# Logstash 7.0 does ignore index\_patterns / template fields in template and overrules that with "logstash-\*"

**URL:** <https://discuss.elastic.co/t/logstash-7-0-does-ignore-index-patterns-template-fields-in-template-and-overrules-that-with-logstash/179341>\
**Category:** Logstash\
**Created:** [May 2, 2019, 10:50am UTC](https://discuss.elastic.co/t/logstash-7-0-does-ignore-index-patterns-template-fields-in-template-and-overrules-that-with-logstash/179341 "2019-05-02T10:50:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![seilre](https://avatars.discourse-cdn.com/v4/letter/s/fbc32d/32.png) [@seilre](https://discuss.elastic.co/u/seilre)\
**Post date:** [May 2, 2019, 10:50am UTC](https://discuss.elastic.co/t/logstash-7-0-does-ignore-index-patterns-template-fields-in-template-and-overrules-that-with-logstash/179341/1 "2019-05-02T10:50:03Z")

</div>

I was using elastic stack 6.52 before and upgraded to 7.0 recently. Now it seems that my index templates are no longer updated correctly. I use the elasticsearch output plugin to install my template with following configuration (regarding template):

```
output {
    elasticsearch {
            #...
            manage_template => true
            template => "/usr/share/logstash/templates/my_mapping.json"
            template_name => "my_index_template"
            template_overwrite => true
            #...
     }
}

```

The template looks like this:

```
{
    "index_patterns" : ["my-index-name*"],
    "settings" : {
        "index.refresh_interval" : "10s",
        "index.number_of_shards" : 3,
        "index.number_of_replicas" : 0
    },
    "mappings" : {
        "numeric_detection" : true
    }
}

```

Now when logstash creates a index the following log message shows, that logstash uses that template but always overwrites my index\_patterns with "logstash-\*" or probably just ignores them. Here an example log line:

```
[2019-05-02T11:36:17,388][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage_template=>{"settings"=>{"index.refresh_interval"=>"10s", "index.number_of_shards"=>3, "index.number_of_replicas"=>0, "index.lifecycle.name"=>"logstash-policy", "index.lifecycle.rollover_alias"=>"logstash"}, "mappings"=>{"numeric_detection"=>true}, "index_patterns"=>"logstash-*"}}

```

I also tried with the deprecated field "template" instead of "index\_patterns" but had the same effect. When I put the same template directly to elasticsearch it's working.

Does anybody know what I'm missing here? Or was there a change in the elasticsearch output plugin which is not stated in the "Breaking Changes" section for logstash 7.0?

Thank's in advance for some help!

---

<div class="post-metadata">

**Author:** ![seilre](https://avatars.discourse-cdn.com/v4/letter/s/fbc32d/32.png) [@seilre](https://discuss.elastic.co/u/seilre)\
**Post date:** [May 2, 2019, 11:37am UTC](https://discuss.elastic.co/t/logstash-7-0-does-ignore-index-patterns-template-fields-in-template-and-overrules-that-with-logstash/179341/2 "2019-05-02T11:37:13Z")

</div>

Seems that I was not the only one with that issue but did not search enough I guess 😇

[https://github.com/elastic/logstash/issues/10687](https://github.com/elastic/logstash/issues/10687)

The described workaround (ilm\_enabled =\> false) works for me too and I can wait for the fixed version...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2019, 11:37am UTC](https://discuss.elastic.co/t/logstash-7-0-does-ignore-index-patterns-template-fields-in-template-and-overrules-that-with-logstash/179341/3 "2019-05-30T11:37:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
