# "Failed to install template... contact Elasticsearch"

**URL:** <https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687>\
**Category:** Logstash\
**Created:** [November 2, 2016, 9:06am UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687 "2016-11-02T09:06:35Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![bme](https://avatars.discourse-cdn.com/v4/letter/b/d2c977/32.png) [@bme](https://discuss.elastic.co/u/bme)\
**Post date:** [November 2, 2016, 9:06am UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687/1 "2016-11-02T09:06:35Z")

</div>

I am testing elastic search with logstash and filebeats, trying to import our IIS log for analysing and viewing in Kibana. All latest version (5.0).

I have run into a problem during the startup of logstash where it says this during startup:

[2016-11-02T09:57:12,578][WARN][logstash.runner] SIGINT received. Shutting down the agent.  
[2016-11-02T09:57:12,687][WARN][logstash.agent] stopping pipeline {:id=\>"main"}  
[2016-11-02T09:58:44,305][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=\>"192.168.0.2:5045"}  
[2016-11-02T09:58:44,633][INFO][org.logstash.beats.Server] Starting server on port: 5045  
[2016-11-02T09:58:45,008][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>["[http://192.168.0.2:9200](http://192.168.0.2:9200)"]}}  
[2016-11-02T09:58:45,027][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>"M:\logstash-5.0.0\config\iis.myapp.template.json"}  
[2016-11-02T09:58:45,258][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"mappings"=\>{"_default_"=\>{"\_all"=\>{"enabled"=\>true, "norms"=\>{"enabled"=\>false}}, "dynamic\_templates"=\>[{"iisTemplate"=\>{"mapping"=\>{"doc\_values"=\>true, "ignore\_above"=\>1024, "index"=\>"not\_analyzed", "type"=\>"{dynamic\_type}"}, "match"=\>"_"}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "index"=\>"analyzed"}, "status"=\>{"type"=\>"integer", "index"=\>"analyzed", "doc\_values"=\>true}, "timeTaken"=\>{"type"=\>"integer", "index"=\>"analyzed", "doc\_values"=\>true}, "bytesSent"=\>{"type"=\>"integer", "index"=\>"analyzed", "doc\_values"=\>true}, "bytesTotal"=\>{"type"=\>"integer", "index"=\>"analyzed", "doc\_values"=\>false}, "bytesReceived"=\>{"type"=\>"integer", "index"=\>"analyzed", "doc\_values"=\>true}, "subStatus"=\>{"type"=\>"integer", "index"=\>"not\_analyzed"}, "geoip"=\>{"type"=\>"object", "dynamic"=\>"true", "index"=\>"analyzed", "properties"=\>{"location"=\>{"type"=\>"geo\_point"}}}}}, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "template"=\>"iis-_"}}}  
[2016-11-02T09:58:45,274][INFO][logstash.outputs.elasticsearch] Installing elasticsearch template to \_template/logstash  
**[2016-11-02T09:58:45,305][ERROR][logstash.outputs.elasticsearch] Failed to install template. {:message=\>"Got response code '400' contact Elasticsearch at URL '[http://192.168.0.2:9200/\_template/logstash](http://192.168.0.2:9200/_template/logstash)'", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError"}**  
[2016-11-02T09:58:45,321][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["192.168.0.2:9200"]}  
[2016-11-02T09:58:45,586][INFO][logstash.filters.geoip] Using geoip database {:path=\>"M:\logstash-5.0.0\GeoLite2-City.mmdb"}  
[2016-11-02T09:58:45,618][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>500}  
[2016-11-02T09:58:45,618][INFO][logstash.pipeline] Pipeline main started  
[2016-11-02T09:58:45,774][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

Can anyone tell me from this what the issue could be? Elastic pointed me to this forum...

The template is present in the log above.

