# Error when using template generated by ECS Tooling (1.7 and master) for datastream

**URL:** <https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016>\
**Category:** Elasticsearch\
**Tags:** ecs-elastic-common-schema\
**Created:** [February 2, 2021, 5:22pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016 "2021-02-02T17:22:06Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![mxu](https://avatars.discourse-cdn.com/v4/letter/m/90ced4/32.png) [@mxu](https://discuss.elastic.co/u/mxu)\
**Post date:** [February 2, 2021, 5:22pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016/1 "2021-02-02T17:22:06Z")

</div>

ECS Tooling (1.7.0 and master) generates template as following with my template-settings input:

```auto
{
   "index_patterns":[
      "my-data-stream*"
   ],
   "data_stream":{
   },
   "mappings":{
      "properties":{
         "message":{
            "type":"text"
         }
      }
   },
   "settings":{
      "index":{
         "lifecycle":{
            "name":"my-ilm-policy"
         },
         "mapping":{
            "total_fields":{
               "limit":10000
            }
         }
      }
   }
}

```

Pushing this template to elasticsearch (7.10.2), causing error:

```auto
"x_content_parse_exception","reason":"[4:3] [index_template] unknown field [mappings]"}.

```

It works with following format:

```auto
{
   "index_patterns":[
      "my-data-stream*"
   ],
   "data_stream":{
   },
   "template":{
      "mappings":{
         "properties":{
            "message":{
               "type":"text"
            }
         }
      }
   },
   "settings":{
      "index":{
         "lifecycle":{
            "name":"my-ilm-policy"
         },
         "mapping":{
            "total_fields":{
               "limit":10000
            }
         }
      }
   }
}

```

Note there's "template" here. I added "template" to template-settings for the tool without luck.

Is this supported by ECS Tooling? Any hidden options?  
Thanks for any help,

Meimei

---

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [February 5, 2021, 8:28pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016/2 "2021-02-05T20:28:52Z")

</div>

Currently, there are two different types of Elasticsearch index templates that the tooling generates:

- The first is compatible with the [legacy index template API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates-v1.html), `_template`. This type will appear in the output directory at `generated/elasticsearch/7/template.json` for the 7.x compatible version.

- The second is intended for use with the v2 [index template API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-template.html), `_index_template`. The generated example in the ECS tooling also makes use of component templates (more details [here](https://github.com/elastic/ecs/tree/master/generated/elasticsearch#sample-elasticsearch-templates-for-ecs)). The component template will be found at `generated/elasticsearch/template.json` with the component templates in the `generated/elasticsearch/component` directory.

Which template file are you trying to use in these examples?

Based on the `error` message and use of `data_stream: { }`, it looks like you're using the `_index_template` API?

You're correct that the exception from `_index_template` API is due to the `aliases`, `mappings`, and `settings` configs to be nested underneath `template` now:

```auto
POST _index_template/my-data-stream
{
  "index_patterns": [
    "my-data-stream*"
  ],
  "data_stream": {},
  "template": {
    "mappings": {
      "properties": {
        "message": {
          "type": "text"
        }
      }
    },
    "settings": {
      "index": {
        "lifecycle": {
          "name": "my-ilm-policy"
        },
        "mapping": {
          "total_fields": {
            "limit": 10000
          }
        }
      }
    }
  }
}

```

There's a [known issue](https://github.com/elastic/ecs/pull/1205) for the ECS tooling where custom settings for `--template-settings` aren't applied to the generated composable template. You may be experiencing the same problem if you're not seeing your `--template-settings` applied correctly. Work is in progress to fix this issue.

---

<div class="post-metadata">

**Author:** ![mxu](https://avatars.discourse-cdn.com/v4/letter/m/90ced4/32.png) [@mxu](https://discuss.elastic.co/u/mxu)\
**Post date:** [February 5, 2021, 9:35pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016/3 "2021-02-05T21:35:38Z")

</div>

Eric, thanks for the response.  
Yes, I am using \_index\_template API.  
I was using generated/elasticsearch/7/template.json for the above API and ran into exception.  
For now, we can manually edit either template.json files to have it work with \_index\_template (required by datastream).

Thanks for your help.

mm

---

<div class="post-metadata">

**Author:** ![mxu](https://avatars.discourse-cdn.com/v4/letter/m/90ced4/32.png) [@mxu](https://discuss.elastic.co/u/mxu)\
**Post date:** [February 8, 2021, 2:07pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016/4 "2021-02-08T14:07:11Z")

</div>

@ebeahan is there option to generate one index template instead of component index in 1.8?  
Thanks for your help,  
Meimei

---

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [February 9, 2021, 7:08pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016/5 "2021-02-09T19:08:18Z")

</div>

Yes, the legacy index templates are still generated as artifacts in the output: `generated/elasticsearch/<version>/template.json`.

---

<div class="post-metadata">

**Author:** ![mxu](https://avatars.discourse-cdn.com/v4/letter/m/90ced4/32.png) [@mxu](https://discuss.elastic.co/u/mxu)\
**Post date:** [February 11, 2021, 2:00pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016/6 "2021-02-11T14:00:25Z")

</div>

Thanks.

We extend ECS schemas and named object starting with upper case, e.g., Link, Metric.Cpu.  
The tool generates index template with composed\_of as following:

```auto
"composed_of": [
    "ecs_2.0.0-dev_agent",
    "ecs_2.0.0-dev_base",
    "...",
    "ecs_2.0.0-dev_Metric.Cpu",
    "ecs_2.0.0-dev_Link" 
  ]

```

Elasticsearch throws exception due to upper case in the component\_index names.  
Is there an option to have all lower case for component index names?  
Is there a way to have ONLY index template and NOT component templates in ECS Tooling 1.8 (just as legacy template)?

Thanks,

mm

---

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [February 11, 2021, 4:49pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016/7 "2021-02-11T16:49:42Z")

</div>

> [@mxu](#):
>
> Elasticsearch throws exception due to upper case in the component\_index names.

This is a bug since a component template name must be lower case. I've created an issue to track [here](https://github.com/elastic/ecs/issues/1259).

> [@mxu](#):
>
> Is there a way to have ONLY index template and NOT component templates in ECS Tooling 1.8 (just as legacy template)?

This isn't something the tooling generates today. It either the single template using the legacy template format or the current index template format using composable templates.

---

<div class="post-metadata">

**Author:** ![mxu](https://avatars.discourse-cdn.com/v4/letter/m/90ced4/32.png) [@mxu](https://discuss.elastic.co/u/mxu)\
**Post date:** [February 11, 2021, 7:38pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016/8 "2021-02-11T19:38:21Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2021, 7:39pm UTC](https://discuss.elastic.co/t/error-when-using-template-generated-by-ecs-tooling-1-7-and-master-for-datastream/263016/9 "2021-03-11T19:39:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
