# Edit index template settings

**URL:** <https://discuss.elastic.co/t/edit-index-template-settings/251142>\
**Category:** Elasticsearch\
**Created:** [October 6, 2020, 2:03pm UTC](https://discuss.elastic.co/t/edit-index-template-settings/251142 "2020-10-06T14:03:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikejdunphy](https://avatars.discourse-cdn.com/v4/letter/m/6a8cbe/32.png) [@mikejdunphy](https://discuss.elastic.co/u/mikejdunphy)\
**Post date:** [October 6, 2020, 2:03pm UTC](https://discuss.elastic.co/t/edit-index-template-settings/251142/1 "2020-10-06T14:03:04Z")

</div>

so I have 2 indexes created everyday on my elkstack  
filebeat-%{[@metadata][version]}-2020.10.03  
filebeat-7.9.2-2020.10.03

the filebeat-7.9.2-2020.10.03 is from the elk server itself and the other  
is from filebeat from 2 remote syslog servers that collects all our logs with filebeat

It would be fine even tho the metadata and version are not getting filled out except the search doesn’t work, when I discover/search I only  
get the elkstack ubuntu server and a bunch of error popups for 1 of 3 shards failed  
I traced it down to the index not having this in the settings  
"index.max\_docvalue\_fields\_search": "200"

When I edit it manually and add it .. it works, I am trying to find a way to addit when the  
new index is created everyday

I tried adding that to the /etc/filebeat/filebeat.yml so that it would add it on creation but no luck  
setup.template.settings:  
index.number\_of\_shards: 1  
index.max\_docvalue\_fields\_search: 200  
Also the filebeat-7.9.2\* index from the elkserver itself has a template with this info and the other is not so I cloned it and called filebeat- in the hopes that it would use that but it would not  
Any ideas ?

---

<div class="post-metadata">

**Author:** ![mikejdunphy](https://avatars.discourse-cdn.com/v4/letter/m/6a8cbe/32.png) [@mikejdunphy](https://discuss.elastic.co/u/mikejdunphy)\
**Post date:** [October 19, 2020, 5:07pm UTC](https://discuss.elastic.co/t/edit-index-template-settings/251142/2 "2020-10-19T17:07:10Z")

</div>

I figured it out ... I cloned the filebeat index and called it filebeat-\* I was missing the '\*' so it didnt match

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2020, 5:07pm UTC](https://discuss.elastic.co/t/edit-index-template-settings/251142/3 "2020-11-16T17:07:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
