# Specifying with Elasticsearch template and file to use

**URL:** <https://discuss.elastic.co/t/specifying-with-elasticsearch-template-and-file-to-use/33362>\
**Category:** Logstash\
**Created:** [October 30, 2015, 11:44am UTC](https://discuss.elastic.co/t/specifying-with-elasticsearch-template-and-file-to-use/33362 "2015-10-30T11:44:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelv1n](https://avatars.discourse-cdn.com/v4/letter/k/59ef9b/32.png) [@kelv1n](https://discuss.elastic.co/u/kelv1n)\
**Post date:** [October 30, 2015, 11:44am UTC](https://discuss.elastic.co/t/specifying-with-elasticsearch-template-and-file-to-use/33362/1 "2015-10-30T11:44:32Z")

</div>

Hi Guys

This is probably a newbie config mistake.

When specifying a custom Elasticsearch template for an output, it appears the index and template\_name need to be the same.. so if I had a generic template that I want to use across several indices, it doesn't work.

So for example if I have the following config

```
output {
    if [parser] == "fortimail" {
        elasticsearch {
            hosts => localhost
            index => ["fortimail-%{+YYYY.MM.DD}"]
            template => "/etc/logstash/templates/fortimail.json"
            template_name => "fortimail-*"
       }
      }
}

```

Then my fortimail.json looks like this, notice the template name is fortmail-\* -

```
{
  "template" : "fortimail-*",
  "settings" : {
    "index.refresh_interval" : "5s"
  },
  "mappings" : {
    "_default_" : {
       "_all" : {"enabled" : true, "omit_norms" : true},
       "dynamic_templates" : [ {
         "message_field" : {
           "match" : "message",
           "match_mapping_type" : "string",
           "mapping" : {
             "type" : "string", "index" : "analyzed", "omit_norms" : true
           }
         }
       }, {
         "string_fields" : {
           "match" : "*",
           "match_mapping_type" : "string",
           "mapping" : {
             "type" : "string", "index" : "analyzed", "omit_norms" : true,
               "fields" : {
                 "raw" : {"type": "string", "index" : "not_analyzed", "ignore_above" : 256}
               }
           }
         }
       } ],
       "properties" : {
         "@version": { "type": "string", "index": "not_analyzed" },
         "geoip" : {
           "type" : "object",
             "dynamic": true,
             "properties" : {
               "location" : { "type" : "geo_point" }
             }
         },
         "src_geoip" : {
           "type" : "object",
             "dynamic": true,
             "properties" : {
               "location" : { "type" : "geo_point" }
             }
         },
         "dst_geoip" : {
           "type" : "object",
             "dynamic": true,
             "properties" : {
               "location" : { "type" : "geo_point" }
             }
         }
       }
    }
  }
}

```

This works fine, but if I create a new index by changing the output to

```
index => ["MyNewIndex-%{+YYYY.MM.DD}"]

```

Then Elasticsearch reverts to using the default Logstash elasticsearch template.. And the only way to get it to work, is to clone the FortiMail.json file and change the the template value to "MyNewIndex-\*".

Am I doing something wrong? Or is this how its meant to work?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 30, 2015, 6:17pm UTC](https://discuss.elastic.co/t/specifying-with-elasticsearch-template-and-file-to-use/33362/2 "2015-10-30T18:17:55Z")

</div>

Yes, this is how it's supposed to work.

The template pattern ("fortimail-\*" in your case) must match the index name. Setting `template` for an elasticsearch output won't necessarily cause ES to use _that_ template. It'll only cause Logstash to push the template to ES, giving it the name in `template_name` (which is the _name_ of the template, not the index name pattern it should apply to). If the name of the index Logstash posts data to happens to match your template then it'll be applied. Otherwise not.

---

<div class="post-metadata">

**Author:** ![kelv1n](https://avatars.discourse-cdn.com/v4/letter/k/59ef9b/32.png) [@kelv1n](https://discuss.elastic.co/u/kelv1n)\
**Post date:** [October 31, 2015, 11:57pm UTC](https://discuss.elastic.co/t/specifying-with-elasticsearch-template-and-file-to-use/33362/3 "2015-10-31T23:57:08Z")

</div>

Thanks Magnus 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:24am UTC](https://discuss.elastic.co/t/specifying-with-elasticsearch-template-and-file-to-use/33362/4 "2017-07-06T05:24:40Z")

</div>


