# How to set default analyzer for new Logstash indices?

**URL:** <https://discuss.elastic.co/t/how-to-set-default-analyzer-for-new-logstash-indices/163976>\
**Category:** Logstash\
**Created:** [January 12, 2019, 3:55am UTC](https://discuss.elastic.co/t/how-to-set-default-analyzer-for-new-logstash-indices/163976 "2019-01-12T03:55:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [January 12, 2019, 3:55am UTC](https://discuss.elastic.co/t/how-to-set-default-analyzer-for-new-logstash-indices/163976/1 "2019-01-12T03:55:26Z")

</div>

Hi, I'm new to the Elastic stack in general. I would like to know how to set or modify the default analyzer for new indices. I'm currently modifying the analyzer to stop queries from lower-casing the tokens. I have successfully done that using this:

```
PUT /logstash-*/_settings
{
  "settings": {
    "analysis": {
      "analyzer": {
        "default": {
          "filter": [],
          "type": "custom",
          "tokenizer": "whitespace"
        }
      }
    }
  }
}

```

However, it doesn't seem to apply for the new, automatically created indices (e.g. logstash-2019.01.20). Does anyone know how to make the modified settings apply automatically to new indices? Thanks!

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [January 12, 2019, 4:34pm UTC](https://discuss.elastic.co/t/how-to-set-default-analyzer-for-new-logstash-indices/163976/2 "2019-01-12T16:34:44Z")

</div>

Elasticsearch can be configured with one or more [Index Templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html), which allow you to define fields and options before an index is created based on the name of the index matching a pattern.

The Elasticsearch Output Plugin can be configured to manage the template for you, using [`manage_template => true`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-manage_template) and also providing the path to a file containing a template with the [`template`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template) option. This will send the provided template to Elasticsearch each time that the Logstash plugin starts up, ensuring it is up-to-date before any data is sent or additional indexes are created.

---

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [January 13, 2019, 4:34am UTC](https://discuss.elastic.co/t/how-to-set-default-analyzer-for-new-logstash-indices/163976/3 "2019-01-13T04:34:38Z")

</div>

Alright, thanks! I'll have a go at it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2019, 4:34am UTC](https://discuss.elastic.co/t/how-to-set-default-analyzer-for-new-logstash-indices/163976/4 "2019-02-10T04:34:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
