# Difference between logstash .conf file and elastic template file

**URL:** <https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269>\
**Category:** Elasticsearch\
**Created:** [April 24, 2018, 9:12am UTC](https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269 "2018-04-24T09:12:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![SRIpandu1729](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripandu1729/32/27368_2.png) [@SRIpandu1729](https://discuss.elastic.co/u/SRIpandu1729)\
**Post date:** [April 24, 2018, 9:12am UTC](https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269/1 "2018-04-24T09:12:20Z")

</div>

Why do we need templates even though we have logstash configuraion files or the question would be reiterated as what is the difference between logstash's configuration file and elastic's template file? (Here what I mean to say is if we can change some types using mutate in logstash conf file, why do we need templates? Am I looking at it completely wrong?)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 24, 2018, 9:19am UTC](https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269/2 "2018-04-24T09:19:51Z")

</div>

When you cast fields in Logstash, you change the way they are represented in the JSON documents sent to Elasticsearch. That is why you have a [limited number of types to choose from](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-convert).

When this reaches Elasticsearch, the index template tells Elasticsearch how these fields should be interpreted. If no template is present, Elasticsearch will attempt to use dynamic mapping, but there is a limit to what it can map automatically, and this does not include e.g. IP and geo\_ip fields.

---

<div class="post-metadata">

**Author:** ![SRIpandu1729](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripandu1729/32/27368_2.png) [@SRIpandu1729](https://discuss.elastic.co/u/SRIpandu1729)\
**Post date:** [April 24, 2018, 9:27am UTC](https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269/3 "2018-04-24T09:27:27Z")

</div>

Thanks @Christian_Dahlqvist for the reply.

Those fields are the main reason why I asked this question continuing from this [one](https://discuss.elastic.co/t/inconsistent-results-using-lucene-query-syntax/129034). So what are the pros and cons of not mapping ip's as type 'ip' and instead leaving them as strings? Which one should we prefer? (The same with geo\_ip as well?) Thanks 🙂 in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 24, 2018, 9:29am UTC](https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269/4 "2018-04-24T09:29:26Z")

</div>

Well, geo\_ip fields need to be mapped if you are going to be able to use maps. When it comes to IP fields the ideal mapping depends on how you want to be able to query them.

---

<div class="post-metadata">

**Author:** ![SRIpandu1729](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripandu1729/32/27368_2.png) [@SRIpandu1729](https://discuss.elastic.co/u/SRIpandu1729)\
**Post date:** [April 24, 2018, 9:32am UTC](https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269/5 "2018-04-24T09:32:51Z")

</div>

Does it make any difference as far as storage is concerned?

And if queries are mostly range based queries which is better?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 24, 2018, 9:38am UTC](https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269/6 "2018-04-24T09:38:27Z")

</div>

I would map it as ip type as it supports [IP range aggregations](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/search-aggregations-bucket-iprange-aggregation.html) and probably takes up less space.

---

<div class="post-metadata">

**Author:** ![SRIpandu1729](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripandu1729/32/27368_2.png) [@SRIpandu1729](https://discuss.elastic.co/u/SRIpandu1729)\
**Post date:** [April 24, 2018, 9:40am UTC](https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269/7 "2018-04-24T09:40:39Z")

</div>

Thank you very much @Christian_Dahlqvist

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2018, 9:40am UTC](https://discuss.elastic.co/t/difference-between-logstash-conf-file-and-elastic-template-file/129269/8 "2018-05-22T09:40:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
