# \#! Deprecation: Deprecated field \[template\] used, replaced by \[index\_patterns\]

**URL:** <https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943>\
**Category:** Elasticsearch\
**Created:** [April 29, 2018, 7:10am UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943 "2018-04-29T07:10:22Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yaasar\_Shaikh](https://avatars.discourse-cdn.com/v4/letter/y/bbe5ce/32.png) [@Yaasar\_Shaikh](https://discuss.elastic.co/u/Yaasar_Shaikh)\
**Post date:** [April 29, 2018, 7:10am UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943/1 "2018-04-29T07:10:22Z")

</div>

iam trying to create a new index but this error occurs

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 29, 2018, 8:09am UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943/2 "2018-04-29T08:09:23Z")

</div>

Share what you are doing. The exact commands, version...

---

<div class="post-metadata">

**Author:** ![Hunsin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsin/32/30596_2.png) [@Hunsin](https://discuss.elastic.co/u/Hunsin)\
**Post date:** [April 30, 2018, 9:30am UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943/3 "2018-04-30T09:30:58Z")

</div>

I'm facing similar problem and looking for help. Steps to reproduce:

- Environment: new created GCP compute engine, Debian 9, only Docker installed
- Version: Filebeat, Elasticsearch, Kibana, all 6.2.4, Docker image

```auto
$ docker network create ebk

$ sudo sysctl -w vm.max_map_count=262144

$ docker run -d --network=ebk --name es1 -p 9200:9200 -p 9300:9300 -e ELASTIC_PASSWORD=<password> -e "ES_JAVA_OPTS=-Xms2g -Xmx2g" -v path/to/data:/usr/share/elasticsearch/data docker.elastic.co/elasticsearch/elasticsearch:6.2.4

$ docker run -d --network=ebk --name kibana -p 5601:5601 -v path/to/kibana.yml:/usr/share/kibana/config/kibana.yml docker.elastic.co/kibana/kibana:6.2.4

$ touch filebeat.yml

```

Content of `filebeat.yml`:

```auto
filebeat.prospectors:
- type: log
  enabled: true
  paths: /var/log/*.log

output.elasticsearch:
  hosts: ["es1:9200"]
  username: elastic
  password: <password>

setup.dashboards:
  enabled: true

setup.kibana:
  host: "kibana:5601"

```

Everything goes well so far. Then I start filebeat:

```auto
$ docker run -d --network=ebk --name fbeat -v path/to/filebeat.yml:/usr/share/filebeat/filebeat.yml -v path/to/log:/var/log --hostname <hostname> docker.elastic.co/beats/filebeat:6.2.4

```

Each time I start `fbeat` container, elasticsearch generates 2X lines of same log:

```auto
[2018-04-30T08:52:40,438][WARN][o.e.d.a.a.i.t.p.PutIndexTemplateRequest] Deprecated field [template] used, replaced by [index_patterns]

```

---

<div class="post-metadata">

**Author:** ![Bernt\_Rostad](https://avatars.discourse-cdn.com/v4/letter/b/3ab097/32.png) [@Bernt\_Rostad](https://discuss.elastic.co/u/Bernt_Rostad)\
**Post date:** [April 30, 2018, 10:34am UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943/4 "2018-04-30T10:34:42Z")

</div>

After version 5.6 the format of Elasticsearch [index templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html) changed; the **template** field, which was used to specify one or more patterns for matching index names that would use the template at create time, was deprecated and superseded by the more appropriately named field **index\_patterns** which works exactly the same way.

To solve the issue and get rid of the deprecation warnings you will have to update all your pre-6.0 index templates, changing the **template** to **index\_patterns**.

You can list all your index templates by running this command:

`curl -XGET 'http://localhost:9200/_template/*?pretty'`

Or replace the asterisk with the name of one specific index template.

---

<div class="post-metadata">

**Author:** ![Yaasar\_Shaikh](https://avatars.discourse-cdn.com/v4/letter/y/bbe5ce/32.png) [@Yaasar\_Shaikh](https://discuss.elastic.co/u/Yaasar_Shaikh)\
**Post date:** [May 1, 2018, 7:41am UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943/5 "2018-05-01T07:41:34Z")

</div>

thanks,it worked for me.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 8, 2018, 9:06am UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943/6 "2018-05-08T09:06:25Z")

</div>

@Hunsin You mount a data directory. Could it be that this contains old Elasticsearch data or is it a fresh empty directory? Could you share your full Filebeat and Elasticsearch log?

I tried to reproduce a simplified version by just starting and 6.2.4 elasticsearch container and point 6.2.4 Filebeat at it but without success.

---

<div class="post-metadata">

**Author:** ![Hunsin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hunsin/32/30596_2.png) [@Hunsin](https://discuss.elastic.co/u/Hunsin)\
**Post date:** [May 9, 2018, 6:33am UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943/7 "2018-05-09T06:33:36Z")

</div>

@ruflin it's an empty directory.  
If I remove `setup.dashboards.enabled: true` from the `filebeat.yml`, then no more log generated from ES.  
Is it a bad configuration or something related to Kibana?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 11, 2018, 1:54pm UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943/8 "2018-05-11T13:54:05Z")

</div>

@Hunsin This was the key. I managed to reproduce this. It seems that somehow when running with `--setup` the Kibana API does something that triggers this. I will check further internally where this is coming from. Probably an API in Kibana that is not update yet.

Thanks for being consistent and pushing this forward.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2018, 1:54pm UTC](https://discuss.elastic.co/t/deprecation-deprecated-field-template-used-replaced-by-index-patterns/129943/9 "2018-06-08T13:54:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
