# Index Mapping Templates and sustainable practices

**URL:** <https://discuss.elastic.co/t/index-mapping-templates-and-sustainable-practices/50863>\
**Category:** Logstash\
**Created:** [May 24, 2016, 3:23pm UTC](https://discuss.elastic.co/t/index-mapping-templates-and-sustainable-practices/50863 "2016-05-24T15:23:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![whyapenny](https://avatars.discourse-cdn.com/v4/letter/w/90db22/32.png) [@whyapenny](https://discuss.elastic.co/u/whyapenny)\
**Post date:** [May 24, 2016, 3:23pm UTC](https://discuss.elastic.co/t/index-mapping-templates-and-sustainable-practices/50863/1 "2016-05-24T15:23:06Z")

</div>

Wasn't sure whether to post this question in Logstash forum or ElasticSearch since it can technically be in either.

Scenario: Multiple applications logging to a single ELK stack. Each application's logs will differ in format. All application logs will log to the same index (logstash-%date).

Question: How does one maintain index/mapping templates for each application stack in a sustainable and organized manner? Meaning if the log structure changes, it should be easy to change the mapping for that specific app without affecting other apps. It should also be versionable if possible.

I was thinking for this, best use would be to store the templates on logstash servers in a config directory where they are applied by logstash on the first message of a new index. The flat files could be versioned and easily modified/replaced.

Would love to hear how other people are handling this and what options and possibilities there are that I may be missing.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 24, 2016, 8:30pm UTC](https://discuss.elastic.co/t/index-mapping-templates-and-sustainable-practices/50863/2 "2016-05-24T20:30:49Z")

</div>

> How does one maintain index/mapping templates for each application stack in a sustainable and organized manner? Meaning if the log structure changes, it should be easy to change the mapping for that specific app without affecting other apps.

If all applications log to the same indexes keep in mind that the mappings need to be the same for a given field, i.e. a field named _x_ will have mapping _y_ regardless of the type.

> I was thinking for this, best use would be to store the templates on logstash servers in a config directory where they are applied by logstash on the first message of a new index. The flat files could be versioned and easily modified/replaced.

Not sure why you're talking about plural here—if all applications share the same index then there will only be one template.

I prefer disabling Logtash's template management and storing the templates directly in ES but I don't think there are any significant advantages (or disadvantages) in doing so.

---

<div class="post-metadata">

**Author:** ![whyapenny](https://avatars.discourse-cdn.com/v4/letter/w/90db22/32.png) [@whyapenny](https://discuss.elastic.co/u/whyapenny)\
**Post date:** [May 26, 2016, 3:24pm UTC](https://discuss.elastic.co/t/index-mapping-templates-and-sustainable-practices/50863/3 "2016-05-26T15:24:01Z")

</div>

Sorry for the confusion with the multiple templates. You are right that there will be a single index, and thus a single template. Perhaps I may be over complicating things a bit, so while i have your attention maybe i can ask this question first:  
Is there a way to have kibana search through all indexes at once? For instance if we had iis-%date tomcat-%date mysql-%date, could kibana still do a single query look up through all of them at once in order to track a transaction through all stacks?

Now on to answering some of the concerns you brought up...Yes a single index and thus a single template. Each app will have different fields, however, just the nature of the beast. some fields may overlap such as timestamps and success/fail fields, but not all fields will be the same.

I keep using plural because i was thinking the template could be broken down into multiple pieces instead of one large file, same way the logstash configuration is. In the config we have 00\_input.conf 10\_iis.conf 20\_tomcat.conf 30\_mysql.confg 99\_output.conf. I was expecting to be able to do a similar thing for the template where each piece is separated out.

The reason is changes to tomcat app are frequent, and fields may be added or removed as needed and thus the template would have to change. I am attempting to plan ahead and make this as easy going forward as possible and establish some procedures and standards.

Am I way over complicating this? Thanks for your help!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 27, 2016, 11:18am UTC](https://discuss.elastic.co/t/index-mapping-templates-and-sustainable-practices/50863/4 "2016-05-27T11:18:37Z")

</div>

> Is there a way to have kibana search through all indexes at once? For instance if we had iis-%date tomcat-%date mysql-%date, could kibana still do a single query look up through all of them at once in order to track a transaction through all stacks?

Yes, as long as there's a single index pattern that selects all those indexes (and no indexes you _don't_ want to search). You may want to prefix all your log indexes.

> I keep using plural because i was thinking the template could be broken down into multiple pieces instead of one large file, same way the logstash configuration is. In the config we have 00\_input.conf 10\_iis.conf 20\_tomcat.conf 30\_mysql.confg 99\_output.conf. I was expecting to be able to do a similar thing for the template where each piece is separated out.

Okay. Sure, but merging those files will be up to you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:55am UTC](https://discuss.elastic.co/t/index-mapping-templates-and-sustainable-practices/50863/5 "2017-07-06T04:55:55Z")

</div>


