# Issue with my template creation

**URL:** <https://discuss.elastic.co/t/issue-with-my-template-creation/9734>\
**Category:** Elasticsearch\
**Created:** [November 16, 2012, 1:41am UTC](https://discuss.elastic.co/t/issue-with-my-template-creation/9734 "2012-11-16T01:41:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Praveen\_Kariyanahall](https://avatars.discourse-cdn.com/v4/letter/p/4491bb/32.png) [@Praveen\_Kariyanahall](https://discuss.elastic.co/u/Praveen_Kariyanahall)\
**Post date:** [November 16, 2012, 1:41am UTC](https://discuss.elastic.co/t/issue-with-my-template-creation/9734/1 "2012-11-16T01:41:40Z")

</div>

This used to work great when I went through pyes and was creating index.  
But when I try convert it into template PUT, I see the following error.  
There seems to be some issue with the "search\_analyzer" too. Any idea, what  
is wrong with this?

Thanks in Advance  
-pk

_Error:_  
\*  
\*  
{"error":"ElasticSearchIllegalArgumentException[Malformed mappings section  
for type [index\_analyzer], should include an inner object describing the  
mapping]","status":400}

_Template:_  
\*  
\*  
curl -XPUT localhost:9200/_template/foo -d '{  
"template" : "foo_\*",  
"settings" : { "number\_of\_shards": 1,  
"analysis": {  
"filter": {  
"mynGram" : {  
"type" : "nGram",  
"min\_gram": 1,  
"max\_gram": 20  
}  
},  
"tokenizer" : {  
"email\_tokenizer" : {  
"type" : "pattern",  
"pattern" :  
"[^@:/\.\!=\-\w\p{L}\d]+"  
}  
},  
"analyzer": {  
"a1" : {  
"type" : "custom",  
"tokenizer":"email\_tokenizer",  
"filter" : ["lowercase", "mynGram"]  
}  
}  
}  
},  
"mappings" : {  
"index\_analyzer" : "a1",  
"search\_analyzer" : "whitespace",  
"properties" : {  
"message" : {  
"type" : "string",  
"store": "yes"  
}  
}  
}  
}'

--

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [November 16, 2012, 2:40am UTC](https://discuss.elastic.co/t/issue-with-my-template-creation/9734/2 "2012-11-16T02:40:27Z")

</div>

Elasticsearch expect to see a type name inside mappings:

```
    "mappings" : {

```

- 

```
        "doc" : {*
                  "index_analyzer" : "a1",
                  "search_analyzer" : "whitespace",
                  "properties" : {
                      "message" : {
                          "type" : "string",
                          "store": "yes"
                      }
                  }

```

- 

```
               }*
          }

```

On Thursday, November 15, 2012 8:41:40 PM UTC-5, Praveen Kariyanahalli  
wrote:

> This used to work great when I went through pyes and was creating index.  
> But when I try convert it into template PUT, I see the following error.  
> There seems to be some issue with the "search\_analyzer" too. Any idea, what  
> is wrong with this?
> 
> Thanks in Advance  
> -pk
> 
> _Error:_  
> \*  
> \*  
> {"error":"ElasticSearchIllegalArgumentException[Malformed mappings section  
> for type [index\_analyzer], should include an inner object describing the  
> mapping]","status":400}
> 
> _Template:_  
> \*  
> \*  
> curl -XPUT localhost:9200/_template/foo -d '{  
> "template" : "foo_\*",  
> "settings" : { "number\_of\_shards": 1,  
> "analysis": {  
> "filter": {  
> "mynGram" : {  
> "type" : "nGram",  
> "min\_gram": 1,  
> "max\_gram": 20  
> }  
> },  
> "tokenizer" : {  
> "email\_tokenizer" : {  
> "type" : "pattern",  
> "pattern" :  
> "[^@:/\.\!=\-\w\p{L}\d]+"  
> }  
> },  
> "analyzer": {  
> "a1" : {  
> "type" : "custom",  
> "tokenizer":"email\_tokenizer",  
> "filter" : ["lowercase", "mynGram"]  
> }  
> }  
> }  
> },  
> "mappings" : {  
> "index\_analyzer" : "a1",  
> "search\_analyzer" : "whitespace",  
> "properties" : {  
> "message" : {  
> "type" : "string",  
> "store": "yes"  
> }  
> }  
> }  
> }'

