# ES gives me 400 for my index template but its seems to be validate

**URL:** <https://discuss.elastic.co/t/es-gives-me-400-for-my-index-template-but-its-seems-to-be-validate/120278>\
**Category:** Logstash\
**Created:** [February 17, 2018, 12:41am UTC](https://discuss.elastic.co/t/es-gives-me-400-for-my-index-template-but-its-seems-to-be-validate/120278 "2018-02-17T00:41:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [February 17, 2018, 12:41am UTC](https://discuss.elastic.co/t/es-gives-me-400-for-my-index-template-but-its-seems-to-be-validate/120278/1 "2018-02-17T00:41:10Z")

</div>

Logstash can connect to the cluster fine and I can query [http://mycluster/\_template/](http://mycluster/_template/) so it looks like the 400 is just about something in the template it doesn't like.

I get this error:  
2018-02-17T00:35:11,571][INFO][logstash.outputs.elasticsearch] Installing elasticsearch template to \_template/iis-request-log  
[2018-02-17T00:35:11,703][ERROR][logstash.outputs.elasticsearch] Failed to install template. {:message=\>"Got response code '400' contacting Elasticsearch at URL '[http://mycluster:80/\_template/iis-request-log](http://mycluster:80/_template/iis-request-log)'", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError", ....

Im running ES 6.0

Here is my template, its valid json, not sure how to debug, ES gives me no useful info on what it doesn't like about it:  
{  
"template": "logstash-iis\*",  
"settings": {  
"number\_of\_shards": 5,  
"number\_of\_replicas": 1  
},  
"aliases": {  
"iis-request-logs": {}  
},  
"order": 12,  
"mappings": {  
"_default_": {  
"dynamic": false,  
"\_all": {  
"enabled": false  
},  
"properties": {  
"@timestamp": {  
"type": "date",  
"include\_in\_all": false  
},  
"@version": {  
"type": "keyword",  
"include\_in\_all": false  
},  
"bytesReceived": {  
"type": "long"  
},  
"bytesSent": {  
"type": "long"  
},  
"clientIP": {  
"type": "ip"  
},  
"cookie": {  
"type": "text",  
"norms": false  
},  
"userAgent\_device": {  
"type": "keyword"  
},  
"userAgent\_name": {  
"type": "keyword"  
},  
"userAgent\_os": {  
"type": "keyword"  
},  
"userAgent\_os\_name": {  
"type": "keyword"  
},  
"geoip": {  
"dynamic": "true",  
"properties": {  
"city\_name": {  
"type": "keyword"  
},  
"continent\_code": {  
"type": "keyword"  
},  
"country\_code2": {  
"type": "keyword"  
},  
"country\_code3": {  
"type": "keyword"  
},  
"country\_name": {  
"type": "keyword"  
},  
"dma\_code": {  
"type": "long"  
},  
"ip": {  
"type": "ip"  
},  
"latitude": {  
"type": "half\_float"  
},  
"location": {  
"type": "geo\_point"  
},  
"longitude": {  
"type": "half\_float"  
},  
"postal\_code": {  
"type": "keyword"  
},  
"region\_code": {  
"type": "keyword"  
},  
"region\_name": {  
"type": "keyword"  
},  
"timezone": {  
"type": "keyword"  
}  
}  
},  
"host": {  
"type": "ip"  
},  
"log\_timestamp": {  
"type": "keyword"  
},  
"message": {  
"type": "text",  
"norms": false  
},  
"method": {  
"type": "keyword"  
},  
"port": {  
"type": "long"  
},  
"protocolVersion": {  
"type": "keyword"  
},  
"referer": {  
"type": "text",  
"norms": false,  
"fields": {  
"keyword": {  
"type": "keyword"  
}  
}  
},  
"requestHost": {  
"type": "keyword"  
},  
"response": {  
"type": "keyword"  
},  
"serverIP": {  
"type": "ip"  
},  
"serverName": {  
"type": "keyword"  
},  
"serviceName": {  
"type": "keyword"  
},  
"subresponse": {  
"type": "keyword"  
},  
"tags": {  
"type": "text",  
"norms": false  
},  
"timetaken": {  
"type": "long"  
},  
"type": {  
"type": "keyword"  
},  
"uriQuery": {  
"type": "text",  
"norms": false  
},  
"uriStem": {  
"type": "keyword"  
},  
"userAgent": {  
"type": "keyword"  
},  
"username": {  
"type": "keyword"  
},  
"win32response": {  
"type": "keyword"  
},  
"xForwardedFor": {  
"type": "text",  
"norms": false  
},  
"xForwardedForProto": {  
"type": "text",  
"norms": false  
},  
"xForwardedForSrc": {  
"type": "ip",  
"fields": {  
"keyword": {  
"type": "keyword"  
}  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Ranjith\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranjith_m/32/19272_2.png) [@Ranjith\_M](https://discuss.elastic.co/u/Ranjith_M)\
**Post date:** [February 17, 2018, 3:13am UTC](https://discuss.elastic.co/t/es-gives-me-400-for-my-index-template-but-its-seems-to-be-validate/120278/2 "2018-02-17T03:13:11Z")

