# Copy logstash template

**URL:** <https://discuss.elastic.co/t/copy-logstash-template/204694>\
**Category:** Logstash\
**Created:** [October 22, 2019, 4:58pm UTC](https://discuss.elastic.co/t/copy-logstash-template/204694 "2019-10-22T16:58:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![SirJune](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sirjune/32/55205_2.png) [@SirJune](https://discuss.elastic.co/u/SirJune)\
**Post date:** [October 22, 2019, 4:58pm UTC](https://discuss.elastic.co/t/copy-logstash-template/204694/1 "2019-10-22T16:58:53Z")

</div>

i would like to copy logstash template to a newname template. I did a GET \_template/logstash , copied and edited (replace the word "logstash" with "blah")

Did a PUT but got an error of:

```
{
  "error": {
    "root_cause": [
      {
        "type": "parse_exception",
        "reason": "unknown key [blah] in the template "
      }
    ],
    "type": "parse_exception",
    "reason": "unknown key [blah] in the template "
  },
  "status": 400
}

```

PUT \_template/blah

```
{
  "blah" : {
    "order" : 0,
    "version" : 60001,
    "index_patterns" : [
      "blah-*"
    ],
    "settings" : {
      "index" : {
        "number_of_shards" : "1",
        "refresh_interval" : "5s"
      }
    },
    "mappings" : {
      "dynamic_templates" : [
        {
          "message_field" : {
            "path_match" : "message",
            "mapping" : {
              "norms" : false,
              "type" : "text"
            },
            "match_mapping_type" : "string"
          }
        },
        {
          "string_fields" : {
            "mapping" : {
              "norms" : false,
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "ignore_above" : 256,
                  "type" : "keyword"
                }
              }
            },
            "match_mapping_type" : "string",
            "match" : "*"
          }
        }
      ],
      "properties" : {
        "@timestamp" : {
          "type" : "date"
        },
        "geoip" : {
          "dynamic" : true,
          "properties" : {
            "ip" : {
              "type" : "ip"
            },
            "latitude" : {
              "type" : "half_float"
            },
            "location" : {
              "type" : "geo_point"
            },
            "longitude" : {
              "type" : "half_float"
            }
          }
        },
        "@version" : {
          "type" : "keyword"
        }
      }
    },
    "aliases" : { }
  }
}

```

How do I copy logstash template? such that i can use "blah" in my index names?

thanks!  
Sirjune

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 22, 2019, 7:45pm UTC](https://discuss.elastic.co/t/copy-logstash-template/204694/2 "2019-10-22T19:45:34Z")

</div>

Please edit your post and format it so that special characters are not consumed as markup. Select the text of your template and click on \</\> in the toolbar above the edit pane. The appearence of the selected text will change to look

```
    like this
```

---

<div class="post-metadata">

**Author:** ![SirJune](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sirjune/32/55205_2.png) [@SirJune](https://discuss.elastic.co/u/SirJune)\
**Post date:** [October 22, 2019, 9:02pm UTC](https://discuss.elastic.co/t/copy-logstash-template/204694/3 "2019-10-22T21:02:52Z")

</div>

Thanks @Badger! i formatted the original post.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 22, 2019, 9:50pm UTC](https://discuss.elastic.co/t/copy-logstash-template/204694/4 "2019-10-22T21:50:13Z")

</div>

You cannot take the output of "GET \_template" and feed it to "PUT \_template" without modification. You can do a GET on more than one template at a time, so the structure of the output is

```
{
"templateName1": { contents of template1 },
"templateName2": { contents of template2 }
}

```

If you just fetch one template it still uses that structure

```
{ "templateName1": { contents of template } }

```

So for the PUT you need to remove the leading { "blah" : and the trailing }

Take a look at [this](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es7x.json) to see an example of what you would PUT.

---

<div class="post-metadata">

**Author:** ![SirJune](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sirjune/32/55205_2.png) [@SirJune](https://discuss.elastic.co/u/SirJune)\
**Post date:** [October 24, 2019, 1:17am UTC](https://discuss.elastic.co/t/copy-logstash-template/204694/5 "2019-10-24T01:17:29Z")

</div>

Thanks much @Badger! I was able to create a new template. My target is to (at least) have the geoip mappings without "logstash" prefix in my index name.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2019, 1:17am UTC](https://discuss.elastic.co/t/copy-logstash-template/204694/6 "2019-11-21T01:17:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
