : "integer",
           "mapping" : { "type" : "integer", "doc_values" : true }
         }
       }, {
         "long_fields" : {
           "match" : "*",
           "match_mapping_type" : "long",
           "mapping" : { "type" : "long", "doc_values" : true }
         }
       }, {
         "date_fields" : {
           "match" : "*",
           "match_mapping_type" : "date",
           "mapping" : { "type" : "date", "doc_values" : true }
         }
       } ],
       "properties" : {
         "@timestamp": { "type": "date", "doc_values" : true },
         "@version": { "type": "string", "index": "not_analyzed", "doc_values" : true },
         "clientip": { "type": "ip", "doc_values" : true },
         "geoip" : {
           "type" : "object",
           "dynamic": true,
           "properties" : {
             "ip": { "type": "ip", "doc_values" : true },
             "location" : { "type" : "geo_point", "doc_values" : true },
             "latitude" : { "type" : "float", "doc_values" : true },
             "longitude" : { "type" : "float", "doc_values" : true }
           }
         }
       }
    },
    "nginx_json" : {
      "properties" : {
        "duration" : { "type" : "float", "doc_values" : true },
        "status" : { "type" : "short", "doc_values" : true }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 10, 2015, 8:29pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/9 "2015-08-10T20:29:15Z")

</div>

I will give this a try.

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 10, 2015, 9:26pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/10 "2015-08-10T21:26:54Z")

</div>

Aaron, I tried with the above template. Stuck with the 400 error. If there is something else I need to share let me know. I can dump the template if needed. Thanks, Frank.

from my config:  
output  
{  
elasticsearch  
{  
template\_overwrite =\> true  
template\_name =\> "maptest"  
manage\_template =\> true  
template =\> "c:/elasticsearch-1.6.0/config/templates/maptest/maptest.json"  
host =\> "localhost"  
index =\> "map-test"  
workers =\> 1  
}

it reads the template. from my log:  
{:timestamp=\>"2015-08-10T16:24:58.045000-0500", :message=\>"Automatic template management enabled", :manage\_template=\>"true", :level=\>:info}  
{:timestamp=\>"2015-08-10T16:24:58.232000-0500", :message=\>"Using mapping template", :template=\>{"template"=\>"map-\*", "mappings"=\>{"_default_"=\>{"\_all"=\>{"enabled"=\>false}, "dynamic\_templates"=\>#Java::JavaUtil::ArrayList:0x414c1f60, "properties"=\>{"pk\_col"=\>{"type"=\>"string", "doc\_values"=\>true, "index"=\>"not\_analyzed"}, "dt\_type"=\>{"type"=\>"string", "index"=\>"not\_analyzed", "doc\_values"=\>true}, "int\_type"=\>{"type"=\>"integer", "doc\_values"=\>true}, "float\_type"=\>{"type"=\>"float", "doc\_values"=\>true}, "str\_type\_analyzed"=\>{"type"=\>"string", "index"=\>"analyzed", "doc\_values"=\>true}, "str\_type\_not\_analyzed"=\>{"type"=\>"string", "index"=\>"not\_analyzed", "doc\_values"=\>true}}}}}, :level=\>:info}

Then I get the 400 error:  
{:timestamp=\>"2015-08-10T16:24:59.433000-0500", :message=\>"failed action with response of 400, dropping action: ["index", {:\_id=\>nil, :\_index=\>"map-test", :\_type=\>"test1", :\_routing=\>nil}, #\<LogStash::Event:0x6e23664f @metadata\_accessors=#\<LogStash::Util::Accessors:0x423696a3 @store={"retry\_count"=\>0}, @lut={}\>, @cancelled=false, @data={"message"=\>....

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 10, 2015, 9:39pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/11 "2015-08-10T21:39:38Z")

</div>

I can't resolve a permissions error remotely.

What do you see if you try to delete it via curl?

`curl -XDELETE localhost:9200/_template/maptest?pretty`

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 10, 2015, 9:41pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/12 "2015-08-10T21:41:51Z")

</div>

{  
"acknowledged": true  
}

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 10, 2015, 9:44pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/13 "2015-08-10T21:44:48Z")

</div>

when I run logstash it creates the template, but does not create the index (hence the 400 error).

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 10, 2015, 9:54pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/14 "2015-08-10T21:54:28Z")

</div>

I can't help with that. That sounds like something between Logstash and Elasticsearch, or within Elasticsearch.

---

<div class="post-metadata">

**Author:** ![FrankC](https://avatars.discourse-cdn.com/v4/letter/f/ed655f/32.png) [@FrankC](https://discuss.elastic.co/u/FrankC)\
**Post date:** [August 11, 2015, 2:23pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/15 "2015-08-11T14:23:34Z")

</div>

Hi Aaron,

Persistence pays off or maybe just that I took a break. Anyways... I got it to work 🙂

I boiled the template down to the bare essentials. It appears when I added the "order": 1 to the template it picks up the data types definition b/c it is a higher priority over the default logstash one.

As for the 400 error it must have been something logstash/ES does not like. I have seen quite a few others write about the same. Wish the error message could provide clues where to look.

Here is the template that worked:  
{  
"template" : "maptest",  
"order": 1,  
"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : false},  
"properties" : {  
"pk\_col": { "type": "string", "index": "not\_analyzed","doc\_values" : true },  
"dt\_type": { "type": "date", "index": "not\_analyzed", "format": "yyyy-MM-dd HH:mm:ss.SSS", "doc\_values" : true},  
"int\_type": { "type": "integer","doc\_values" : true },  
"float\_type": { "type": "float","doc\_values" : true },  
"str\_type\_analyzed": { "type": "string", "index": "analyzed" },  
"str\_type\_not\_analyzed": { "type": "string", "index": "not\_analyzed" ,"doc\_values" : true }  
}  
}  
}  
}

The config file:

elasticsearch  
{  
template\_overwrite =\> true  
template\_name =\> "maptest"  
manage\_template =\> true  
template =\> "c:/elasticsearch-1.6.0/config/templates/maptest/maptest.json"  
host =\> "localhost"  
index =\> "maptest"  
workers =\> 1  
}

---

<div class="post-metadata">

**Author:** ![jauffrey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jauffrey/32/16164_2.png) [@jauffrey](https://discuss.elastic.co/u/jauffrey)\
**Post date:** [March 8, 2017, 6:48am UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/16 "2017-03-08T06:48:00Z")

</div>

To complement your answer, it seems that the **settings** section in the template is causing the error 400.  
I successfully reproduced your issue on Elasticsearch / Logstash 5.2.1 and got rid of error 400 by removing the settings section:

```
"settings" : {
    "index" : {
      "refresh_interval" : "5s"
    }

```

Hope this helps!

---

<div class="post-metadata">

**Author:** ![wayann](https://avatars.discourse-cdn.com/v4/letter/w/c68b51/32.png) [@wayann](https://discuss.elastic.co/u/wayann)\
**Post date:** [April 14, 2017, 1:26pm UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/17 "2017-04-14T13:26:27Z")

</div>

Removing settings got me past the 400 error.... thx!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:27am UTC](https://discuss.elastic.co/t/cannot-get-my-template-to-work/27150/18 "2017-07-06T04:27:03Z")

</div>