Also, the default configuration of elasticsearch itself seems to cause it to crash (multiple exceptions and out-of-memory errors). I had hoped elasticsearch could handle it a bit better when memory was tight instead of outright failing. :-/

Thanks,

Bernhard

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 2, 2016, 9:07am UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687/2 "2016-11-02T09:07:25Z")

</div>

Check your ES logs;

> [@bme](#):
>
> Got response code '400'

Means something wasn't accepted in ES.

---

<div class="post-metadata">

**Author:** ![bme](https://avatars.discourse-cdn.com/v4/letter/b/d2c977/32.png) [@bme](https://discuss.elastic.co/u/bme)\
**Post date:** [November 2, 2016, 9:11am UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687/3 "2016-11-02T09:11:27Z")

</div>

I cannot see anything wrong looking in the elasticsearch log:

[2016-11-02T09:57:49,563][INFO][o.e.n.Node] [] initializing ...  
[2016-11-02T09:57:49,704][INFO][o.e.e.NodeEnvironment] [OGKkOnR] using [1] data paths, mounts [[MainDb (M:)]], net usable\_space [987.4gb], net total\_space [999.8gb], spins? [unknown], types [NTFS]  
[2016-11-02T09:57:49,704][INFO][o.e.e.NodeEnvironment] [OGKkOnR] heap size [1.9gb], compressed ordinary object pointers [true]  
[2016-11-02T09:57:49,766][INFO][o.e.n.Node] [OGKkOnR] node name [OGKkOnR] derived from node ID; set [[node.name](http://node.name)] to override  
[2016-11-02T09:57:49,766][INFO][o.e.n.Node] [OGKkOnR] version[5.0.0], pid[23916], build[253032b/2016-10-26T04:37:51.531Z], OS[Windows Server 2012/6.2/amd64], JVM[Oracle Corporation/Java HotSpot(TM) 64-Bit Server VM/1.8.0\_101/25.101-b13]  
[2016-11-02T09:57:51,344][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [aggs-matrix-stats]  
[2016-11-02T09:57:51,344][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [ingest-common]  
[2016-11-02T09:57:51,344][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [lang-expression]  
[2016-11-02T09:57:51,344][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [lang-groovy]  
[2016-11-02T09:57:51,344][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [lang-mustache]  
[2016-11-02T09:57:51,344][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [lang-painless]  
[2016-11-02T09:57:51,344][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [percolator]  
[2016-11-02T09:57:51,344][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [reindex]  
[2016-11-02T09:57:51,344][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [transport-netty3]  
[2016-11-02T09:57:51,359][INFO][o.e.p.PluginsService] [OGKkOnR] loaded module [transport-netty4]  
[2016-11-02T09:57:51,359][INFO][o.e.p.PluginsService] [OGKkOnR] no plugins loaded  
[2016-11-02T09:57:55,891][INFO][o.e.n.Node] [OGKkOnR] initialized  
[2016-11-02T09:57:55,891][INFO][o.e.n.Node] [OGKkOnR] starting ...  
[2016-11-02T09:57:56,453][INFO][o.e.t.TransportService] [OGKkOnR] publish\_address {192.168.0.2:9300}, bound\_addresses {192.168.0.2:9300}  
[2016-11-02T09:57:56,469][INFO][o.e.b.BootstrapCheck] [OGKkOnR] bound or publishing to a non-loopback or non-link-local address, enforcing bootstrap checks  
[2016-11-02T09:58:00,610][INFO][o.e.c.s.ClusterService] [OGKkOnR] new\_master {OGKkOnR}{OGKkOnRcQNKOtKqF2X7XFQ}{YgqBcaU8QNyjNoTLMxlL9g}{192.168.0.2}{192.168.0.2:9300}, reason: zen-disco-elected-as-master ([0] nodes joined)  
[2016-11-02T09:58:00,625][INFO][o.e.h.HttpServer] [OGKkOnR] publish\_address {192.168.0.2:9200}, bound\_addresses {192.168.0.2:9200}  
[2016-11-02T09:58:00,641][INFO][o.e.n.Node] [OGKkOnR] started  
[2016-11-02T09:58:01,281][INFO][o.e.g.GatewayService] [OGKkOnR] recovered [3] indices into cluster\_state  
[2016-11-02T09:58:01,938][INFO][o.e.c.r.a.AllocationService] [OGKkOnR] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[.kibana][0]] ...]).

