# How does custom template work in elasticsearch?

**URL:** <https://discuss.elastic.co/t/how-does-custom-template-work-in-elasticsearch/178731>\
**Category:** Elasticsearch\
**Created:** [April 26, 2019, 11:01pm UTC](https://discuss.elastic.co/t/how-does-custom-template-work-in-elasticsearch/178731 "2019-04-26T23:01:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![exocore123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exocore123/32/45130_2.png) [@exocore123](https://discuss.elastic.co/u/exocore123)\
**Post date:** [April 26, 2019, 11:01pm UTC](https://discuss.elastic.co/t/how-does-custom-template-work-in-elasticsearch/178731/1 "2019-04-26T23:01:56Z")

</div>

I've asked a question a while back, but cant seem to find a proper solution or a work around...

I currently have a filter that parse a certain amount of logs and aggregate it all together to finalize a final log (each A, B, C, etc part logs have an identified called orderId) and we query for orderId as a keyword to aggregate proper ones (otherwise, the query would return incorrect results).

I have a custom template here:

```
{
	"order" : 1,
	"template": "logstash-transaction-*",
	"settings": {
		"index.refresh_interval": "5s"
	},
	"mappings": {
		"logs": {
			"_all": {
				"enabled": true,
				"omit_norms": true
			},
			"dynamic_templates": [
				{
					"message_field": {
						"match": "message",
						"match_mapping_type": "string",
						"mapping": {
							"type": "string",
							"index": "analyzed",
							"omit_norms": true
						}
					}
				},
				{
					"string_fields": {
						"match": "*",
						"match_mapping_type": "string",
						"mapping": {
							"type": "string",
							"index": "not_analyzed",
							"ignore_above": 256
						}
					}
				}
			],
			"properties": {
				"orderId": {
					"type": "keyword"
				}
			}
		}
	}
}

```

However, for some reason, once our index would be created after delete and clean restart, it would not correctly map the template... I suspect its due to this template for some reason that exist that I've asked about a long time ago here ([Forcing only a particular template on index?](https://discuss.elastic.co/t/forcing-only-a-particular-template-on-index/171810)). To summarize, I suspected that the index was affected by the other template that presumably was generated by logstash because when I do `GET _template` I see there are two different templates that could be applied to my index of `logstash-transaction-%{+YYYY.MM.dd}`

I thought this ([Disable logstash default template creation](https://discuss.elastic.co/t/disable-logstash-default-template-creation/36965)) would solve it, but it stops the `logstash-*` template from generating, but my custom template is still not applied...

This is my output-elasticsearch.conf, could anyone care to expand on this behavior? Am I missing something here??

```
output {
    if (![log]) {
        elasticsearch {
            hosts => ["${OUTPUT_ELASTICSEARCH_HOSTS}"]
            index => "${OUTPUT_ELASTICSEARCH_INDEX}"
            action => "${OUTPUT_ELASTICSEARCH_ACTION:index}"
            document_id => "%{logGUID}"
            document_type => "${OUTPUT_ELASTICSEARCH_DOCUMENT_TYPE}"
            retry_on_conflict => 50
            template_name => "logstash-transaction"
            manage_template => true
            template_overwrite => true
            template => "${CONFIG_DIR}/_/logs-elasticsearch-template.json"
         }
    }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 28, 2019, 2:30am UTC](https://discuss.elastic.co/t/how-does-custom-template-work-in-elasticsearch/178731/2 "2019-04-28T02:30:25Z")

</div>

What version are you on?

> [@exocore123](#):
>
> index =\> "${OUTPUT\_ELASTICSEARCH\_INDEX}"

This needs to match your index, so I'd make sure of that. Also;

> [@exocore123](#):
>
> document\_type =\> "${OUTPUT\_ELASTICSEARCH\_DOCUMENT\_TYPE}"

That needs to match your mapping type, so check it does as well.

---

<div class="post-metadata">

**Author:** ![exocore123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exocore123/32/45130_2.png) [@exocore123](https://discuss.elastic.co/u/exocore123)\
**Post date:** [April 29, 2019, 4:25pm UTC](https://discuss.elastic.co/t/how-does-custom-template-work-in-elasticsearch/178731/3 "2019-04-29T16:25:20Z")

</div>

I'm using Elasticsearch 5.6.8

As for document\_type, I'm assuming thats the mappings's name?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 29, 2019, 8:15pm UTC](https://discuss.elastic.co/t/how-does-custom-template-work-in-elasticsearch/178731/4 "2019-04-29T20:15:45Z")

</div>

`document_type` needs to be the same as `logs`.

---

<div class="post-metadata">

**Author:** ![exocore123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exocore123/32/45130_2.png) [@exocore123](https://discuss.elastic.co/u/exocore123)\
**Post date:** [April 29, 2019, 8:40pm UTC](https://discuss.elastic.co/t/how-does-custom-template-work-in-elasticsearch/178731/5 "2019-04-29T20:40:02Z")

</div>

Ah ok, that's what I did then. I think that might have fixed it, seems like the environmental variable did not exist so it used the default template.

Now it seems like it makes every string field a keyword type, is there a way to only make it keyword for specifically orderId? I guess it has to deal with the mapping under string\_fields vs message\_fields.  
like this?

```
"string_fields": {
	"match": "*",
	"match_mapping_type": "string",
	"mapping": {
		"type": "string",
		"index": "analyzed",
		"ignore_above": 256
	}
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2019, 8:40pm UTC](https://discuss.elastic.co/t/how-does-custom-template-work-in-elasticsearch/178731/6 "2019-05-27T20:40:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