--

---

<div class="post-metadata">

**Author:** ![Praveen\_Kariyanahall](https://avatars.discourse-cdn.com/v4/letter/p/4491bb/32.png) [@Praveen\_Kariyanahall](https://discuss.elastic.co/u/Praveen_Kariyanahall)\
**Post date:** [November 16, 2012, 9:36pm UTC](https://discuss.elastic.co/t/issue-with-my-template-creation/9734/3 "2012-11-16T21:36:14Z")

</div>

Thanks .. that helped.

I am facing another problem now. Here is the new template. I added  
date\_formats. It accepts. When I try insert a document .. it complains the  
following.

_Insert Document:_

curl -XPOST '[http://127.0.0.1:9200/foo\_2012-11-15/foo\_doc?pretty=1](http://127.0.0.1:9200/foo_2012-11-15/foo_doc?pretty=1)' -d ' {  
"message":"Insignificant message", "created\_timestamp" :  
"2012-11-15T10:10:10"}'  
\*  
\*  
_Error:_

{  
"error" : "MapperParsingException[mapping [elastica\_logs]]; nested:  
IllegalArgumentException[Illegal pattern component: T]; ",  
"status" : 400  
}

_Template:_

curl -XPUT localhost:9200/_template/foo -d '{  
"template" : "foo__",  
"settings" : { "number\_of\_shards": 1,  
"analysis": {  
"filter": {  
"mynGram" : {  
"type" : "nGram",  
"min\_gram": 1,  
"max\_gram": 20  
}  
},  
"tokenizer" : {  
"email\_tokenizer" : {  
"type" : "pattern",  
"pattern" :  
"[^@\:\.\-/=\-\w\p{L}\d]+"  
}  
},  
"analyzer": {  
"a1" : {  
"type" : "custom",  
"tokenizer":"email\_tokenizer",  
"filter" : ["lowercase", "mynGram"]  
}  
}  
}  
},  
"mappings" : {  
"foo\_doc" : {  
"index\_analyzer" : "a1",  
"search\_analyzer" : "whitespace",  
\* "date\_formats" : ["yyyy-MM-dd'T'HH:mm:ss"],_  
"properties" : {  
"created\_timestamp" : {  
"index" : "not\_analyzed",  
"type" : "date",  
"store" : "yes"  
},  
"message" : {  
"index": "not\_analyzed",  
"type" : "string",  
"store": "yes"  
}  
}  
}  
}  
}'

--

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [November 16, 2012, 9:43pm UTC](https://discuss.elastic.co/t/issue-with-my-template-creation/9734/4 "2012-11-16T21:43:06Z")

</div>

You need to escape apostrophes when you are using curl. Otherwise your date  
format is sent to es as "yyyy-MM-ddTHH:mm:ss" Try this:

"date\_formats" : ["yyyy-MM-dd'''T'''HH:mm:ss"],

On Friday, November 16, 2012 4:36:15 PM UTC-5, Praveen Kariyanahalli wrote:

