# Invalid\_index\_template\_exception

**URL:** <https://discuss.elastic.co/t/invalid-index-template-exception/358285>\
**Category:** Beats\
**Tags:** fleet\
**Created:** [April 26, 2024, 12:08pm UTC](https://discuss.elastic.co/t/invalid-index-template-exception/358285 "2024-04-26T12:08:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [April 26, 2024, 12:08pm UTC](https://discuss.elastic.co/t/invalid-index-template-exception/358285/1 "2024-04-26T12:08:33Z")

</div>

Hi,

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/6/56c1d2efbc125c60ed65d126d4d2783a87569006.png)

Today I've added a new integration "Custom Windows Event Logs" but with a custom Dataset name. Sadly I've made a mistake and put some capitalisation in it (winlog.TerminalServices) and the integration didn't go well.

I've recreated it from scratch with a new dataset name (winlog.tse) and this time it goes well.  
But now when trying to create the same integration in another agent policy, despite selecting the good dataset (winlog.tse) I get an error related to the previously mistakenly created dataset.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0f6155e0484bd636c4c2f1ec9fcd7c0a9a3ad92a.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a3a429286550c0c3d2916723c1f0e8bb8c45249.png)

```auto
Error installing winlog 2.1.0: invalid_index_template_exception Root causes: invalid_index_template_exception: index_template [logs-winlog.TerminalServices@package] invalid, cause [Validation Failed: 1: name must be lower cased;]

```

From the name "winlog.TerminalServices@package" it seems to be a component template but I can't find it (from Stack Management or the Dev Tools Console). It is expected as it was not created because of the wrong name.

And even when I try to update the integration, I encounter the same error. That's weird!

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/6/86edd5cc473992359b9105c3c07d59ee6a58a96b.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f881b66e87a7ce69261583e2a468a0157033583f.png)

I did a full rolling restart of my cluster but it's not better.

Bonus question please :  
Why is there so many dataset with the same name appearing in this list?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/5/051f2be034811f8891a8bf0a7a32db899f515328.png)

Thanks a lot for your help!  
Regards.

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [April 29, 2024, 7:51am UTC](https://discuss.elastic.co/t/invalid-index-template-exception/358285/2 "2024-04-29T07:51:15Z")

</div>

Hi all,  
Just a little push in order to know if it's a bug from Elastic or a misconfiguration on my side please.  
Currently I'm pretty stuck as this integration is already deployed on many Agent Policies...  
Thanks a lot for your help!  
Regards.

---

<div class="post-metadata">

**Author:** ![DaddyYusk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daddyyusk/32/127617_2.png) [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Post date:** [May 2, 2024, 12:37pm UTC](https://discuss.elastic.co/t/invalid-index-template-exception/358285/3 "2024-05-02T12:37:10Z")

</div>

Hi all,

As I was unable to do anything with this integration (update, reinstall, uninstall), here is a quick workaround below.

Steps I've done :

- Delete all "Custom Windows Event Logs" integrations in each Agent Policies
- Uninstall it from Kibana \> Integrations \> Installed Integrations \> Settings
- Reinstall it from the same panel
- From the same panel, add it again for each Agent Policies

TLDR; uninstall then reinstall from scratch.  
Have a great day!
