# Index Templates tracing

**URL:** <https://discuss.elastic.co/t/index-templates-tracing/213413>\
**Category:** Elasticsearch\
**Created:** [December 31, 2019, 7:01am UTC](https://discuss.elastic.co/t/index-templates-tracing/213413 "2019-12-31T07:01:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ayala](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@Ayala](https://discuss.elastic.co/u/Ayala)\
**Post date:** [December 31, 2019, 7:01am UTC](https://discuss.elastic.co/t/index-templates-tracing/213413/1 "2019-12-31T07:01:25Z")

</div>

Is there a way to track which index templates were used/applied for the creation of an index?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [December 31, 2019, 7:25pm UTC](https://discuss.elastic.co/t/index-templates-tracing/213413/2 "2019-12-31T19:25:45Z")

</div>

When an index is created, this message is logged that lists templates applied.

```
creating index, cause [auto(bulk api)], templates [our-metricbeat, metricbeat-6.7.1], shards [1]/[1], mappings [doc]

```

I think the templates are listed in descending "order" value.

---

<div class="post-metadata">

**Author:** ![Ayala](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@Ayala](https://discuss.elastic.co/u/Ayala)\
**Post date:** [January 3, 2020, 8:44am UTC](https://discuss.elastic.co/t/index-templates-tracing/213413/3 "2020-01-03T08:44:33Z")

</div>

Thanks!  
How can I view the log?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 3, 2020, 1:29pm UTC](https://discuss.elastic.co/t/index-templates-tracing/213413/4 "2020-01-03T13:29:43Z")

</div>

The default location is /var/log/elasticsearch, it creates a new file at least daily.

You can also ingest these logs with the filebeat elasticsearch module. We ingest these and logstash logs for consolidated log views. At least any (data?) node can create the index, so you have to look at all their logs to find them.

You need to be cautious when ingesting these logs, any error could log another event to ingest creating a runaway log loop. It might be better to send them to a monitoring cluster.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2020, 1:29pm UTC](https://discuss.elastic.co/t/index-templates-tracing/213413/5 "2020-01-31T13:29:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
