# Logstash using default template instead of the one I added

**URL:** <https://discuss.elastic.co/t/logstash-using-default-template-instead-of-the-one-i-added/168904>\
**Category:** Logstash\
**Created:** [February 18, 2019, 9:49pm UTC](https://discuss.elastic.co/t/logstash-using-default-template-instead-of-the-one-i-added/168904 "2019-02-18T21:49:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jwalls](https://avatars.discourse-cdn.com/v4/letter/j/0ea827/32.png) [@jwalls](https://discuss.elastic.co/u/jwalls)\
**Post date:** [February 18, 2019, 9:49pm UTC](https://discuss.elastic.co/t/logstash-using-default-template-instead-of-the-one-i-added/168904/1 "2019-02-18T21:49:32Z")

</div>

when booting up logstash, i can't find the template for ES I added and I get:

```
 [2019-02-18T21:24:30,994][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=>nil}
 [2019-02-18T21:24:31,009][INFO][logstash.outputs.elasticsearch] Attempting to install template {...}

```

So I get that there's no path specified for the logstash template, but where do I specify the path? And if I'm using a container, do I specify the ES link ie. `localhost:9200/_template/logstash` ? or a file path?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 18, 2019, 10:01pm UTC](https://discuss.elastic.co/t/logstash-using-default-template-instead-of-the-one-i-added/168904/2 "2019-02-18T22:01:49Z")

</div>

You would supply it using the [template option](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template) on the elasticsearch output. I am surprised you get that message given what the [code](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/df4ec9a73591fb96fff0d7002a67d27e0adc6672/lib/logstash/outputs/elasticsearch/template_manager.rb#L6) looks like.

---

<div class="post-metadata">

**Author:** ![jwalls](https://avatars.discourse-cdn.com/v4/letter/j/0ea827/32.png) [@jwalls](https://discuss.elastic.co/u/jwalls)\
**Post date:** [February 20, 2019, 7:25pm UTC](https://discuss.elastic.co/t/logstash-using-default-template-instead-of-the-one-i-added/168904/3 "2019-02-20T19:25:42Z")

</div>

I've specified the path, but I'm getting the following error.

```
  # This setting must be a path
  # File does not exist or cannot be opened /etc/logstash/logstash_index.template.json
  template => "/etc/logstash/logstash_index.template.json"

```

I've given permissions to all folders and the template itself. I'm running logstash on a docker container.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 20, 2019, 9:51pm UTC](https://discuss.elastic.co/t/logstash-using-default-template-instead-of-the-one-i-added/168904/4 "2019-02-20T21:51:50Z")

</div>

I have never used docker, but I have seen several times people posting about failure to open files in docker images where the issue was that they didn't map the file into the image.

---

<div class="post-metadata">

**Author:** ![jwalls](https://avatars.discourse-cdn.com/v4/letter/j/0ea827/32.png) [@jwalls](https://discuss.elastic.co/u/jwalls)\
**Post date:** [February 22, 2019, 8:10pm UTC](https://discuss.elastic.co/t/logstash-using-default-template-instead-of-the-one-i-added/168904/5 "2019-02-22T20:10:39Z")

</div>

Yes thank you, the template wasn't being mounted to the container properly. That solved the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2019, 8:10pm UTC](https://discuss.elastic.co/t/logstash-using-default-template-instead-of-the-one-i-added/168904/6 "2019-03-22T20:10:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
