# Index Template vs Logstash Managed Template

**URL:** <https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897>\
**Category:** Elasticsearch\
**Created:** [November 18, 2015, 8:40am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897 "2015-11-18T08:40:11Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![aacb9](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aacb9](https://discuss.elastic.co/u/aacb9)\
**Post date:** [November 18, 2015, 8:40am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/1 "2015-11-18T08:40:11Z")

</div>

Is there any downside to using logstash managed template vs elasticsearch index template? The output for logstash looks like %{type}-%{+YYYY.MM.dd}, so I'm not sure if logstash mapped template can even be like %{type}.json.

Reason I'd prefer it through logstash is it's easier to manage that through puppet than posting into ES which is kind of stateful

---

<div class="post-metadata">

**Author:** ![aacb9](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aacb9](https://discuss.elastic.co/u/aacb9)\
**Post date:** [November 18, 2015, 8:57am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/2 "2015-11-18T08:57:10Z")

</div>

Btw in ES 2.0 is config/templates no longer a thing? I see it missing in docs [https://www.elastic.co/guide/en/elasticsearch/reference/2.0/indices-templates.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.0/indices-templates.html) vs [https://www.elastic.co/guide/en/elasticsearch/reference/1.5/indices-templates.html](https://www.elastic.co/guide/en/elasticsearch/reference/1.5/indices-templates.html)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 18, 2015, 9:14am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/3 "2015-11-18T09:14:34Z")

</div>

It ends up being the same unless I'm missing your question.  
So no downside IMO. LS will PUT the template for you.

---

<div class="post-metadata">

**Author:** ![aacb9](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aacb9](https://discuss.elastic.co/u/aacb9)\
**Post date:** [November 18, 2015, 9:17am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/4 "2015-11-18T09:17:05Z")

</div>

What I'm not sure is when does logtash send the PUT request? i.e. does it send the PUT request per bulk or what?

Secondly can you clarify re the templates directory being deprecated in 2.0?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 18, 2015, 9:40am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/5 "2015-11-18T09:40:31Z")

</div>

Logstash checks when it starts the elasticsearch output that the template exists or not in elasticsearch. If not, it sends the template using `PUT _template` API.

---

<div class="post-metadata">

**Author:** ![aacb9](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aacb9](https://discuss.elastic.co/u/aacb9)\
**Post date:** [November 18, 2015, 9:44am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/6 "2015-11-18T09:44:22Z")

</div>

tyvm.

---

<div class="post-metadata">

**Author:** ![aacb9](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aacb9](https://discuss.elastic.co/u/aacb9)\
**Post date:** [November 18, 2015, 9:50am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/7 "2015-11-18T09:50:39Z")

</div>

Actually sorry just though - if I point to templates.json and so templates are approrpriately created, if I update that file, will logstash see the file is updated and PUT the template again? Or does it only check by name basically?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 18, 2015, 10:28am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/8 "2015-11-18T10:28:23Z")

</div>

It only checks on index creation, so that'll usually be daily.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 18, 2015, 10:53am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/9 "2015-11-18T10:53:52Z")

</div>

If you need to update that file, then you need to remove the template in elasticsearch and restart logstash.

Logstash elasticsearch output will then restart, will try to check if the template exists and then will put the new template.

I don't think there is a "force put template" option in logstash output but you'd better ask that question in the logstash group 😛

---

<div class="post-metadata">

**Author:** ![aacb9](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@aacb9](https://discuss.elastic.co/u/aacb9)\
**Post date:** [November 18, 2015, 5:49pm UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/10 "2015-11-18T17:49:06Z")

</div>

You and Mark seem to have differing answers. Could one of you clarify who is correct?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 19, 2015, 12:46am UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/11 "2015-11-19T00:46:57Z")

</div>

David is right, it checks on index creation but it does that based on the template that is in ES.

I think LS checks the file each time it starts though.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:37pm UTC](https://discuss.elastic.co/t/index-template-vs-logstash-managed-template/34897/12 "2017-07-05T23:37:25Z")

</div>


