# Logstash-Elasticsearch Output Using Templates

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-output-using-templates/61160>\
**Category:** Logstash\
**Created:** [September 21, 2016, 4:46pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-using-templates/61160 "2016-09-21T16:46:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maxwell\_Flanders](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@Maxwell\_Flanders](https://discuss.elastic.co/u/Maxwell_Flanders)\
**Post date:** [September 21, 2016, 4:46pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-using-templates/61160/1 "2016-09-21T16:46:12Z")

</div>

I have been wondering something about the "template" and "template\_overwrite" option in the elasticsearch output plugin for logstash. Because this is part of the output configuration, it should be invoked for every single record that passes through that output block. Does this mean logstash makes a "PUT" api call with the same template for every single record that passes through it?? Because in high-throughput pipelines, even if the template never changed, wouldn't this increase the load on the cluster??

If it does not do that, when DOES it run that template "PUT" operation, because it must have to do that periodically in order to be sure that the template remains up to date.

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 21, 2016, 5:43pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-using-templates/61160/2 "2016-09-21T17:43:01Z")

</div>

Templates are only installed when Logstash starts up.

---

<div class="post-metadata">

**Author:** ![Maxwell\_Flanders](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@Maxwell\_Flanders](https://discuss.elastic.co/u/Maxwell_Flanders)\
**Post date:** [September 21, 2016, 5:49pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-using-templates/61160/3 "2016-09-21T17:49:10Z")

</div>

Oh so if I change a template file referenced in a logstash- elasticsearch output, I still need to restart logstash to see the template change reflected in elasticsearch?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 21, 2016, 6:09pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-using-templates/61160/4 "2016-09-21T18:09:54Z")

</div>

Yes. See also [https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/380](https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/380).

I prefer managing the templates outside of Logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:37am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-using-templates/61160/5 "2017-07-06T04:37:31Z")

</div>


