# Changes removed from system index templates

**URL:** <https://discuss.elastic.co/t/changes-removed-from-system-index-templates/377168>\
**Category:** Elastic Security\
**Created:** [April 15, 2025, 10:56pm UTC](https://discuss.elastic.co/t/changes-removed-from-system-index-templates/377168 "2025-04-15T22:56:16Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![jcruz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcruz/32/91772_2.png) [@jcruz](https://discuss.elastic.co/u/jcruz)\
**Post date:** [April 15, 2025, 10:56pm UTC](https://discuss.elastic.co/t/changes-removed-from-system-index-templates/377168/1 "2025-04-15T22:56:16Z")

</div>

I have made some changes to a system index template (`.alerts-security.alerts-default-index-template`) by adding a new **Component Template** to map some custom fields for use as filters in the Alerts dashboard. However, after some time, I noticed that the Component Template was no longer associated with the `.alerts-security.alerts-default-index-template`, and once again, the filters based on custom fields stopped working.

Is there a way to make this change permanent, or is there a better approach to mapping custom fields in the alerts index?
