# Help with Elasticsearch template definition

**URL:** <https://discuss.elastic.co/t/help-with-elasticsearch-template-definition/65901>\
**Category:** Elasticsearch\
**Created:** [November 13, 2016, 11:01am UTC](https://discuss.elastic.co/t/help-with-elasticsearch-template-definition/65901 "2016-11-13T11:01:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [November 13, 2016, 11:01am UTC](https://discuss.elastic.co/t/help-with-elasticsearch-template-definition/65901/1 "2016-11-13T11:01:55Z")

</div>

Hi, reading [the documentation about index templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html), I have some doubts on which should be the best practice to define a new template.  
My particular situation is very simple, I would like to:

- Define only one template (for Logstash)
- Restrict Elasticsearch to use only 2 shards and 1 replicas
- Add some field mappings directly on the template, if needed

So far I've used the default template generated by Logstash:

`{"logstash":{"order":0,"template":"logstash-*","settings":{"index":{"refresh_interval":"5s"}},"mappings":{"_default_":{"dynamic_templates":[{"message_field":{"mapping":{"fielddata":{"format":"disabled"},"index":"analyzed","omit_norms":true,"type":"string"},"match_mapping_type":"string","match":"message"}},{"string_fields":{"mapping":{"fielddata":{"format":"disabled"},"index":"analyzed","omit_norms":true,"type":"string","fields":{"raw":{"ignore_above":256,"index":"not_analyzed","type":"string"}}},"match_mapping_type":"string","match":"*"}}],"_all":{"omit_norms":true,"enabled":true},"properties":{"@timestamp":{"type":"date"},"geoip":{"dynamic":true,"properties":{"ip":{"type":"ip"},"latitude":{"type":"float"},"location":{"type":"geo_point"},"longitude":{"type":"float"}}},"@version":{"index":"not_analyzed","type":"string"}}}},"aliases":{}}}`

Should I keep this template and simply add:

```
PUT _template/logstash
{
  "template": "logstash",
  "settings": {
    "number_of_shards": 2,
    "number_of_replicas": 1
  }
}

```

For the mappings, which is the best option:

1. Adding them into the index template (like shown above)
2. Adding them per index using a `PUT my_index` [as shown here](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html)
3. Leaving Logstash assign the correct mapping provided that its configuration contains them

Also, as an alternative to the REST API, which is the proper way to assign an index template to Elasticsearch _at startup time_?

Thank you

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 13, 2016, 10:53pm UTC](https://discuss.elastic.co/t/help-with-elasticsearch-template-definition/65901/2 "2016-11-13T22:53:31Z")

</div>

> [@espogian](#):
>
> Should I keep this template and simply add:

No because that will only ever match indices called `logstash`, that is what the value of `template` means.

You would be better off copying the existing mapping file, make the changes, then explicitly defining it in the output.

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [November 14, 2016, 7:58am UTC](https://discuss.elastic.co/t/help-with-elasticsearch-template-definition/65901/3 "2016-11-14T07:58:16Z")

</div>

Hi @warkolm thanks.  
For the moment I have copied the whole logstash template and PUT it with my changes to Elasticsearch.  
And obviously now my indexes have new replicas & shards.  
However, from your answer I didn't catch if I should take another action. Is there any way to change default template settings prior to starting Elasticsearch?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 14, 2016, 8:18am UTC](https://discuss.elastic.co/t/help-with-elasticsearch-template-definition/65901/4 "2016-11-14T08:18:10Z")

</div>

> [@espogian](#):
>
> Is there any way to change default template settings prior to starting Elasticsearch?

Nope.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2016, 8:19am UTC](https://discuss.elastic.co/t/help-with-elasticsearch-template-definition/65901/5 "2016-12-12T08:19:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
