# Multiple templates in single file in logstash's elasticsearch output plugin

**URL:** <https://discuss.elastic.co/t/multiple-templates-in-single-file-in-logstashs-elasticsearch-output-plugin/167155>\
**Category:** Elasticsearch\
**Created:** [February 5, 2019, 3:47pm UTC](https://discuss.elastic.co/t/multiple-templates-in-single-file-in-logstashs-elasticsearch-output-plugin/167155 "2019-02-05T15:47:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![siginigin](https://avatars.discourse-cdn.com/v4/letter/s/4bbf92/32.png) [@siginigin](https://discuss.elastic.co/u/siginigin)\
**Post date:** [February 5, 2019, 3:47pm UTC](https://discuss.elastic.co/t/multiple-templates-in-single-file-in-logstashs-elasticsearch-output-plugin/167155/1 "2019-02-05T15:47:02Z")

</div>

Hi guys,

I'm trying to install multiple templates (=2) in single index, based on name pattern. The point is to minimize number of fileds in indexes. I want to achieve to have _default_ and proxy fields in logstash-proxy indexes, and _default_ and mail fields in logstash-mail-\* indexes.

This is my setup:

/etc/logstash/template.json:  
{  
"template": "logstash-_",  
"settings": {  
"number\_of\_shards": 3,  
"number\_of\_replicas": 1,  
"index.refresh\_interval" : "5s",  
"index.mapping.total\_fields.limit": 1000  
},  
"mappings": {  
"default":{  
"properties": {  
"message": { "type": "text"},  
"received\_at": { "type": "date" },  
"collector\_ip": { "type": "ip" },  
"logstash": { "type": "keyword" },  
"program": { "type": "keyword" },  
"host": { "type": "ip" },  
"logsource": { "type": "ip" },  
}  
},  
"logstash-proxy-_":{  
"properties": {  
"url": { "type": "keyword" }  
# more fields located only in logstash-proxy-\*  
}  
},  
"logstash-mail-_":{  
"properties": {  
"sender-address": { "type": "keyword" }  
# more fields located only in logstash-mail-_  
}  
}  
}  
}

Logstash output config:  
output {  
if [program] == "squid" {  
elasticsearch {  
hosts =\> "127.0.0.1"  
template =\> ["/etc/logstash/template.json"]  
manage\_template =\> true  
template\_overwrite =\> true  
index =\> "logstash-proxy-%{+YYYY.MM.dd}"  
}  
} else if [program] == "postfix" {  
elasticsearch {  
hosts =\> "127.0.0.1"  
template =\> ["/etc/logstash/template.json"]  
manage\_template =\> true  
template\_overwrite =\> true  
index =\> "logstash-mail-%{+YYYY.MM.dd}"  
}  
}  
}

The problem is that multiple mappings in single template are not allowed (Logstash's error: Got response code '400', blabla, block in install\_template\_after\_successful\_connection). What's the correct way to do this?

Thank you for help.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 5, 2019, 11:42pm UTC](https://discuss.elastic.co/t/multiple-templates-in-single-file-in-logstashs-elasticsearch-output-plugin/167155/2 "2019-02-05T23:42:31Z")

</div>

The correct way is to have two separate files, Elasticsearch won't accept what you have there so it'll never work.

---

<div class="post-metadata">

**Author:** ![siginigin](https://avatars.discourse-cdn.com/v4/letter/s/4bbf92/32.png) [@siginigin](https://discuss.elastic.co/u/siginigin)\
**Post date:** [February 11, 2019, 10:41am UTC](https://discuss.elastic.co/t/multiple-templates-in-single-file-in-logstashs-elasticsearch-output-plugin/167155/3 "2019-02-11T10:41:58Z")

</div>

Ok, thanx for reply. I did that using ansible templates. For anyone looking for same solution, here you go:

template-basic.j2  
{  
"template": "logstash-{{ item.index }}-\*",  
"settings": {  
"number\_of\_shards": 3,  
"number\_of\_replicas": 1,  
},  
"mappings": {  
"doc":{  
"properties": {  
"message": { "type": "text"},  
and other basic mappings  
"host": { "type": "keyword"},  
{# here goes fields for specific templates #}  
{{ item.file | indent(32,true) }}  
}  
}  
}  
}

Specific template, for example proxy.txt  
"url": { "type": "keyword" },  
"domain": { "type": "keyword" },  
"http\_protocol": { "type": "keyword" },  
"http\_method": { "type": "keyword" },  
"http\_status\_code": { "type": "integer" },  
"squid\_result\_code": { "type": "keyword" },  
"squid\_hierarchy\_code": { "type": "keyword" },  
"duration": { "type": "integer" },  
"bytes": { "type": "integer" },  
"server": { "type": "ip" }

And now ansible playbook:

- name: elastics  
hosts: all  
vars:  
logstash\_templates:  
- file: "{{ lookup('file', 'proxy.txt' ) }}"  
index: proxy  
- file: "{{ lookup('file', 'asa.txt' ) }}"  
index: asa  
etc...  
tasks:
  - name: Logstash - template for field mapping  
template:  
src: template-basic.j2  
dest: /etc/logstash/templates/{{ item.index }}.json  
mode: 0644  
with\_items:
    - "{{ logstash\_templates }}"  
notify: Restart Logstash  
tags: logstash

In this scenario I have separate templates for various indexes, which I can now use like this in logstash:  
output {  
if [program] == "ASA" {  
elasticsearch {  
hosts =\> "127.0.0.1"  
template =\> ["/etc/logstash/templates/asa.json"]  
template\_name =\> "logstash-asa"  
manage\_template =\> true  
template\_overwrite =\> true  
index =\> "logstash-asa-%{+YYYY.MM.dd}"  
}  
if [program] == "squid" {  
elasticsearch {  
hosts =\> "127.0.0.1"  
template =\> ["/etc/logstash/templates/proxy.json"]  
template\_name =\> "logstash-proxy"  
manage\_template =\> true  
template\_overwrite =\> true  
index =\> "logstash-proxy-%{+YYYY.MM.dd}"  
}  
}  
}

It's worth mention that default template name in logstash output is logstash, so I needed to change it using template\_name, otherwise you'll end up with one template - the last one in your output.

Better solution is welcome 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2019, 10:41am UTC](https://discuss.elastic.co/t/multiple-templates-in-single-file-in-logstashs-elasticsearch-output-plugin/167155/4 "2019-03-11T10:41:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
