# Elasticsearch Index Template

**URL:** <https://discuss.elastic.co/t/elasticsearch-index-template/120218>\
**Category:** Elasticsearch\
**Created:** [February 16, 2018, 4:28pm UTC](https://discuss.elastic.co/t/elasticsearch-index-template/120218 "2018-02-16T16:28:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gittinfunky](https://avatars.discourse-cdn.com/v4/letter/g/b5ac83/32.png) [@gittinfunky](https://discuss.elastic.co/u/gittinfunky)\
**Post date:** [February 16, 2018, 4:28pm UTC](https://discuss.elastic.co/t/elasticsearch-index-template/120218/1 "2018-02-16T16:28:38Z")

</div>

I am following this tutorial and trying to send tshark captures to ELK.

[https://www.elastic.co/blog/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana](http://Tutorial)

I am required to create an elasticsearch mapping but am confused as to what this is. Does this mean to create an index template like below

packets-index\_pattern.json

```
PUT _template/packets
{
  "template": "packets-*",
  "mappings": {
"pcap_file": {
  "dynamic": "false",
  "properties": {
    "timestamp": {
      "type": "date"
    },
    "layers": {
      "properties": {
        "frame": {
          "properties": {
            "frame_frame_len": {
              "type": "long"
            },
            "frame_frame_protocols": {
              "type": "keyword"
            }
          }
        },
        "ip": {
          "properties": {
            "ip_ip_src": {
              "type": "ip"
            },
            "ip_ip_dst": {
              "type": "ip"
            }
          }
        },
        "udp": {
          "properties": {
            "udp_udp_srcport": {
              "type": "integer"
            },
            "udp_udp_dstport": {
              "type": "integer"
            }
          }
        }
      }
    }
  }
}
  }
}

```

So far I have created a file called packets-index\_pattern.json and tried to upload it to Elasticsearch using the below, however I get an error saying status 400 curl: (6) could not resolve host: Content-Type

`curl -XPUT 'localhost:9200/_template/packets-?pretty' -H 'Content-Type: application/json'`

Any help glady accepted

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2018, 4:28pm UTC](https://discuss.elastic.co/t/elasticsearch-index-template/120218/2 "2018-03-16T16:28:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