> Thanks .. that helped.
> 
> I am facing another problem now. Here is the new template. I added  
> date\_formats. It accepts. When I try insert a document .. it complains the  
> following.
> 
> _Insert Document:_
> 
> curl -XPOST '[http://127.0.0.1:9200/foo\_2012-11-15/foo\_doc?pretty=1](http://127.0.0.1:9200/foo_2012-11-15/foo_doc?pretty=1)' -d '  
> { "message":"Insignificant message", "created\_timestamp" :  
> "2012-11-15T10:10:10"}'  
> \*  
> \*  
> _Error:_
> 
> {  
> "error" : "MapperParsingException[mapping [elastica\_logs]]; nested:  
> IllegalArgumentException[Illegal pattern component: T]; ",  
> "status" : 400  
> }
> 
> _Template:_
> 
> curl -XPUT localhost:9200/_template/foo -d '{  
> "template" : "foo__",  
> "settings" : { "number\_of\_shards": 1,  
> "analysis": {  
> "filter": {  
> "mynGram" : {  
> "type" : "nGram",  
> "min\_gram": 1,  
> "max\_gram": 20  
> }  
> },  
> "tokenizer" : {  
> "email\_tokenizer" : {  
> "type" : "pattern",  
> "pattern" :  
> "[^@\:\.\-/=\-\w\p{L}\d]+"  
> }  
> },  
> "analyzer": {  
> "a1" : {  
> "type" : "custom",  
> "tokenizer":"email\_tokenizer",  
> "filter" : ["lowercase", "mynGram"]  
> }  
> }  
> }  
> },  
> "mappings" : {  
> "foo\_doc" : {  
> "index\_analyzer" : "a1",  
> "search\_analyzer" : "whitespace",  
> \* "date\_formats" : ["yyyy-MM-dd'T'HH:mm:ss"],_  
> "properties" : {  
> "created\_timestamp" : {  
> "index" : "not\_analyzed",  
> "type" : "date",  
> "store" : "yes"  
> },  
> "message" : {  
> "index": "not\_analyzed",  
> "type" : "string",  
> "store": "yes"  
> }  
> }  
> }  
> }  
> }'

--

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [November 16, 2012, 9:48pm UTC](https://discuss.elastic.co/t/issue-with-my-template-creation/9734/5 "2012-11-16T21:48:04Z")

</div>

When you are using curl, you need to escape apostrophes. Otherwise your  
date format is sent to es as "yyyy-MM-ddTHH:mm:ss" Try this:

"date\_formats" : ["yyyy-MM-dd'''T'''HH:mm:ss"],

On Friday, November 16, 2012 4:36:15 PM UTC-5, Praveen Kariyanahalli wrote:

> Thanks .. that helped.
> 
> I am facing another problem now. Here is the new template. I added  
> date\_formats. It accepts. When I try insert a document .. it complains the  
> following.
> 
> _Insert Document:_
> 
> curl -XPOST '[http://127.0.0.1:9200/foo\_2012-11-15/foo\_doc?pretty=1](http://127.0.0.1:9200/foo_2012-11-15/foo_doc?pretty=1)' -d '  
> { "message":"Insignificant message", "created\_timestamp" :  
> "2012-11-15T10:10:10"}'  
> \*  
> \*  
> _Error:_
> 
> {  
> "error" : "MapperParsingException[mapping [elastica\_logs]]; nested:  
> IllegalArgumentException[Illegal pattern component: T]; ",  
> "status" : 400  
> }
> 
> _Template:_
> 
> curl -XPUT localhost:9200/_template/foo -d '{  
> "template" : "foo__",  
> "settings" : { "number\_of\_shards": 1,  
> "analysis": {  
> "filter": {  
> "mynGram" : {  
> "type" : "nGram",  
> "min\_gram": 1,  
> "max\_gram": 20  
> }  
> },  
> "tokenizer" : {  
> "email\_tokenizer" : {  
> "type" : "pattern",  
> "pattern" :  
> "[^@\:\.\-/=\-\w\p{L}\d]+"  
> }  
> },  
> "analyzer": {  
> "a1" : {  
> "type" : "custom",  
> "tokenizer":"email\_tokenizer",  
> "filter" : ["lowercase", "mynGram"]  
> }  
> }  
> }  
> },  
> "mappings" : {  
> "foo\_doc" : {  
> "index\_analyzer" : "a1",  
> "search\_analyzer" : "whitespace",  
> \* "date\_formats" : ["yyyy-MM-dd'T'HH:mm:ss"],_  
> "properties" : {  
> "created\_timestamp" : {  
> "index" : "not\_analyzed",  
> "type" : "date",  
> "store" : "yes"  
> },  
> "message" : {  
> "index": "not\_analyzed",  
> "type" : "string",  
> "store": "yes"  
> }  
> }  
> }  
> }  
> }'

