# Logstash -\> Elasticsearch index template

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339>\
**Category:** Elasticsearch\
**Created:** [July 31, 2020, 10:56am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339 "2020-07-31T10:56:44Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![egray](https://avatars.discourse-cdn.com/v4/letter/e/278dde/32.png) [@egray](https://discuss.elastic.co/u/egray)\
**Post date:** [July 31, 2020, 10:56am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/1 "2020-07-31T10:56:44Z")

</div>

I am running Logstash and a three-node Elasticsearch cluster in docker containers. In the Elasticsearch output plugin of Logstash, I'm attempting to use a custom index template with the following lines in logstash.conf:

```auto
manage_template => true
template_name => "my-logs"
template => "/usr/share/logstash/template.json"

```

When I run this, I get a 'failed to install template' error with code 400 from Elasticsearch, which I've interpreted to mean there's something wrong with my template, but from looking at the examples I can't see anything wrong. I've also tried making sure Elasticsearch is definitely up and running before starting Logstash.

```auto
{
    "index_patterns" : ["my-logs*"],
    "priority" : 1,
    "template": {
    	"settings" : {
    		"number_of_shards" : 1,
    		"number_of_replicas" : 1
    	},
    	"mappings": {
    		"properties": {
    			"geoip":{
    				"dynamic": true,
    				"type" : "object",
    				"properties": {
    					"location": {
    						"type" : "geo_point"
    					}
    				}
    			}
    		}
    	}
    }
}

```

Edit: I forgot to add that the the logs are first coming from Filebeat, although that shouldn't be relevant.

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [July 31, 2020, 12:17pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/2 "2020-07-31T12:17:09Z")

</div>

Which version of ES are you running?

---

<div class="post-metadata">

**Author:** ![egray](https://avatars.discourse-cdn.com/v4/letter/e/278dde/32.png) [@egray](https://discuss.elastic.co/u/egray)\
**Post date:** [July 31, 2020, 12:34pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/3 "2020-07-31T12:34:25Z")

</div>

7.8.0

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [July 31, 2020, 12:35pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/4 "2020-07-31T12:35:53Z")

</div>

If you run Logstash with `--debug` do you get more information about that HTTP 400?

---

<div class="post-metadata">

**Author:** ![egray](https://avatars.discourse-cdn.com/v4/letter/e/278dde/32.png) [@egray](https://discuss.elastic.co/u/egray)\
**Post date:** [July 31, 2020, 1:25pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/5 "2020-07-31T13:25:35Z")

</div>

Changing logging level to debug didn't give me any more information, but here is the full error message:

> Failed to install template. {:message=\>"Got response code '400' contacting Elasticsearch at URL '[http://es01:9200/\_template/my-logs](http://es01:9200/_template/my-logs)'", :class=\>"LogStash::Outputs::Elasticsearch::HttpClient::Pool::BadResponseCodeError", :backtrace=\>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http\_client/manticore\_adapter.rb:80:in `perform_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:332:in `perform\_request\_to\_url'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:319:in `block in perform_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:414:in `with\_connection'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:318:in `perform_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:326:in `block in Pool'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http\_client.rb:352:in `template_put'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client.rb:86:in `template\_install'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/template\_manager.rb:28:in `install'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/template_manager.rb:16:in `install\_template'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/common.rb:205:in `install_template'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/common.rb:49:in `block in setup\_after\_successful\_connection'"]}

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [July 31, 2020, 1:36pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/6 "2020-07-31T13:36:32Z")

</div>

Oh, I know why...

Logstash doesn't yet support the new [index templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html), but only the [legacy index templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates-v1.html).

If you change your template to the following one, it will work:

```
{
    "index_patterns" : ["my-logs*"],
    "order" : 1,
	"settings" : {
		"number_of_shards" : 1,
		"number_of_replicas" : 1
	},
	"mappings": {
		"properties": {
			"geoip":{
				"dynamic": true,
				"type" : "object",
				"properties": {
					"location": {
						"type" : "geo_point"
					}
				}
			}
		}
	}
}

```

I've opened a [new issue](https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/958) to track this.

---

<div class="post-metadata">

**Author:** ![egray](https://avatars.discourse-cdn.com/v4/letter/e/278dde/32.png) [@egray](https://discuss.elastic.co/u/egray)\
**Post date:** [July 31, 2020, 1:52pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/7 "2020-07-31T13:52:51Z")

</div>

Thank you, this worked! Or at least got rid of the error. Will legacy templates continue to be supported in the update?

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [July 31, 2020, 1:54pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/8 "2020-07-31T13:54:44Z")

</div>

Cool, glad it helped!

If the issue will be handled, I suppose the `elasticsearch` output plugin should continue working with both legacy and new templates for the foreseeable future.

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [July 31, 2020, 6:15pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/9 "2020-07-31T18:15:40Z")

</div>

> [@egray](#):
>
> ```auto
> 
> ```

Out of curiosity, what's the advantage of the new template compared to the old one?

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [July 31, 2020, 8:52pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/10 "2020-07-31T20:52:23Z")

</div>

The biggest advantage is that now index templates will be [composable](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-component-template.html) out of component templates.

The main reason they did this (I believe) was to help with the redesign of the new [Ingest Manager and Data Streams](https://www.elastic.co/blog/introducing-elastic-agent-and-ingest-manager), where each data set will be able to provide its own component templates. This and probably many other reasons, too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2020, 8:52pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339/11 "2020-08-28T20:52:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