But is there any hints of anything wrong?

---

<div class="post-metadata">

**Author:** ![bme](https://avatars.discourse-cdn.com/v4/letter/b/d2c977/32.png) [@bme](https://discuss.elastic.co/u/bme)\
**Post date:** [November 7, 2016, 11:01am UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687/4 "2016-11-07T11:01:30Z")

</div>

I guess this is an unsolvable error then.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 7, 2016, 9:02pm UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687/5 "2016-11-07T21:02:38Z")

</div>

What does `GET _template` against ES show?

---

<div class="post-metadata">

**Author:** ![bme](https://avatars.discourse-cdn.com/v4/letter/b/d2c977/32.png) [@bme](https://discuss.elastic.co/u/bme)\
**Post date:** [November 8, 2016, 9:48am UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687/6 "2016-11-08T09:48:24Z")

</div>

It lists 2 templates, none of which are relevant to my logstash template.

The logstash output has this output configured:

output {  
elasticsearch {  
hosts =\> ['192.168.0.2:9200']  
index =\> 'iis-myapp-%{+[YYYY.MM](http://YYYY.MM)}'  
template =\> "M:\logstash-5.0.0\config\iis.myapp.template.json"  
template\_overwrite =\> true  
}  
}

The index is being created as iis-myapp-\* but there is no template. I guess the template must be bad, but elasticsearch didn't complain about it and logstash says elastisearch wont accept it. JSON validater says the template is valid json. I am at a loss here.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 8, 2016, 9:49am UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687/7 "2016-11-08T09:49:08Z")

</div>

Maybe you can show us your template.

---

<div class="post-metadata">

**Author:** ![bme](https://avatars.discourse-cdn.com/v4/letter/b/d2c977/32.png) [@bme](https://discuss.elastic.co/u/bme)\
**Post date:** [November 8, 2016, 9:50am UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687/8 "2016-11-08T09:50:17Z")

</div>

Sure, it is already in the first post as part of the log, but here it is again:

{  
"mappings": {  
"_default_": {  
"\_all": {  
"enabled": true,  
"norms": {  
"enabled": false  
}  
},  
"dynamic\_templates": [{  
"iisTemplate": {  
"mapping": {  
"doc\_values": true,  
"ignore\_above": 1024,  
"index": "not\_analyzed",  
"type": "{dynamic\_type}"  
},  
"match": "_"  
}  
}  
],  
"properties": {  
"@timestamp": {  
"type": "date",  
"index": "analyzed"  
},  
"status": {  
"type": "integer",  
"index": "analyzed",  
"doc\_values": true  
},  
"timeTaken": {  
"type": "integer",  
"index": "analyzed",  
"doc\_values": true  
},  
"bytesSent": {  
"type": "integer",  
"index": "analyzed",  
"doc\_values": true  
},  
"bytesTotal": {  
"type": "integer",  
"index": "analyzed",  
"doc\_values": false  
},  
"bytesReceived": {  
"type": "integer",  
"index": "analyzed",  
"doc\_values": true  
},  
"subStatus": {  
"type": "integer",  
"index": "not\_analyzed"  
},  
"geoip": {  
"type": "object",  
"dynamic": "true",  
"index": "analyzed",  
"properties": {  
"location": {  
"type": "geo\_point"  
}  
}  
}  
}  
},  
"settings": {  
"index.refresh\_interval": "5s"  
},  
"template": "iis-_"  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:30am UTC](https://discuss.elastic.co/t/failed-to-install-template-contact-elasticsearch/64687/9 "2017-07-06T04:30:45Z")

</div>


