# Creating Custom Index Template

**URL:** <https://discuss.elastic.co/t/creating-custom-index-template/276847>\
**Category:** Kibana\
**Created:** [June 23, 2021, 8:15pm UTC](https://discuss.elastic.co/t/creating-custom-index-template/276847 "2021-06-23T20:15:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jthart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jthart/32/90189_2.png) [@jthart](https://discuss.elastic.co/u/jthart)\
**Post date:** [June 23, 2021, 8:15pm UTC](https://discuss.elastic.co/t/creating-custom-index-template/276847/1 "2021-06-23T20:15:59Z")

</div>

I have a UniFi controller sending syslog data to logstash with custom patterns defined for parsing, and the data flow itself is working. However, the issue I am having is that I have no clue how to get the index definition defined appropriately. I'm working from information found at the following URL:

> **[r/logstash - Ubiquiti syslog](https://www.reddit.com/r/logstash/comments/av4kru/ubiquiti_syslog/)**
>
> 2 votes and 1 comment so far on Reddit

I believe I just have something small that needs to be tweaked in the following attempted definition, but I haven't found a clear explanation of what it could be:

Attempted Index Creation:

```auto
PUT /_index_template/unifisyslog_template?pretty
{
  "unifisyslog" : {
    "order" : 0,
    "index_patterns" : [
      "unifisyslog-*"
    ],
    "settings" : {
      "index" : {
        "number_of_shards" : "1",
        "number_of_replicas" : "1"
      }
    },
    "mappings" : {
      "doc" : {
        "properties" : {
          "ubiquiti.switch" : {
            "type" : "object"
          },
          "source.geo" : {
            "dynamic" : true,
            "properties" : {
              "ip" : {
                "type" : "ip"
              },
              "location" : {
                "type" : "geo_point"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          },
          "destination.geo" : {
            "dynamic" : true,
            "properties" : {
              "ip" : {
                "type" : "ip"
              },
              "location" : {
                "type" : "geo_point"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          },
          "source.ip" : {
            "type" : "ip"
          },
          "destination.ip" : {
            "type" : "ip"
          }
        }
      }
    },
    "aliases" : { }
  }
}

```

I get an error on the "unifisyslog" item at the beginning, but I can't seem to find an example that shows me what would be different (I thought the name being assigned would be the first item?). Any pointers that could help me figure out how to format the request appropriately?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [June 23, 2021, 9:14pm UTC](https://discuss.elastic.co/t/creating-custom-index-template/276847/2 "2021-06-23T21:14:15Z")

</div>

> [@jthart](#):
>
> ```auto
> {
> "unifisyslog" :
> 
> ```

These parts are returned when you GET an index, but you need to take those off (and the ending }) before you PUT.

Here is the start of one of my templates to compare:

```auto
{
    "order" : 100,
    "index_patterns" : [
      "redacted-*"
    ],
    "settings" : {
      "index" : {
<snip>

```

---

<div class="post-metadata">

**Author:** ![jthart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jthart/32/90189_2.png) [@jthart](https://discuss.elastic.co/u/jthart)\
**Post date:** [June 23, 2021, 11:21pm UTC](https://discuss.elastic.co/t/creating-custom-index-template/276847/3 "2021-06-23T23:21:55Z")

</div>

Going with editing the original I get an error regarding "order" now.

Here's the revised start:

```auto
PUT /_index_template/unifisyslog_template?pretty
{
  "order" : 100,
  "index_patterns" : [
    "unifisyslog-*"
  ],
  "settings" : {
    "index" : {
<snip>

```

I had the same error before shifting everything to the left (just in case it was somehow an issue on spacing).

This is the exact error:

 ![Screen Shot 2021-06-23 at 6.20.54 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/8/286ff040c1b59021005b7b121e23b1f886e708bb.png)

(apologies for the screenshot instead of copying the text, but for some reason it would not copy/paste out of the response side of the window)

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [June 24, 2021, 12:13am UTC](https://discuss.elastic.co/t/creating-custom-index-template/276847/4 "2021-06-24T00:13:26Z")

</div>

There were a couple of errors in the Index, the mapping and settings must be in the template body, and some other elements were misplaced too, take a look at: [Create or update index template API | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-template.html) if you want to find them in detail, but, there you go:

```auto
PUT /_index_template/unifisyslog_template
{
  "index_patterns": [
    "unifisyslog-*"
  ],
  "template": {
    "settings": {
      "index": {
        "number_of_shards": "1",
        "number_of_replicas": "1"
      }
    },
    "mappings": {
        "properties": {
          "ubiquiti.switch": {
            "type": "object"
          },
          "source.geo": {
            "dynamic": true,
            "properties": {
              "ip": {
                "type": "ip"
              },
              "location": {
                "type": "geo_point"
              },
              "latitude": {
                "type": "half_float"
              },
              "longitude": {
                "type": "half_float"
              }
            }
          },
          "destination.geo": {
            "dynamic": true,
            "properties": {
              "ip": {
                "type": "ip"
              },
              "location": {
                "type": "geo_point"
              },
              "latitude": {
                "type": "half_float"
              },
              "longitude": {
                "type": "half_float"
              }
            }
          },
          "source.ip": {
            "type": "ip"
          },
          "destination.ip": {
            "type": "ip"
          }
        }
    },
    "aliases": {}
  }
}

```

---

<div class="post-metadata">

**Author:** ![jthart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jthart/32/90189_2.png) [@jthart](https://discuss.elastic.co/u/jthart)\
**Post date:** [June 24, 2021, 2:22am UTC](https://discuss.elastic.co/t/creating-custom-index-template/276847/5 "2021-06-24T02:22:29Z")

</div>

That worked. Thank you very much. Having an example to use to go through the documentation makes it a lot easier for me to grasp!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2021, 2:23am UTC](https://discuss.elastic.co/t/creating-custom-index-template/276847/6 "2021-07-22T02:23:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