</div>

> [@red888](#):
>
> "template": "logstash-iis\*",

If I am not wrong in es 6 , this is not template any more but pattern.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [February 17, 2018, 8:57am UTC](https://discuss.elastic.co/t/es-gives-me-400-for-my-index-template-but-its-seems-to-be-validate/120278/3 "2018-02-17T08:57:02Z")

</div>

Remove the definition to the `_all` field and all `include_in_all` attributes.

This should work...

```auto
{
  "template": "logstash-iis*",
  "settings": {
    "number_of_shards": 5,
    "number_of_replicas": 1
  },
  "aliases": {
    "iis-request-logs": {}
  },
  "order": 12,
  "mappings": {
    "doc": {
      "dynamic": false,
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "@version": {
          "type": "keyword"
        },
        "bytesReceived": {
          "type": "long"
        },
        "bytesSent": {
          "type": "long"
        },
        "clientIP": {
          "type": "ip"
        },
        "cookie": {
          "type": "text",
          "norms": false
        },
        "userAgent_device": {
          "type": "keyword"
        },
        "userAgent_name": {
          "type": "keyword"
        },
        "userAgent_os": {
          "type": "keyword"
        },
        "userAgent_os_name": {
          "type": "keyword"
        },
        "geoip": {
          "dynamic": "true",
          "properties": {
            "city_name": {
              "type": "keyword"
            },
            "continent_code": {
              "type": "keyword"
            },
            "country_code2": {
              "type": "keyword"
            },
            "country_code3": {
              "type": "keyword"
            },
            "country_name": {
              "type": "keyword"
            },
            "dma_code": {
              "type": "long"
            },
            "ip": {
              "type": "ip"
            },
            "latitude": {
              "type": "half_float"
            },
            "location": {
              "type": "geo_point"
            },
            "longitude": {
              "type": "half_float"
            },
            "postal_code": {
              "type": "keyword"
            },
            "region_code": {
              "type": "keyword"
            },
            "region_name": {
              "type": "keyword"
            },
            "timezone": {
              "type": "keyword"
            }
          }
        },
        "host": {
          "type": "ip"
        },
        "log_timestamp": {
          "type": "keyword"
        },
        "message": {
          "type": "text",
          "norms": false
        },
        "method": {
          "type": "keyword"
        },
        "port": {
          "type": "long"
        },
        "protocolVersion": {
          "type": "keyword"
        },
        "referer": {
          "type": "text",
          "norms": false,
          "fields": {
            "keyword": {
              "type": "keyword"
            }
          }
        },
        "requestHost": {
          "type": "keyword"
        },
        "response": {
          "type": "keyword"
        },
        "serverIP": {
          "type": "ip"
        },
        "serverName": {
          "type": "keyword"
        },
        "serviceName": {
          "type": "keyword"
        },
        "subresponse": {
          "type": "keyword"
        },
        "tags": {
          "type": "text",
          "norms": false
        },
        "timetaken": {
          "type": "long"
        },
        "type": {
          "type": "keyword"
        },
        "uriQuery": {
          "type": "text",
          "norms": false
        },
        "uriStem": {
          "type": "keyword"
        },
        "userAgent": {
          "type": "keyword"
        },
        "username": {
          "type": "keyword"
        },
        "win32response": {
          "type": "keyword"
        },
        "xForwardedFor": {
          "type": "text",
          "norms": false
        },
        "xForwardedForProto": {
          "type": "text",
          "norms": false
        },
        "xForwardedForSrc": {
          "type": "ip",
          "fields": {
            "keyword": {
              "type": "keyword"
            }
          }
        }
      }
    }
  }
}

```

Hopefully that helps.

Rob

Robert Cowart ([rob@koiossian.com](mailto:rob@koiossian.com))  
[www.koiossian.com](http://www.koiossian.com)  
True Turnkey SOLUTIONS for the Elastic Stack

---

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [February 19, 2018, 2:33am UTC](https://discuss.elastic.co/t/es-gives-me-400-for-my-index-template-but-its-seems-to-be-validate/120278/4 "2018-02-19T02:33:22Z")

</div>

Thank you!!

I should have stated I used this template with 5.4 previously and I am know trying to use it with 6.0.

I did some googling after your post and found those fields are no longer valid. Thanks for looking at this for me!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2018, 2:33am UTC](https://discuss.elastic.co/t/es-gives-me-400-for-my-index-template-but-its-seems-to-be-validate/120278/5 "2018-03-19T02:33:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