--

---

<div class="post-metadata">

**Author:** ![radu\_gheorghe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/radu_gheorghe/32/556_2.png) [@radu\_gheorghe](https://discuss.elastic.co/u/radu_gheorghe)\
**Post date:** [November 17, 2012, 2:37pm UTC](https://discuss.elastic.co/t/issue-with-my-template-creation/9734/6 "2012-11-17T14:37:50Z")

</div>

Hello Praveen,

If you use curl from the command-line, you'll probably have to escape  
the quotes, like:

"date\_formats" : ["yyyy-MM-dd'"'T'"'HH:mm:ss"]

So instead of: single-quote-T-single-quote -\> which will translate  
into the string T, since you have single quotes at the beginning and  
the end of your data. So the single quotes there will only end the  
quoted string started first, add a T, then begin a new quoted string

You can put: single-quote-double-quote-single-quote-T-single-quote-double-quote-single-quote  
-\> which will translate to 'T', which is what you want. That's because  
the first single quote ends the first part of your JSON, then you  
start a double-quoted string which contains 'T', then you use  
single-quotes again to continue your JSON.

That's a lot of quotes 🙂 Hope it helps, though.

## Best regards, Radu

[http://sematext.com/](http://sematext.com/) -- Elasticsearch -- Solr -- Lucene

On Fri, Nov 16, 2012 at 11:36 PM, Praveen Kariyanahalli  
[praveen.kariyanahalli@gmail.com](mailto:praveen.kariyanahalli@gmail.com) wrote:

> Thanks .. that helped.
> 
> I am facing another problem now. Here is the new template. I added  
> date\_formats. It accepts. When I try insert a document .. it complains the  
> following.
> 
> Insert Document:
> 
> curl -XPOST '[http://127.0.0.1:9200/foo\_2012-11-15/foo\_doc?pretty=1](http://127.0.0.1:9200/foo_2012-11-15/foo_doc?pretty=1)' -d ' {  
> "message":"Insignificant message", "created\_timestamp" :  
> "2012-11-15T10:10:10"}'
> 
> Error:
> 
> {  
> "error" : "MapperParsingException[mapping [elastica\_logs]]; nested:  
> IllegalArgumentException[Illegal pattern component: T]; ",  
> "status" : 400  
> }
> 
> Template:
> 
> curl -XPUT localhost:9200/_template/foo -d '{  
> "template" : "foo_\*",  
> "settings" : { "number\_of\_shards": 1,  
> "analysis": {  
> "filter": {  
> "mynGram" : {  
> "type" : "nGram",  
> "min\_gram": 1,  
> "max\_gram": 20  
> }  
> },  
> "tokenizer" : {  
> "email\_tokenizer" : {  
> "type" : "pattern",  
> "pattern" :  
> "[^@\:\.\-/=\-\w\p{L}\d]+"  
> }  
> },  
> "analyzer": {  
> "a1" : {  
> "type" : "custom",  
> "tokenizer":"email\_tokenizer",  
> "filter" : ["lowercase", "mynGram"]  
> }  
> }  
> }  
> },  
> "mappings" : {  
> "foo\_doc" : {  
> "index\_analyzer" : "a1",  
> "search\_analyzer" : "whitespace",  
> "date\_formats" : ["yyyy-MM-dd'T'HH:mm:ss"],  
> "properties" : {  
> "created\_timestamp" : {  
> "index" : "not\_analyzed",  
> "type" : "date",  
> "store" : "yes"  
> },  
> "message" : {  
> "index": "not\_analyzed",  
> "type" : "string",  
> "store": "yes"  
> }  
> }  
> }  
> }  
> }'
> 
> --

--

---

<div class="post-metadata">

**Author:** ![Praveen\_Kariyanahall](https://avatars.discourse-cdn.com/v4/letter/p/4491bb/32.png) [@Praveen\_Kariyanahall](https://discuss.elastic.co/u/Praveen_Kariyanahall)\
**Post date:** [November 19, 2012, 6:44pm UTC](https://discuss.elastic.co/t/issue-with-my-template-creation/9734/7 "2012-11-19T18:44:26Z")

</div>

That did the trick. Thanks Igor and Radu.

