# Logstash template creation problem: parsing

**URL:** https://discuss.elastic.co/t/logstash-template-creation-problem-parsing/14176
**Category:** Elasticsearch
**Created:** [October 30, 2013, 7:45pm UTC](https://discuss.elastic.co/t/logstash-template-creation-problem-parsing/14176 "2013-10-30T19:45:02Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![tom\_rkba](https://avatars.discourse-cdn.com/v4/letter/t/e79b87/32.png) [@tom\_rkba](https://discuss.elastic.co/u/tom_rkba)
#### Post date: [October 30, 2013, 7:45pm UTC](https://discuss.elastic.co/t/logstash-template-creation-problem-parsing/14176/1 "2013-10-30T19:45:02Z")

</div>

curl -XPUT [http://localhost:9200/\_template/logstash\_per\_index](http://localhost:9200/_template/logstash_per_index) -d '{

> "template": "logstash\*",  
> "settings": {  
> "index.query.default\_field": "@message",  
> "index.cache.field.type": "soft",  
> "index.store.compress.stored": true  
> },  
> "mappings": {  
> "_default_": {  
> "\_all": { "enabled": false },  
> "properties": {  
> "@message": { "type": "string", "index": "analyzed" },  
> "@source": { "type": "string", "index": "not\_analyzed" },  
> "@source\_host": { "type": "string", "index": "not\_analyzed" },  
> "@source\_path": { "type": "string", "index": "not\_analyzed" },  
> "@tags": { "type": "string", "index": "not\_analyzed" },  
> "@timestamp": { "type": "string", "index": "not\_analyzed" },  
> "@type": { "type": "string", "index": "not\_analyzed" },  
> },  
> }  
> }  
> }  
> '  
> {"error":"ElasticSearchIllegalArgumentException[failed to parse template  
> source]; nested: JsonParseException[Unexpected character ('}' (code 125)):  
> was expecting either valid name character (for unquoted name) or  
> double-quote (for quoted) to start field name\n at [Source: [B@6594ed01; line: 19, column: 8]]; ","status":400}

What am I missing? Line 19 is a closing brace. Everything looks correct.  
Any ideas?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [October 30, 2013, 7:49pm UTC](https://discuss.elastic.co/t/logstash-template-creation-problem-parsing/14176/2 "2013-10-30T19:49:14Z")

</div>

Some comma signs at the end should not be here I guess.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 30 oct. 2013 à 20:45, tom rkba [tomrkba@gmail.com](mailto:tomrkba@gmail.com) a écrit :

> curl -XPUT [http://localhost:9200/\_template/logstash\_per\_index](http://localhost:9200/_template/logstash_per_index) -d '{
> 
> > "template": "logstash\*",  
> > "settings": {  
> > "index.query.default\_field": "@message",  
> > "index.cache.field.type": "soft",  
> > "index.store.compress.stored": true  
> > },  
> > "mappings": {  
> > "_default_": {  
> > "\_all": { "enabled": false },  
> > "properties": {  
> > "@message": { "type": "string", "index": "analyzed" },  
> > "@source": { "type": "string", "index": "not\_analyzed" },  
> > "@source\_host": { "type": "string", "index": "not\_analyzed" },  
> > "@source\_path": { "type": "string", "index": "not\_analyzed" },  
> > "@tags": { "type": "string", "index": "not\_analyzed" },  
> > "@timestamp": { "type": "string", "index": "not\_analyzed" },  
> > "@type": { "type": "string", "index": "not\_analyzed" },  
> > },  
> > }  
> > }  
> > }  
> > '  
> > {"error":"ElasticSearchIllegalArgumentException[failed to parse template source]; nested: JsonParseException[Unexpected character ('}' (code 125)): was expecting either valid name character (for unquoted name) or double-quote (for quoted) to start field name\n at [Source: [B@6594ed01; line: 19, column: 8]]; ","status":400}
> 
> What am I missing? Line 19 is a closing brace. Everything looks correct. Any ideas?
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![tom\_rkba](https://avatars.discourse-cdn.com/v4/letter/t/e79b87/32.png) [@tom\_rkba](https://discuss.elastic.co/u/tom_rkba)
#### Post date: [October 31, 2013, 1:56pm UTC](https://discuss.elastic.co/t/logstash-template-creation-problem-parsing/14176/3 "2013-10-31T13:56:37Z")

</div>

SOLUTION: remove two commas

curl -XPUT [http://localhost:9200/\_template/logstash\_per\_index](http://localhost:9200/_template/logstash_per_index) -d '{  
"template": "logstash\*",  
"settings": {  
"index.query.default\_field": "@message",  
"index.cache.field.type": "soft",  
"index.store.compress.stored": true  
},  
"mappings": {  
"_default_": {  
"\_all": { "enabled": false },  
"properties": {  
"@message": { "type": "string", "index": "analyzed" },  
"@source": { "type": "string", "index": "not\_analyzed" },  
"@source\_host": { "type": "string", "index": "not\_analyzed" },  
"@source\_path": { "type": "string", "index": "not\_analyzed" },  
"@tags": { "type": "string", "index": "not\_analyzed" },  
"@timestamp": { "type": "string", "index": "not\_analyzed" },  
"@type": { "type": "string", "index": "not\_analyzed" }  
}  
}  
}  
}  
'

Remove the comma at the end of any line that ends with } and has no other  
items after it.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 2:09am UTC](https://discuss.elastic.co/t/logstash-template-creation-problem-parsing/14176/4 "2017-07-06T02:09:37Z")

</div>


