# Issues manually loading a template to ES

**URL:** <https://discuss.elastic.co/t/issues-manually-loading-a-template-to-es/62972>\
**Category:** Elasticsearch\
**Created:** [October 13, 2016, 4:54pm UTC](https://discuss.elastic.co/t/issues-manually-loading-a-template-to-es/62972 "2016-10-13T16:54:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mcasa](https://avatars.discourse-cdn.com/v4/letter/m/67e7ee/32.png) [@mcasa](https://discuss.elastic.co/u/mcasa)\
**Post date:** [October 13, 2016, 4:54pm UTC](https://discuss.elastic.co/t/issues-manually-loading-a-template-to-es/62972/1 "2016-10-13T16:54:29Z")

</div>

So I upgraded winlogbeats to 5.x alpha to get a more granular view of my sys logs but I cant get the new json template loaded into elastic search. currently files are still getting shipped from winlogbeats to LS and eventually to ES, im just not getting all the fields that i was expecting with 5.x upgrade. bellow are my commands and errors.

from windows to ELK server  
`  
PS C:\Program Files (x86)\winlogbeat-5.0.0-alpha5-windows-x86\_64\> Invoke-WebRequest -Method Put -InFile winlogbeat.temp  
ate.json -Uri [http://x.x.x.251:9200/\_template/winlogbeat?pretty](http://x.x.x.251:9200/_template/winlogbeat?pretty)  
Invoke-WebRequest : { "error" : { "root\_cause" : [ { "type" : "mapper\_parsing\_exception", "reason" : "No handler for  
type [keyword] declared on field [related\_activity\_id]" } ], "type" : "mapper\_parsing\_exception", "reason" : "Failed  
to parse mapping [_default_]: No handler for type [keyword] declared on field [related\_activity\_id]", "caused\_by" : {  
"type" : "mapper\_parsing\_exception", "reason" : "No handler for type [keyword] declared on field  
[related\_activity\_id]" } }, "status" : 400 }  
At line:1 char:1

- Invoke-WebRequest -Method Put -InFile winlogbeat.template.json -Uri [http://x.x](http://x.x) ...
- 

```auto
  + CategoryInfo : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebExc
 eption
  + FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand  

```

`i also copied over the winlogbeat.template.json over to the ELK server and tried to load it :slight_smile:`  
[root@chglnx05 conf.d]# curl -XPUT '[http://localhost:9200/\_template/winlogbeat](http://localhost:9200/_template/winlogbeat)' /home/admin/winlogbeat.template.json  
{"error":{"root\_cause":[{"type":"parse\_exception","reason":"Failed to derive xcontent"}],"type":"parse\_exception","reason":"Failed to derive xcontent"},"status":400}curl: (3) malformed `

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 14, 2016, 10:06am UTC](https://discuss.elastic.co/t/issues-manually-loading-a-template-to-es/62972/2 "2016-10-14T10:06:19Z")

</div>

`curl -XPUT 'http://localhost:9200/_template/winlogbeat' -d @/home/admin/winlogbeat.template.json` - you're missing the `-d @` in the command.

See [https://www.elastic.co/guide/en/beats/packetbeat/1.3/packetbeat-template.html#load-template-shell](https://www.elastic.co/guide/en/beats/packetbeat/1.3/packetbeat-template.html#load-template-shell), which is the same process as [https://www.elastic.co/guide/en/beats/winlogbeat/5.0/winlogbeat-template.html#load-template-manually](https://www.elastic.co/guide/en/beats/winlogbeat/5.0/winlogbeat-template.html#load-template-manually)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:12pm UTC](https://discuss.elastic.co/t/issues-manually-loading-a-template-to-es/62972/3 "2017-07-05T22:12:19Z")

</div>