Regards  
-pk

On Sat, Nov 17, 2012 at 6:37 AM, Radu Gheorghe  
[radu.gheorghe@sematext.com](mailto:radu.gheorghe@sematext.com)wrote:

> Hello Praveen,
> 
> If you use curl from the command-line, you'll probably have to escape  
> the quotes, like:
> 
> "date\_formats" : ["yyyy-MM-dd'"'T'"'HH:mm:ss"]
> 
> So instead of: single-quote-T-single-quote -\> which will translate  
> into the string T, since you have single quotes at the beginning and  
> the end of your data. So the single quotes there will only end the  
> quoted string started first, add a T, then begin a new quoted string
> 
> You can put:  
> single-quote-double-quote-single-quote-T-single-quote-double-quote-single-quote  
> -\> which will translate to 'T', which is what you want. That's because  
> the first single quote ends the first part of your JSON, then you  
> start a double-quoted string which contains 'T', then you use  
> single-quotes again to continue your JSON.
> 
> That's a lot of quotes 🙂 Hope it helps, though.
> 
> ## Best regards, Radu
> 
> [http://sematext.com/](http://sematext.com/) -- Elasticsearch -- Solr -- Lucene
> 
> On Fri, Nov 16, 2012 at 11:36 PM, Praveen Kariyanahalli  
> [praveen.kariyanahalli@gmail.com](mailto:praveen.kariyanahalli@gmail.com) wrote:
> 
> > Thanks .. that helped.
> > 
> > I am facing another problem now. Here is the new template. I added  
> > date\_formats. It accepts. When I try insert a document .. it complains  
> > the  
> > following.
> > 
> > Insert Document:
> > 
> > curl -XPOST '[http://127.0.0.1:9200/foo\_2012-11-15/foo\_doc?pretty=1](http://127.0.0.1:9200/foo_2012-11-15/foo_doc?pretty=1)' -d  
> > ' {  
> > "message":"Insignificant message", "created\_timestamp" :  
> > "2012-11-15T10:10:10"}'
> > 
> > Error:
> > 
> > {  
> > "error" : "MapperParsingException[mapping [elastica\_logs]]; nested:  
> > IllegalArgumentException[Illegal pattern component: T]; ",  
> > "status" : 400  
> > }
> > 
> > Template:
> > 
> > curl -XPUT localhost:9200/_template/foo -d '{  
> > "template" : "foo_\*",  
> > "settings" : { "number\_of\_shards": 1,  
> > "analysis": {  
> > "filter": {  
> > "mynGram" : {  
> > "type" : "nGram",  
> > "min\_gram": 1,  
> > "max\_gram": 20  
> > }  
> > },  
> > "tokenizer" : {  
> > "email\_tokenizer" : {  
> > "type" : "pattern",  
> > "pattern" :  
> > "[^@\:\.\-/=\-\w\p{L}\d]+"  
> > }  
> > },  
> > "analyzer": {  
> > "a1" : {  
> > "type" : "custom",  
> > "tokenizer":"email\_tokenizer",  
> > "filter" : ["lowercase", "mynGram"]  
> > }  
> > }  
> > }  
> > },  
> > "mappings" : {  
> > "foo\_doc" : {  
> > "index\_analyzer" : "a1",  
> > "search\_analyzer" : "whitespace",  
> > "date\_formats" : ["yyyy-MM-dd'T'HH:mm:ss"],  
> > "properties" : {  
> > "created\_timestamp" : {  
> > "index" : "not\_analyzed",  
> > "type" : "date",  
> > "store" : "yes"  
> > },  
> > "message" : {  
> > "index": "not\_analyzed",  
> > "type" : "string",  
> > "store": "yes"  
> > }  
> > }  
> > }  
> > }  
> > }'
> > 
> > --
> 
> --

--

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:03am UTC](https://discuss.elastic.co/t/issue-with-my-template-creation/9734/8 "2017-07-06T03:03:40Z")

</div>


