# Dynamic Template not applying

**URL:** <https://discuss.elastic.co/t/dynamic-template-not-applying/51905>\
**Category:** Elasticsearch\
**Created:** [June 6, 2016, 6:38am UTC](https://discuss.elastic.co/t/dynamic-template-not-applying/51905 "2016-06-06T06:38:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![James\_Tighe](https://avatars.discourse-cdn.com/v4/letter/j/8797f3/32.png) [@James\_Tighe](https://discuss.elastic.co/u/James_Tighe)\
**Post date:** [June 6, 2016, 6:38am UTC](https://discuss.elastic.co/t/dynamic-template-not-applying/51905/1 "2016-06-06T06:38:18Z")

</div>

Hi Guys,

I have an issue with my index template not working as I would expect.

I have an index being created from my Filebeats input. This index is called **"testlogs"** and a type of **"testlog"**.

As I have set a specific index name I had tried to import the filebeats template and change the index and type names to match my specific settings. The issue is that the index does not appear to be being applied.

My newly created (by Logstash GROK filter) fields are being set to be analysed. The Dynamic\_template option should set all newly discovered fields to be not\_analyzed. My template is below.

"template\_2": {  
"order": 0,  
"template": "testlogs-_",  
"settings": {  
"index": {  
"refresh\_interval": "5s"  
}  
},  
"mappings": {  
"testlog": {  
"dynamic\_templates": [  
{  
"fields": {  
"path\_match": "fields._",  
"mapping": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
},  
"match\_mapping\_type": "string"  
}  
}  
],  
"\_all": {  
"norms": {  
"enabled": false  
}  
},  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"offset": {  
"type": "long"  
},  
"beat": {  
"properties": {  
"hostname": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
},  
"name": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
}  
}  
},  
"input\_type": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
},  
"source": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
},  
"message": {  
"norms": {  
"enabled": false  
},  
"index": "analyzed",  
"type": "string"  
},  
"type": {  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "string"  
}  
}  
}  
},  
"aliases": {}  
}

Is there something wrong with the dynamic\_template section is because I have set the index and type name? I understand I could manually map the fields but I would rather have the dynamic mapping set all fields as not\_analyzed and then enable analysing on specific fields.

It worked fine before I manually changed the index name from filebeat-\* to an actual name.

Any help would be appreciated.

James

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 6, 2016, 7:04am UTC](https://discuss.elastic.co/t/dynamic-template-not-applying/51905/2 "2016-06-06T07:04:06Z")

</div>

Your type looks ok, but;

> [@James\_Tighe](#):
>
> This index is called "testlogs"

> [@James\_Tighe](#):
>
> "template": "testlogs-\*",

These don't match? What does your LS config look like?

---

<div class="post-metadata">

**Author:** ![James\_Tighe](https://avatars.discourse-cdn.com/v4/letter/j/8797f3/32.png) [@James\_Tighe](https://discuss.elastic.co/u/James_Tighe)\
**Post date:** [June 6, 2016, 7:41am UTC](https://discuss.elastic.co/t/dynamic-template-not-applying/51905/3 "2016-06-06T07:41:11Z")

</div>

Sorry the index is called **"testlogs-YYYY.MM.dd"** so the template should match on **"testlogs-\*"**

My LS Config is below

input {  
beats {  
port =\> 5044  
codec =\> multiline {  
pattern =\> "^[0-2][0-9]-[0-2][0-9]-[0-3][0-9] [0-2][0-9]:[0-5][0-9]:[0-5][0-9].[0-9]{3}"  
negate =\> "true"  
what =\> "previous"  
max\_lines =\> 600  
}  
}  
}

filter {  
if [type] == "OdinBA" {  
grok {  
patterns\_dir =\> ["./patterns"]  
match =\> { "message" =\> "%{ODINTIME:time} %{NOTSPACE:Process} %{GREEDYDATA:ID} %{PRIORITY:Priority} %{GREEDYDATA:Message}" }  
match =\> { "source" =\> "%{GREEDYDATA}\%{GREEDYDATA}\%{GREEDYDATA}\%{GREEDYDATA:Filename}.log" }  
break\_on\_match =\> false  
}  
date {  
match =\> ["time", "YY-MM-dd HH:mm:ss.SSS"]  
}  
mutate {  
gsub =\> ["Priority", "]", " " ]  
}  
}  
if [type] == "testlogs" {  
grok {  
patterns\_dir =\> ["./patterns"]  
match =\> { "message" =\> "%{ODINTIME:time} %{NOTSPACE:Process} %{GREEDYDATA:ID} %{PRIORITY:Priority} %{GREEDYDATA:Message}" }  
match =\> { "source" =\> "%{GREEDYDATA}\%{GREEDYDATA}\%{GREEDYDATA:Filename}.log" }  
break\_on\_match =\> false  
}  
date {  
match =\> ["time", "YY-MM-dd HH:mm:ss.SSS"]  
}  
mutate {  
gsub =\> ["Priority", "]", " "]  
}  
}  
}

output {  
if [type] == "OdinBA" {  
elasticsearch {  
hosts =\> ["192.169.38.123:9200","192.168.38.124:9200"]  
manage\_template =\> false  
index =\> "odinba-%{+YYYY.MM.dd}"  
document\_type =\> "BALog"  
}  
}  
if [type] == "testlogs" {  
elasticsearch {  
hosts =\> ["192.168.38.123:9200","192.168.38.124:9200"]  
manage\_template =\> false  
index =\> "testlogs-%{+YYYY.MM.dd}"  
document\_type =\> "testlog"  
}  
}  
}

My config splits the filebeat input into 2 different indexes and sets the type. This seems to work fine and both indexes appear. Elasticsearch sees the index and shows the document\_type as testlog so the output looks okay.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:46pm UTC](https://discuss.elastic.co/t/dynamic-template-not-applying/51905/4 "2017-07-05T22:46:02Z")

</div>


