# Logstash Templates Incorrect

**URL:** <https://discuss.elastic.co/t/logstash-templates-incorrect/112816>\
**Category:** Elasticsearch\
**Created:** [December 21, 2017, 12:09pm UTC](https://discuss.elastic.co/t/logstash-templates-incorrect/112816 "2017-12-21T12:09:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Borrelworst](https://avatars.discourse-cdn.com/v4/letter/b/6f9a4e/32.png) [@Borrelworst](https://discuss.elastic.co/u/Borrelworst)\
**Post date:** [December 21, 2017, 12:09pm UTC](https://discuss.elastic.co/t/logstash-templates-incorrect/112816/1 "2017-12-21T12:09:02Z")

</div>

Hi All,

This is not a real issue, well maybe for some of you, but I want to clear some things out:

I am already using Elasticseach for a couple of years and really like the software and what you can do with it. However, I am not really happy with the update/upgrade strategy. It seems that every time when there is a minor or major update, my cluster get's screwed over because of changed mappings,functionality etc.

All of this should not really matter if you can provide is with good examples, however they do not come along with the software.

As an example: I upgraded from 5.6.3 to 6.1.0 and immediately all of my templates are useless, for example the \_all field is deprecated (while this is in all of my templates). It kind of screws up all of my historic data.

Now the annoying thing is, I thought using the Logstash ELK6 template as a base, to see what exactly has changed, and this is what really is weird:

In the default template in logstash 6.1.0 there is this part:

{  
"template" : "logstash-\*",  
"version" : 60001,  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"_default_" : {  
"dynamic\_templates" : [ {

Then when using this template, you will get this in your deprecation logs:

[WARN][o.e.d.a.a.i.t.p.PutIndexTemplateRequest] Deprecated field [template] used, replaced by [index\_patterns]  
[WARN][o.e.d.i.m.MapperService] [_default_] mapping is deprecated since it is not useful anymore now that indexes cannot have more than one type

This kind of baffles me: While it is already known that these things will get deprecated, it is still in the logstash templates of the same version as Elasticsearch. To me this seems kind of messy and people who develop these things should know better.

I am not sure if this is accidental or on purpose so we all need to take ES courses, but as you promoted that from version 5 and on ES, Logstash and Kibana are in line, just get it right.

I had a discussion yesterday with someone about the same topic, and as I was seeing this in the logs I just wanted to share this. Please feel free to comment or share your own experience with upgrading. If I am the only one having this issue, then I should probably take all the ELK courses 😀 !

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [December 25, 2017, 8:18pm UTC](https://discuss.elastic.co/t/logstash-templates-incorrect/112816/2 "2017-12-25T20:18:32Z")

</div>

You don't need to take full ES courses to learn about the breaking changes from one version to another.

Yet some reading is still needed so you stay updated and, for that, I strongly recommend that you read our [blog](https://www.elastic.co/blog). For instance, for the changes you are referring to, which is the document type deprecation, we blogged about it [before](https://www.elastic.co/blog/index-type-parent-child-join-now-future-in-elasticsearch) and [after](https://www.elastic.co/blog/elasticsearch-6-0-0-released) the 6.0 release.

---

<div class="post-metadata">

**Author:** ![Dieter](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@Dieter](https://discuss.elastic.co/u/Dieter)\
**Post date:** [December 26, 2017, 12:21pm UTC](https://discuss.elastic.co/t/logstash-templates-incorrect/112816/3 "2017-12-26T12:21:05Z")

</div>

I noticed the same.  
The logstash defaults seem to create indices with these deprecated mappings.

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [December 26, 2017, 4:14pm UTC](https://discuss.elastic.co/t/logstash-templates-incorrect/112816/4 "2017-12-26T16:14:17Z")

</div>

@thiago I think that what @Borrelworst is referring to is that in the Logstash `elasticsearch` output plugin the [template for ES 6.x](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es6x.json) still contains deprecated settings, i.e.

```auto
{
 "template" : "logstash-*", <---- this is deprecated
 "version" : 60001,
 "settings" : {
   "index.refresh_interval" : "5s"
 },
 "mappings" : {
   "_default_" : { <---- this is deprecated
     "dynamic_templates" : [ {

```

The [template for ES 7.x](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es7x.json) doesn't contain the `_default_` mapping anymore but still uses `template` instead of `index_patterns`.

Note, though, that there's an [open (still unmerged) PR](https://github.com/logstash-plugins/logstash-output-elasticsearch/pull/707) for the first problem and another [open issue](https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/696) for the second problem.

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [December 27, 2017, 11:25am UTC](https://discuss.elastic.co/t/logstash-templates-incorrect/112816/5 "2017-12-27T11:25:23Z")

</div>

The change I mentioned was only an example. My point was to follow our blog to keep updated with breaking changes.

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [December 27, 2017, 3:52pm UTC](https://discuss.elastic.co/t/logstash-templates-incorrect/112816/6 "2017-12-27T15:52:54Z")

</div>

Sure @thiago but my point was that what is currently shipping with Logstash 6 is somewhat deprecated 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2018, 3:52pm UTC](https://discuss.elastic.co/t/logstash-templates-incorrect/112816/7 "2018-01-24T15:52:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
