# Disable logstash default template creation

**URL:** <https://discuss.elastic.co/t/disable-logstash-default-template-creation/36965>\
**Category:** Elasticsearch\
**Created:** [December 11, 2015, 10:06am UTC](https://discuss.elastic.co/t/disable-logstash-default-template-creation/36965 "2015-12-11T10:06:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaminvp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaminvp/32/5868_2.png) [@jaminvp](https://discuss.elastic.co/u/jaminvp)\
**Post date:** [December 11, 2015, 10:06am UTC](https://discuss.elastic.co/t/disable-logstash-default-template-creation/36965/1 "2015-12-11T10:06:58Z")

</div>

Greetings,

I have an issue with Logstash constantly creating a template corresponding to one of my indexes, which messes with the parsing of the fields.

I have 4 indexes, let's call them "foo","fii","faa","fee".

When I don't do something about it, logstash/elasticsearch immediately creates the following template:

{-

"logstash" : {-

"order" : 0,

"template" : "foo",

"settings" : {-

...  
}  
}

With my custom template below this one:

"f\_template" : {-

"order" : 0,

"template" : "f\*",

"settings" : {-  
...  
}  
}  
Is there a way to prevent elasticsearch/logstash adding the first template and linking it to "foo"?

Update: I fixed it in a dirty way by changing the logstash template "template"-field to "logstash-\*" using a POST-query, removing the foo index and resending all the foo-logs.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 13, 2015, 4:46am UTC](https://discuss.elastic.co/t/disable-logstash-default-template-creation/36965/2 "2015-12-13T04:46:09Z")

</div>

You can also use [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-manage\_template](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-manage_template)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:31pm UTC](https://discuss.elastic.co/t/disable-logstash-default-template-creation/36965/3 "2017-07-05T23:31:30Z")

</div>


