# Logstash not using given template json file on output section

**URL:** <https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730>\
**Category:** Logstash\
**Created:** [July 16, 2015, 2:52pm UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730 "2015-07-16T14:52:41Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 16, 2015, 2:52pm UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/1 "2015-07-16T14:52:41Z")

</div>

I have tried to create custom index pattern in Elasticsearch based on my input data. So I wrote some custom json and point it to template section of logstash output plugin.

But not sure why the index are not created in ELS as per the json file. It just creating default pattern in ELS.

Output section:  
output {  
stdout {codec =\> rubydebug }  
elasticsearch {  
host =\> localhost  
protocol =\> http  
index =\> "new-%{+YYYY.MM.dd}"  
template =\> "/opt/logstash/elasticsearch-new.json"

}

Do I need to add this json file somewhere else.?.

Version Details:  
Logstash : 1.5.2  
ELS: .13.9

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [July 17, 2015, 12:17am UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/2 "2015-07-17T00:17:05Z")

</div>

Did you delete the old template from Elasticsearch? Logstash won't add the new one until you delete the old one from Elasticsearch. Use:

```auto
curl -XDELETE <http://localhost:9200/_template/OldTemplateName?pretty>

```

Or you can use template\_overwrite:

[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template\_overwrite](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template_overwrite)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 17, 2015, 2:34am UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/3 "2015-07-17T02:34:50Z")

</div>

Also, is the template valid json?

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 17, 2015, 4:47am UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/4 "2015-07-17T04:47:53Z")

</div>

Why do we need to delete the old template[default template] from Elasticsearch ? Do you mean, we couldn't create custom template per index ?.

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 17, 2015, 4:50am UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/5 "2015-07-17T04:50:01Z")

</div>

@warkolm , Good to see you back again to respond for my query.

Yes, its a valid json file. I have cross verified my json file on this link [http://jsonlint.com/](http://jsonlint.com/) .

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 17, 2015, 4:58am UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/6 "2015-07-17T04:58:37Z")

</div>

Right, but is it valid Elasticsearch json 😄  
Can you apply the template using Sense or curl or similar?

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 17, 2015, 5:12am UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/7 "2015-07-17T05:12:19Z")

</div>

Yes , I already start working with the mentioned json file using curl PUT command. its working fine. Not sure , why this json file is not accepting in logstash output plugin.

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [July 17, 2015, 5:53pm UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/8 "2015-07-17T17:53:31Z")

</div>

If you do:

curl -XGET [http://localhost:9200/\_template/TemplateName?pretty](http://localhost:9200/_template/TemplateName?pretty)

What do you get? Replace TemplateName with what you specified as the template name in elasticsearch-new.json.

---

<div class="post-metadata">

**Author:** ![Sergio\_Pavez](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@Sergio\_Pavez](https://discuss.elastic.co/u/Sergio_Pavez)\
**Post date:** [July 13, 2016, 4:37pm UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/9 "2016-07-13T16:37:17Z")

</div>

I'm having the same problem. This is my template printed:

```
{
  "sigas-log-logstash": {
    "order": 0,
    "template": "sigas-log-logstash",
    "settings": {
      "index": {
        "refresh_interval": "60s"
      }
    },
    "mappings": {
      "_default_": {
        "dynamic_templates": [
          {
            "message_field": {
              "mapping": {
                "index": "not_analyzed",
                "type": "string"
              },
              "match_mapping_type": "string",
              "match": "message"
            }
          },
          {
            "string_fields": {
              "mapping": {
                "index": "not_analyzed",
                "type": "string"
              },
              "match_mapping_type": "string",
              "match": "*"
            }
          }
        ],
        "_all": {
          "enabled": false
        },
        "properties": {
          "severity": {
            "index": "not_analyzed",
            "type": "string"
          },
          "date": {
            "format": "yyyyMMdd HHmmss.SSSSSS",
            "type": "date"
          },
          "interpreter": {
            "index": "not_analyzed",
            "type": "string"
          },
          "thread": {
            "index": "not_analyzed",
            "type": "integer"
          },
          "uuid": {
            "index": "not_analyzed",
            "type": "string"
          },
          "received_from": {
            "index": "not_analyzed",
            "type": "string"
          },
          "@timestamp": {
            "format": "dateOptionalTime",
            "type": "date"
          },
          "resource_id_module": {
            "index": "not_analyzed",
            "type": "string"
          },
          "file": {
            "index": "not_analyzed",
            "type": "string"
          },
          "execute_time": {
            "index": "not_analyzed",
            "type": "integer"
          },
          "@version": {
            "index": "not_analyzed",
            "type": "integer"
          },
          "log_message": {
            "index": "not_analyzed",
            "type": "string"
          },
          "id_log": {
            "index": "not_analyzed",
            "type": "string"
          }
        }
      }
    },
    "aliases": {}
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:48am UTC](https://discuss.elastic.co/t/logstash-not-using-given-template-json-file-on-output-section/25730/10 "2017-07-06T04:48:11Z")

</div>


