# Logstash ignores newly created template when importing index

**URL:** <https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215>\
**Category:** Logstash\
**Created:** [March 22, 2023, 7:40am UTC](https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215 "2023-03-22T07:40:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![eeijlar](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Post date:** [March 22, 2023, 7:40am UTC](https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215/1 "2023-03-22T07:40:43Z")

</div>

I am using the following pipeline to do an import of an index exported from Elastic:

```auto
    - pipeline.id: import-process
      pipeline.workers: 4
      config.string: |
        input {
          file {
            path => "/usr/share/logstash/export/export_metricbeat-7.17.7-2023.03.21-000001.json"
            codec => "json"
            mode => "read"
            exit_after_read => true
          }
        }

        output {
          elasticsearch {
             hosts => "http://localhost:9200"
             manage_template => true
             template => "/usr/share/logstash/config/metricbeat.template.json"
             template_name => "metricbeat-7.17.7"
             template_overwrite => true
             index => "metricbeat-7.17.7-2023.03.21-000001"
             ssl => "false"
          }
        }

```

The metricbeat template is as follows:

```auto
{
  "index_patterns": [
    "metricbeat*"
  ],
  "settings": {
    "index": {
      "mapping": {
        "total_fields": {
          "limit": "10000"
        }
      }
    }
  }
}

```

It just increases the limit on the number of fields for the index. When I run logstash, I can see the template gets loaded:

```auto
[2023-03-22T08:05:17,061][INFO][logstash.outputs.elasticsearch] Installing Elasticsearch template {:name=>"metricbeat-7.17.7"}

```

I can see the template in Kibana. However, when logstash starts importing documents, it issues warnings about exceeding the number of fields:

```auto
"reason"=>"failed to parse", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"Limit of total fields [10
00] has been exceeded while adding new fields [1]"}}}}}

```

If I create a template in Kibana manually (not a legacy template, just a regular template). I used the same settings, and no other options selected. When I do it this way, I don't get the error on the import.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2023, 7:40am UTC](https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215/2 "2023-04-19T07:40:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
