# Loaded template is not appearing in Elastic

**URL:** <https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499>\
**Category:** Logstash\
**Created:** [March 6, 2017, 12:49pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499 "2017-03-06T12:49:46Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 6, 2017, 12:49pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/1 "2017-03-06T12:49:46Z")

</div>

Hello,  
I am currently trying to load existing template from Previous Elastic version 2.\* to the new nodes with version 5.\*.  
Using this command:

C:\Users\admin\> Invoke-RestMethod -Uri '[http://localhost:9200/\_template/nlog](http://localhost:9200/_template/nlog)' -Method 'PUT' -infile c:\nlog.json

and getting the result:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8b5b7e894cd141a7c1616b8b89eb7f2358fd0458.png)

But it is absent in management and i can not see it in dev tools it to check "get \_cat/templates"

Please advise what is wrong?

Thanks.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 6, 2017, 2:21pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/2 "2017-03-06T14:21:36Z")

</div>

Please do not post screen shots of text as it can be very hard to read (it is in this case). Mappings have changed quite a bit between Elasticsearch 2.x and 5.x. What does the index template you are trying to store look like?

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 6, 2017, 2:33pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/3 "2017-03-06T14:33:31Z")

</div>

It is default index template which is located in Logstash folder. "elasticsearch-template-es5x.json"  
sometimes it can be created, sometimes not.  
But currenclty i can not create it neither curl Invoke-RestMethod -Uri '[http://localhost:9200/\_template/nlog](http://localhost:9200/_template/nlog)' -Method 'PUT' -infile c:\elasticsearch-template-es5x.json

nor via Dev tools .

put \_template/logstash-\*

{  
"template" : "logstash-_",  
"version" : 50001,  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"default" : {  
"\_all" : {"enabled" : true, "norms" : false},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"path\_match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text",  
"norms" : false  
}  
}  
}, {  
"string\_fields" : {  
"match" : "_",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text", "norms" : false,  
"fields" : {  
"keyword" : { "type": "keyword" }  
}  
}  
}  
} ],  
"properties" : {  
"@timestamp": { "type": "date", "include\_in\_all": false },  
"@version": { "type": "keyword", "include\_in\_all": false },  
"geoip" : {  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" },  
"location" : { "type" : "geo\_point" },  
"latitude" : { "type" : "half\_float" },  
"longitude" : { "type" : "half\_float" }  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 6, 2017, 2:47pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/4 "2017-03-06T14:47:30Z")

</div>

> [@111148](#):
>
> put \_template/logstash-\*

Haver you tried giving it a name that does not contain a wildcard?

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 6, 2017, 2:54pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/5 "2017-03-06T14:54:20Z")

</div>

yes i have tried. result is the same:

put \_template/logstash-2017.03.06

{  
"error": {  
"root\_cause": [  
{  
"type": "not\_x\_content\_exception",  
"reason": "Compressor detection can only be called on some xcontent bytes or compressed xcontent bytes"  
}  
],  
"type": "not\_x\_content\_exception",  
"reason": "Compressor detection can only be called on some xcontent bytes or compressed xcontent bytes"  
},  
"status": 500  
}

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 6, 2017, 3:14pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/6 "2017-03-06T15:14:40Z")

</div>

> [@111148](#):
>
> "reason": "Compressor detection can only be called on some xcontent bytes or compressed xcontent

Managed create logstash-\* index (application created it for me, not me personally) but only after deleting the whole logstash and reinstalling it from the scratch.  
Guys, i am sorry to say but your product is to difficult and complicated for usage. And after even reading many hours manuals it is still unclear how it works.

now i can see this index with x\_ prefix. (yellow open logstash-2017.03.06 x\_jbWsQiSJmusBv7GQCEVg)  
What does it mean?

and how i should create the rest of indices? I need two more indices for another applications but i can not create them because of this error.

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 6, 2017, 4:20pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/7 "2017-03-06T16:20:37Z")

</div>

Updated up to ELK 5.2.2. and got the same error.  
Guys what is happening? Why i can not create indeces folowing your docs? [https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html)

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 6, 2017, 9:45pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/8 "2017-03-06T21:45:28Z")

</div>

Please explain this because i do not understand why it does not work:

[2017-03-06T21:31:40,719][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2017-03-06T21:31:40,849][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>50001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "norms"=\>false}, "dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword"}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "include\_in\_all"=\>false}, "@version"=\>{"type"=\>"keyword", "include\_in\_all"=\>false}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2017-03-06T21:31:40,864][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>[#\<URI::Generic:0x7250596a URL://localhost:9200\>]}  
[2017-03-06T21:31:40,870][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>250}  
[2017-03-06T21:31:40,874][INFO][logstash.pipeline] Pipeline main started  
[2017-03-06T21:31:40,927][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

As i can see from Logstash logfile its template was instaled. Then please tell me why i still can not see this template instaled in Kibana\Elasticsearch?  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fcf6a24f98817b927b5e8ab330ea9ff550a88c01.jpg)

and there

![](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a92f25168a0f905500b17a4d4a1bf573336f8495.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 6, 2017, 10:00pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/9 "2017-03-06T22:00:06Z")

</div>

Have you indexed any data into Elasticsearch? Can you provide the output from the [cat indices API](https://www.elastic.co/guide/en/elasticsearch/reference/current/cat-indices.html)?

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 6, 2017, 10:27pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/10 "2017-03-06T22:27:51Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/3X/3/2/325868e563fd0aa8a066ccf494245326612f8379.png)  
i have indexed some data and looks like time field appeared and now i can create index template.

yellow open logstash-2017.03.06 UXxhdZsqT2a\_4uNZgCJIOQ 5 1 3418 0 885.9kb 885.9kb

BUT! it works only for the case of data from Azure blob where i have many log files (thousands of logs). But if to index only 1 small file locally it still doesn`t work, does not appear. Is there any limit on the data which should be indexed to make index work? And i thought that i should first create an index and only then start to index data but not vise versa. And should i have the same config on all the ELK nodes or i can use on each node different configs for different input sources for different indexes to avoid one big general comprehensive config on all the nodes which is not so easy to make work? Thanks in advance!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2017, 8:51am UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/11 "2017-03-07T08:51:15Z")

</div>

It seems like you're confusing _indexes_ with _index templates_, which could partly explain why you're having difficulties.

> Is there any limit on the data which should be indexed to make index work?

No.

> And i thought that i should first create an index and only then start to index data but not vise versa.

Indexes will automatically be created as needed based on the documents you're indexing.

> And should i have the same config on all the ELK nodes or i can use on each node different configs for different input sources for different indexes to avoid one big general comprehensive config on all the nodes which is not so easy to make work?

Are you talking about the Logstash configuration? If yes, then it's up to you. Regardless of what you choose things will get complex but in different ways.

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 7, 2017, 1:06pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/12 "2017-03-07T13:06:04Z")

</div>

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2017, 1:06pm UTC](https://discuss.elastic.co/t/loaded-template-is-not-appearing-in-elastic/77499/13 "2017-04-04T13:06:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
