# Deprecated setting, where is it?

**URL:** <https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336>\
**Category:** Elasticsearch\
**Created:** [March 7, 2019, 3:16pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336 "2019-03-07T15:16:47Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [March 7, 2019, 3:16pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/1 "2019-03-07T15:16:47Z")

</div>

I never had 5.x version. started from 6.2. now I am on 6.6.1

I still get following in my log "deprecation.log"

Deprecated field [template] used, replaced by [index\_patterns]

Where do I fix this?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2019, 3:44pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/2 "2019-03-07T15:44:22Z")

</div>

In your index templates.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [March 7, 2019, 4:16pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/3 "2019-03-07T16:16:32Z")

</div>

where is that located?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [March 7, 2019, 4:23pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/4 "2019-03-07T16:23:13Z")

</div>

ok found some command to display template, but which one is causing this problem and how do I find that out and fix it?  
I am confuse.

is this causing problem?

```
logstash-index-template" : {
    "order" : 0,
    "index_patterns" : [
      ".logstash"
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2019, 4:45pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/5 "2019-03-07T16:45:01Z")

</div>

May be this log happens when you start logstash?  
Or the template has been stored using the old field name "template" instead of "index\_patterns".  
When you GET the templates the old format is read, transformed on the fly to the new version.  
So you should just store it again using just what you got?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [March 7, 2019, 5:04pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/6 "2019-03-07T17:04:18Z")

</div>

this log is elasticsearch deprecation log

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2019, 6:20pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/7 "2019-03-07T18:20:22Z")

</div>

I know.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [March 7, 2019, 7:31pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/8 "2019-03-07T19:31:32Z")

</div>

so question is still there.  
how do I find where is it and how do I fix it?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2019, 7:45pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/9 "2019-03-07T19:45:42Z")

</div>

That's the question I answered.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [March 7, 2019, 8:03pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/10 "2019-03-07T20:03:51Z")

</div>

Well I didn't upderstand your answer.

anyway. how do I find where the hell this message coming from?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2019, 8:23pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/11 "2019-03-07T20:23:19Z")

</div>

It's coming from an existing template or from an application (logstash) which is sending a PUT template API request.

---

<div class="post-metadata">

**Author:** ![siradude](https://avatars.discourse-cdn.com/v4/letter/s/0ea827/32.png) [@siradude](https://discuss.elastic.co/u/siradude)\
**Post date:** [March 7, 2019, 8:45pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/12 "2019-03-07T20:45:27Z")

</div>

When upgrading from 6.2 to 6.6.1 did you look at this post?  
I'm new at this, Hope this helps in any way possible.

[https://www.elastic.co/guide/en/elastic-stack/6.6/upgrading-elastic-stack.html](https://www.elastic.co/guide/en/elastic-stack/6.6/upgrading-elastic-stack.html)

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [March 7, 2019, 8:55pm UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/13 "2019-03-07T20:55:23Z")

</div>

I didn't upgrade straight from 6.2 to 6.6.1. I did all the upgrade, mostly as soon as it came.  
as I was new to elk at that time.  
David, I understand it is coming from somewhere. but I don't have anywhere reference of template

[root@ ~]# cd /etc/logstash/  
[root@ logstash]# grep -i template \*

[root@ logstash]# grep -i template _/_  
[root@ logstash]# grep -i template _/_/\*

Then I ran GET /\_template/\*?pretty and look for template, found seven reference but they all are  
"dynamic\_templates"

Then search for patterns and found some. But do not know what this means, do not even know what this template means and where it comes or how do I fix it. or do I even have to worry about it or not  
Found three such reference "patterns"

```
"security-index-template" : {
    "order" : 1000,
    "index_patterns" : [
      ".security-*"
    ],
    "settings" : {
      "index" : {
        "format" : "6",
        "analysis" : {
          "filter" : {
            "email" : {
              "type" : "pattern_capture",
              "preserve_original" : "true",
              "patterns" : [
                "([^@]+)",
                "(\\p{L}+)",
                "(\\d+)",
                "@(.+)"
              ]
            }
          },
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 8, 2019, 11:16am UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/14 "2019-03-08T11:16:35Z")

</div>

I see. Can you share the whole output of the `GET /_template/` call? You can share it on [gist.github.com](http://gist.github.com).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2019, 11:16am UTC](https://discuss.elastic.co/t/deprecated-setting-where-is-it/171336/15 "2019-04-05T11:16:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
