# \[es7.6.2\]\[logstash7.6.2\]Why logstash maps to the default index template when the index name not match the index\_patterns?

**URL:** <https://discuss.elastic.co/t/es7-6-2-logstash7-6-2-why-logstash-maps-to-the-default-index-template-when-the-index-name-not-match-the-index-patterns/228769>\
**Category:** Logstash\
**Created:** [April 20, 2020, 2:38am UTC](https://discuss.elastic.co/t/es7-6-2-logstash7-6-2-why-logstash-maps-to-the-default-index-template-when-the-index-name-not-match-the-index-patterns/228769 "2020-04-20T02:38:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [April 20, 2020, 2:38am UTC](https://discuss.elastic.co/t/es7-6-2-logstash7-6-2-why-logstash-maps-to-the-default-index-template-when-the-index-name-not-match-the-index-patterns/228769/1 "2020-04-20T02:38:21Z")

</div>

Hi Team,

When starting logstash, I see below log which means that my data will be indexed according to default template structure.

> ```
> [2020-04-16T13:05:48,661][INFO] [logstash.outputs.elasticsearch][main] Using default mapping template
> [2020-04-16T13:05:48,718][INFO][logstash.outputs.elasticsearch][main] Attempting to install template {:manage_template=>{"index_patterns"=>"logstash-*", "version"=>60001, "settings"=>{"index.refresh_interval"=>"5s", "number_of_shards"=>1}, "mappings"=>{"dynamic_templates"=>[{"message_field"=>{"path_match"=>"message", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false}}}, {"string_fields"=>{"match"=>"*", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false, "fields"=>{"keyword"=>{"type"=>"keyword", "ignore_above"=>256}}}}}], "properties"=>{"@timestamp"=>{"type"=>"date"}, "@version"=>{"type"=>"keyword"}, "geoip"=>{"dynamic"=>true, "properties"=>{"ip"=>{"type"=>"ip"}, "location"=>{"type"=>"geo_point"}, "latitude"=>{"type"=>"half_float"}, "longitude"=>{"type"=>"half_float"}}}}}}}
> 
> ```

What confuse me is that the conditions to match the default template is that index name must start with "logstash-", but the index name I defined in logstash.conf is "uba", which means that it's impossible match to the default template. Anyone know what's the reason

> output {  
> elasticsearch {  
> action =\> "index"  
> hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
> index =\> "uba" }  
> stdout { codec =\> rubydebug {metadata =\> true}}  
> }

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 20, 2020, 2:42pm UTC](https://discuss.elastic.co/t/es7-6-2-logstash7-6-2-why-logstash-maps-to-the-default-index-template-when-the-index-name-not-match-the-index-patterns/228769/2 "2020-04-20T14:42:29Z")

</div>

> [@cheriemilk](#):
>
> I see below log which means that my data will be indexed according to default template structure

No, it doesn't. It means the elasticsearch output has installed a default template which applies to indexes that match the `logstash-*` pattern. Yours does not, so it will not apply.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2020, 2:42pm UTC](https://discuss.elastic.co/t/es7-6-2-logstash7-6-2-why-logstash-maps-to-the-default-index-template-when-the-index-name-not-match-the-index-patterns/228769/3 "2020-05-18T14:42:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
