# Question regarding template\_overwrite in logstash output to elasticsearch

**URL:** <https://discuss.elastic.co/t/question-regarding-template-overwrite-in-logstash-output-to-elasticsearch/50908>\
**Category:** Logstash\
**Created:** [May 25, 2016, 6:14am UTC](https://discuss.elastic.co/t/question-regarding-template-overwrite-in-logstash-output-to-elasticsearch/50908 "2016-05-25T06:14:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![macymin](https://avatars.discourse-cdn.com/v4/letter/m/8e7dd6/32.png) [@macymin](https://discuss.elastic.co/u/macymin)\
**Post date:** [May 25, 2016, 6:14am UTC](https://discuss.elastic.co/t/question-regarding-template-overwrite-in-logstash-output-to-elasticsearch/50908/1 "2016-05-25T06:14:38Z")

</div>

I want to do the on the fly template overwrite for 1 of my index data (basically is to decrease the shards count). so i need to add below session:  
my questions is do I need to add this to all the logstash indexer's conf which output to same index or only need to add into one? my thought is add into one should be enough because once the template is overwritten (by either of the indexer), the rest of indexer will use the new template already. Please correct me if I am wrong.

output {  
elasticsearch {  
hosts =\> ["fslelkprod01","fslelkprod02","fslelkprod03"]  
index =\> "amhstrending-%{+YYYY.MM.dd}"  
**template =\> "/etc/logstash/template/amhstrending\_template.json"**  
**template\_overwrite =\> true**  
}  
}

---

<div class="post-metadata">

**Author:** ![macymin](https://avatars.discourse-cdn.com/v4/letter/m/8e7dd6/32.png) [@macymin](https://discuss.elastic.co/u/macymin)\
**Post date:** [May 25, 2016, 6:16am UTC](https://discuss.elastic.co/t/question-regarding-template-overwrite-in-logstash-output-to-elasticsearch/50908/2 "2016-05-25T06:16:15Z")

</div>

my template file is very simple actually:

{  
"template" : "amhstrending-\*",  
"settings" : {  
"number\_of\_shards" : "1",  
"number\_of\_replicas" : "0"  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2016, 9:19am UTC](https://discuss.elastic.co/t/question-regarding-template-overwrite-in-logstash-output-to-elasticsearch/50908/3 "2016-05-25T09:19:05Z")

</div>

Putting in one should be ok, has the template been uploaded to ES?

---

<div class="post-metadata">

**Author:** ![macymin](https://avatars.discourse-cdn.com/v4/letter/m/8e7dd6/32.png) [@macymin](https://discuss.elastic.co/u/macymin)\
**Post date:** [May 26, 2016, 1:51am UTC](https://discuss.elastic.co/t/question-regarding-template-overwrite-in-logstash-output-to-elasticsearch/50908/4 "2016-05-26T01:51:52Z")

</div>

yes I can see the template uploaded successfully.

---

<div class="post-metadata">

**Author:** ![macymin](https://avatars.discourse-cdn.com/v4/letter/m/8e7dd6/32.png) [@macymin](https://discuss.elastic.co/u/macymin)\
**Post date:** [May 30, 2016, 7:59am UTC](https://discuss.elastic.co/t/question-regarding-template-overwrite-in-logstash-output-to-elasticsearch/50908/5 "2016-05-30T07:59:10Z")

</div>

hi Mark,  
I see something interesting, the template change only last for 1 day. next day the data will still process by the original shark no. and \_template changed in previous day gone also.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:55am UTC](https://discuss.elastic.co/t/question-regarding-template-overwrite-in-logstash-output-to-elasticsearch/50908/6 "2017-07-06T04:55:33Z")

</div>


