# Logstash templates? Are they needed?

**URL:** <https://discuss.elastic.co/t/logstash-templates-are-they-needed/101512>\
**Category:** Logstash\
**Created:** [September 22, 2017, 3:15pm UTC](https://discuss.elastic.co/t/logstash-templates-are-they-needed/101512 "2017-09-22T15:15:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lucasjkr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucasjkr/32/34317_2.png) [@lucasjkr](https://discuss.elastic.co/u/lucasjkr)\
**Post date:** [September 22, 2017, 3:15pm UTC](https://discuss.elastic.co/t/logstash-templates-are-they-needed/101512/1 "2017-09-22T15:15:32Z")

</div>

Might seem like a dumb question.

I've been trying to learn the ELK stack, and keep shifting focus between each component.

At work, I'm "playing" with a small cluster in attempt to ingest and analyze BRO data. Outside of work, I'm running a single instance that's ingesting from an Apache VPS.

I have never created any templates, either is Logstash or Elasticsearch, yet my data always seems to arrive, and be accessible in Kibana.

It might seem silly, but can anyone tell me if I should be doing something different? 🙂

ALSO: I've posted in other forums, but if anyone has any recommendations for a printed book about the whole stack (Elasticsearch, Kibana, Logstash), I would very much appreciate it. I'd rather a printed guide I can carry with me for instances when its' not practical to have two displays open (coffeeshop, etc). But that's an aside

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 24, 2017, 8:42pm UTC](https://discuss.elastic.co/t/logstash-templates-are-they-needed/101512/2 "2017-09-24T20:42:31Z")

</div>

Elasticsearch's dynamic mapper and Logstash's default index template is often but not always good enough. Occasions where you'd want a custom index template include:

- You're not happy with the default data type used for strings fields (string vs. keyword).
- You want to make sure certain fields are always mapped as e.g. integers, even if a single bad event arrives just after an index is rolled over and a new one is created.
- You have IP address fields.
- You want additional geo\_point fields or you're not happy with the name of the predefined one.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2017, 8:42pm UTC](https://discuss.elastic.co/t/logstash-templates-are-they-needed/101512/3 "2017-10-22T20:42:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
