# Custom template for logstash

**URL:** <https://discuss.elastic.co/t/custom-template-for-logstash/176225>\
**Category:** Logstash\
**Created:** [April 10, 2019, 1:18pm UTC](https://discuss.elastic.co/t/custom-template-for-logstash/176225 "2019-04-10T13:18:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vijayakumar\_Kannan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakumar_kannan/32/34873_2.png) [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Post date:** [April 10, 2019, 1:18pm UTC](https://discuss.elastic.co/t/custom-template-for-logstash/176225/1 "2019-04-10T13:18:13Z")

</div>

My custom logs are sent from filebeat (ingest pipeline) -\> logstash -\> elasticsearch . Now i need to make custom index for retention period purpose. when i try the custom index my geo\_ip not mapping correct one.

**Logstash output pipeline**

> elasticsearch {  
> hosts =\> ["[http://ese0001:9200](http://ese0001:9200)"]  
> index =\> "ftppipelinefields-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> pipeline =\> "%{[@metadata][pipeline]}"  
> }

if i don't use the **index** setting then it's using the **filebeat** template and geo\_ip filter working fine. Now what is the solution for this ?

1. New template and use the **template** parameter?
2. **mutate** filter ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 10, 2019, 1:31pm UTC](https://discuss.elastic.co/t/custom-template-for-logstash/176225/2 "2019-04-10T13:31:31Z")

</div>

If your problem is that [geoip][location] is not a geo\_point then yes, you need to supply a template that matches your index name that tells ES that it should be.

---

<div class="post-metadata">

**Author:** ![Vijayakumar\_Kannan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakumar_kannan/32/34873_2.png) [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Post date:** [April 11, 2019, 5:24am UTC](https://discuss.elastic.co/t/custom-template-for-logstash/176225/3 "2019-04-11T05:24:12Z")

</div>

how do i create one template?

My current mapping .

> ```
> "properties": {
> 
> ```

```
      "ftp": {
        "properties": {
          "vsftpd": {
            "properties": {
              "eventtime": {
                "type": "keyword",
                "ignore_above": 1024
              },
              "eventyear": {
                "type": "keyword",
                "ignore_above": 1024
              },
              "sylogpid": {
                "type": "keyword",
                "ignore_above": 1024
              },
              "username": {
                "type": "keyword",
                "ignore_above": 1024
              },
              "loginstatus": {
                "type": "keyword",
                "ignore_above": 1024
              },
              "action": {
                "ignore_above": 1024,
                "type": "keyword"
              },
              "hostname": {
                "type": "keyword",
                "ignore_above": 1024
              },
              "day": {
                "type": "keyword",
                "ignore_above": 1024
              },
              "clientip": {
                "type": "keyword",
                "ignore_above": 1024
              },
              "filename": {
                "ignore_above": 1024,
                "type": "keyword"
              },
              "filesize": {
                "type": "long"
              },
              "clientgeoip": {
                "properties": {
                  "location": {
                    "type": "geo_point"
                  },
                  "region_name": {
                    "type": "keyword",
                    "ignore_above": 1024
                  },
                  "city_name": {
                    "type": "keyword",
                    "ignore_above": 1024
                  },
                  "continent_name": {
                    "type": "keyword",
                    "ignore_above": 1024
                  },
                  "country_iso_code": {
                    "type": "keyword",
                    "ignore_above": 1024
                  }
                }
              }
            }
          }
        }
      }
        }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 11, 2019, 11:10am UTC](https://discuss.elastic.co/t/custom-template-for-logstash/176225/4 "2019-04-11T11:10:45Z")

</div>

The default template can be found [here](https://github.com/logstash-plugins/logstash-output-elasticsearch/tree/master/lib/logstash/outputs/elasticsearch). You could edit the second line and merge that into any other template you want to use.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2019, 11:15am UTC](https://discuss.elastic.co/t/custom-template-for-logstash/176225/5 "2019-05-09T11:15:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
