# I cannot update template

**URL:** <https://discuss.elastic.co/t/i-cannot-update-template/326775>\
**Category:** Elasticsearch\
**Created:** [March 1, 2023, 2:58pm UTC](https://discuss.elastic.co/t/i-cannot-update-template/326775 "2023-03-01T14:58:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rachelyang](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Post date:** [March 1, 2023, 2:58pm UTC](https://discuss.elastic.co/t/i-cannot-update-template/326775/1 "2023-03-01T14:58:19Z")

</div>

I updated the template of filebeat in the elasticsearch node. It returned me an error:

```auto
{
	"error": {
		"root_cause": [
			{
				"type": "mapper_parsing_exception",
				"reason": "Root mapping definition has unsupported parameters: [_default_ : {dynamic_templates=[{template1={mapping={ignore_above=1024, index=not_analyzed, type={dynamic_type}, doc_values=true}, match=*}}], _all={norms={enabled=false}, enabled=true}, properties={@timestamp={type=date}, geoip={dynamic=true, properties={ip={type=ip}, latitude={type=half_float}, location={type=geo_point}, longitude={type=half_float}}}, offset={type=long, doc_values=true}, message={index=analyzed, type=string}}}]"
			}
		],
		"type": "mapper_parsing_exception",
		"reason": "Failed to parse mapping [_doc]: Root mapping definition has unsupported parameters: [_default_ : {dynamic_templates=[{template1={mapping={ignore_above=1024, index=not_analyzed, type={dynamic_type}, doc_values=true}, match=*}}], _all={norms={enabled=false}, enabled=true}, properties={@timestamp={type=date}, geoip={dynamic=true, properties={ip={type=ip}, latitude={type=half_float}, location={type=geo_point}, longitude={type=half_float}}}, offset={type=long, doc_values=true}, message={index=analyzed, type=string}}}]",
		"caused_by": {
			"type": "mapper_parsing_exception",
			"reason": "Root mapping definition has unsupported parameters: [_default_ : {dynamic_templates=[{template1={mapping={ignore_above=1024, index=not_analyzed, type={dynamic_type}, doc_values=true}, match=*}}], _all={norms={enabled=false}, enabled=true}, properties={@timestamp={type=date}, geoip={dynamic=true, properties={ip={type=ip}, latitude={type=half_float}, location={type=geo_point}, longitude={type=half_float}}}, offset={type=long, doc_values=true}, message={index=analyzed, type=string}}}]"
		}
	},
	"status": 400
}

```

Here is my template file:

```auto
{
  "mappings": {
    "_default_": {
      "_all": {
        "enabled": true,
        "norms": {
          "enabled": false
        }
      },
      "dynamic_templates": [
        {
          "template1": {
            "mapping": {
              "doc_values": true,
              "ignore_above": 1024,
              "index": "not_analyzed",
              "type": "{dynamic_type}"
            },
            "match": "*"
          }
        }
      ],
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "message": {
          "type": "string",
          "index": "analyzed"
        },
        "offset": {
          "type": "long",
          "doc_values": "true"
        },
        "geoip" : {
          "dynamic": "true",
          "properties" : {
	         "ip": { "type": "ip" },
	         "latitude" : { "type" : "half_float" },
	         "longitude" : { "type" : "half_float" },
            "location" : { "type" : "geo_point" }
          }
        }
      }
    }
  },
  "settings": {
    "index.refresh_interval": "5s"
  },
  "template": "filebeat-7.14.1*"
}

```

I used curl to update:

```auto
curl -X PUT -H 'Content-Type: application/json' 'http://localhost:9200/_template/filebeat-7.14.1' -d @filebeat-index-template.json

```

Please help me to check why it was wrong.  
Thanks

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 1, 2023, 4:33pm UTC](https://discuss.elastic.co/t/i-cannot-update-template/326775/2 "2023-03-01T16:33:40Z")

</div>

I could be way off here, and don't know your use case, but here are some thoughts:

> [@rachelyang](#):
>
> ```auto
> "_default_": {
> "_all": {
> "enabled": true,
> "norms": {
> "enabled": false
> }
> },
> "dynamic_templates": [
> {
> "template1": {
> "mapping": {
> "doc_values": true,
> "ignore_above": 1024,
> "index": "not_analyzed",
> "type": "{dynamic_type}"
> },
> "match": "*"
> }
> }
> ]
> 
> ```

Doesn't seem to do much and can probably be safely removed.

> [@rachelyang](#):
>
> ```auto
> "type": "string",
> "index": "analyzed"
> 
> ```

Type string isn't a thing try either "text" or "keyword" depending upon use case.  
Index should be either "true" or "false".  
Once those changes are made I get that template loading in just fine.

````auto
{
  "mappings": {
    "properties": {
      "@timestamp": {
        "type": "date"
      },
      "message": {
        "type": "text",
        "index": "true"
      },
      "offset": {
        "type": "long",
        "doc_values": "true"
      },
      "geoip": {
        "dynamic": "true",
        "properties": {
          "ip": {
            "type": "ip"
          },
          "latitude": {
            "type": "half_float"
          },
          "longitude": {
            "type": "half_float"
          },
          "location": {
            "type": "geo_point"
          }
        }
      }
    }
  },
  "settings": {
    "index.refresh_interval": "5s"
  },
  "template": "filebeat-7.14.1*"
}```
````

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2023, 4:34pm UTC](https://discuss.elastic.co/t/i-cannot-update-template/326775/3 "2023-03-29T16:34:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
