# Template not taking effect for ES output

**URL:** <https://discuss.elastic.co/t/template-not-taking-effect-for-es-output/145095>\
**Category:** Logstash\
**Created:** [August 20, 2018, 6:33am UTC](https://discuss.elastic.co/t/template-not-taking-effect-for-es-output/145095 "2018-08-20T06:33:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kaushik.vankayala](https://avatars.discourse-cdn.com/v4/letter/k/aca169/32.png) [@kaushik.vankayala](https://discuss.elastic.co/u/kaushik.vankayala)\
**Post date:** [August 20, 2018, 6:33am UTC](https://discuss.elastic.co/t/template-not-taking-effect-for-es-output/145095/1 "2018-08-20T06:33:05Z")

</div>

Hello,

I am trying to change the type of a field, so i am using a template option in my elastic search output plugin.

My output field is like;

```
output
{
	#stdout { codec => rubydebug }
	if "uat-" in [app]
	{
		elasticsearch
		{
			index => "geo"
			hosts => ["localhost:9200"]
			template => "D:\ELK\server\elk-conf-template.json"
			template_name => "elk-conf-template"
			template_overwrite => true
		}
	}
}

```

and the template is like;

```
{
  "template": "elk-conf-template",
  "settings": {
     "index.refresh_interval": "5s"
  },

  "mappings": {
    "doc": {
      "properties": {
        "geoip": {
          "properties": {
            "location": {
			  "type" : "geo_point"
            }
          }
        },
        "ip": {
          "type": "ip",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        }
      }
    }
  }
}

```

When i try to, **_PUT geo_** the same from Dev Tools in Kibana, it properly maps the location type to geo\_point but if i am trying to do the same via a template, it does not take effect. It maps the location to a text type by default.

Could anybody please help?

Regards

Kaushik

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 20, 2018, 7:08am UTC](https://discuss.elastic.co/t/template-not-taking-effect-for-es-output/145095/2 "2018-08-20T07:08:07Z")

</div>

What determines which index template is applied is the `index_patterns` (ES 6.x and later) or `template` (ES 5.x and earlier) setting in the template. Your `template` setting says "elk-conf-template" so it'll only match newly created indexes with that exact name. See the ES documentation for details.

---

<div class="post-metadata">

**Author:** ![kaushik.vankayala](https://avatars.discourse-cdn.com/v4/letter/k/aca169/32.png) [@kaushik.vankayala](https://discuss.elastic.co/u/kaushik.vankayala)\
**Post date:** [August 24, 2018, 7:11am UTC](https://discuss.elastic.co/t/template-not-taking-effect-for-es-output/145095/3 "2018-08-24T07:11:19Z")

</div>

Hey @magnusbaeck,

I do not quite follow you. By `index_pattern` do you mean its a setting in elasticsearch?

I did go through the documentation, and could not find it.

Are you saying the template name and the index name must match for it to take effect?

Regards

Kaushik Vankayala

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 24, 2018, 7:35am UTC](https://discuss.elastic.co/t/template-not-taking-effect-for-es-output/145095/4 "2018-08-24T07:35:40Z")

</div>

It's a setting in the index template JSON blob that controls whether the template applies to a new index. In 5.x that setting is called `template` and in 6.x it's called `index_patterns`. See the documentation for your version of ES for details.

---

<div class="post-metadata">

**Author:** ![kaushik.vankayala](https://avatars.discourse-cdn.com/v4/letter/k/aca169/32.png) [@kaushik.vankayala](https://discuss.elastic.co/u/kaushik.vankayala)\
**Post date:** [August 30, 2018, 6:44pm UTC](https://discuss.elastic.co/t/template-not-taking-effect-for-es-output/145095/5 "2018-08-30T18:44:23Z")

</div>

Could you please give an example as to how to work with the template setting of the elasticsearch output plugin?

I am unable to infer its use!  
FYI: I am using a enterprise cloud instance for E and K and the L is running on my local machine with version 6.3!

So, my understanding is to set the type of some specific fields rather than the default (_which is string type_) we use template setting in elasticsearch output plugin which will tell elastic to store those fields as indicated in the template file.

As explained above when i PUT the mapping in dev tools of kibana before ingesting the data i can get the fields as expected.

But i would like to do that with the help of logstash conf file only - the data type setting!

Please kindly help or correct me if i am wrong!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2018, 7:24am UTC](https://discuss.elastic.co/t/template-not-taking-effect-for-es-output/145095/6 "2018-08-31T07:24:14Z")

</div>

> Could you please give an example as to how to work with the template setting of the elasticsearch output plugin?

The template option in the elasticsearch output only selects which template file is uploaded to Elasticsearch. Nothing else. It does not influence which template is applied to the index you're writing to.

As I said, the deciding factor of which template or templates apply to a newly created index is the `template'/`index\_patterns` setting in the template itself.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2018, 7:24am UTC](https://discuss.elastic.co/t/template-not-taking-effect-for-es-output/145095/7 "2018-09-28T07:24:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
