# Metricbeat -\> LS -\> ES, template error \[SOLVED\]

**URL:** <https://discuss.elastic.co/t/metricbeat-ls-es-template-error-solved/64671>\
**Category:** Logstash\
**Created:** [November 2, 2016, 6:31am UTC](https://discuss.elastic.co/t/metricbeat-ls-es-template-error-solved/64671 "2016-11-02T06:31:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gregoryo](https://avatars.discourse-cdn.com/v4/letter/g/34f0e0/32.png) [@gregoryo](https://discuss.elastic.co/u/gregoryo)\
**Post date:** [November 2, 2016, 6:31am UTC](https://discuss.elastic.co/t/metricbeat-ls-es-template-error-solved/64671/1 "2016-11-02T06:31:15Z")

</div>

I have been successfully using Filebeat -\> LS -\> ES for a few months. I now want to add Metricbeat as another source. I started ingesting data fine, but continued reading docs.  
[https://www.elastic.co/guide/en/beats/metricbeat/current/config-metricbeat-logstash.html](https://www.elastic.co/guide/en/beats/metricbeat/current/config-metricbeat-logstash.html) tells me to load the index template manually, so did so (after stopping Metricbeat and deleting the index):

```
$ curl https://raw.githubusercontent.com/elastic/beats/f0b52e1926ef88dff0fa17f5341c16144a831c56/metricbeat/metricbeat.template.json > metricbeat.template.json
$ curl -XPUT 'http://localhost:9200/_template/metricbeat' -d@metricbeat.template.json
{"acknowledged":true}

```

At that point I start getting these errors in logstash.log:

```
"status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"Failed to parse mapping [_default_]: No handler for type [keyword] declared on field [hostname]", "caused_by"=>{"type"=>"mapper_parsing_exception", "reason"=>"No handler for type [keyword] declared on field [hostname]"}}}}, :level=>:warn}

```

I used this page was too:  
[https://www.elastic.co/guide/en/beats/metricbeat/current/logstash-output.html](https://www.elastic.co/guide/en/beats/metricbeat/current/logstash-output.html)

metricbeat.yml snippet:

```
output.logstash:
  index: metricbeat

```

logstash.conf snippet:

```
output {
  if [type] == 'metricsets' {
    elasticsearch {
      index => "%{[@metadata][beat]}-%{+xxxx.ww}"
      document_type => "%{[@metadata][type]}"

```

Can anyone suggest to me what might be wrong here? I think I would ultimately like to use indices named logstash-metricbeat-year-week, but sticking with default metricbeat-year-week while getting past this error.

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [November 2, 2016, 10:31am UTC](https://discuss.elastic.co/t/metricbeat-ls-es-template-error-solved/64671/2 "2016-11-02T10:31:26Z")

</div>

which version of elasticsearch are you using?

[edit]

metric beat provides 2 templates, one for elasticsearch 5.x (metricbeat.template.json) and another for 2.x (metricbeat.template-es2x.json)

---

<div class="post-metadata">

**Author:** ![gregoryo](https://avatars.discourse-cdn.com/v4/letter/g/34f0e0/32.png) [@gregoryo](https://discuss.elastic.co/u/gregoryo)\
**Post date:** [November 2, 2016, 12:34pm UTC](https://discuss.elastic.co/t/metricbeat-ls-es-template-error-solved/64671/3 "2016-11-02T12:34:17Z")

</div>

Excellent point, thank you. I wondered whether perhaps that 'keyword' was a new thing in 5.x, but there were so many uses of it in the template that I was hoping for a shortcut to the faultfinding - which you've given me. I am still using 2.3, waiting for 5.x to become available in the FreeBSD ports system.

I used the -es2x version of the template with a 's/metricbeat-/logstash-metricbeat-/', and all appears well.

Cheers,  
Greg.

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [November 2, 2016, 12:57pm UTC](https://discuss.elastic.co/t/metricbeat-ls-es-template-error-solved/64671/5 "2016-11-02T12:57:54Z")

</div>



---

<div class="post-metadata">

**Author:** ![gregoryo](https://avatars.discourse-cdn.com/v4/letter/g/34f0e0/32.png) [@gregoryo](https://discuss.elastic.co/u/gregoryo)\
**Post date:** [December 5, 2016, 4:41am UTC](https://discuss.elastic.co/t/metricbeat-ls-es-template-error-solved/64671/6 "2016-12-05T04:41:02Z")

</div>

Some details for future reference: I found the templates [here](https://github.com/elastic/beats/tree/bc9fdbf79a1f04adf45b9d9bde36c4d172ec011a/metricbeat), imported the [new version (5?)](https://github.com/elastic/beats/blob/bc9fdbf79a1f04adf45b9d9bde36c4d172ec011a/metricbeat/metricbeat.template.json) template, then after @jsvd's suggestion imported the [version 2 template](https://github.com/elastic/beats/blob/bc9fdbf79a1f04adf45b9d9bde36c4d172ec011a/metricbeat/metricbeat.template-es2x.json).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:30am UTC](https://discuss.elastic.co/t/metricbeat-ls-es-template-error-solved/64671/7 "2017-07-06T04:30:02Z")

</div>


