# /\_template OR /\_index\_template?

**URL:** <https://discuss.elastic.co/t/template-or-index-template/266567>\
**Category:** Logstash\
**Tags:** docker, ilm-index-lifecycle-management\
**Created:** [March 8, 2021, 2:11pm UTC](https://discuss.elastic.co/t/template-or-index-template/266567 "2021-03-08T14:11:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![thesn](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@thesn](https://discuss.elastic.co/u/thesn)\
**Post date:** [March 8, 2021, 2:11pm UTC](https://discuss.elastic.co/t/template-or-index-template/266567/1 "2021-03-08T14:11:31Z")

</div>

Hi,

I am using ES 7.11.1 and Logstash 7.11.1 in Docker container.  
here is my logstash.conf:

```auto
    input {
  file {
    codec => "json"
    path => "/usr/share/logstash/config/sample.log"
  }
}

filter {
}

output {
  elasticsearch {
    hosts => ["http://10.6.226.80:9200"]
    index => "bjb-test-%{+YYYY.MM.dd}"
    manage_template => true
    template => "/usr/share/logstash/config/logstash-test-template.json"
    template_name => "bjb-test"
  }
}

```

here is the logstash-test-template.json:

```auto
    {
  "template": {
    "settings": {
      "number_of_shards": "1",
      "number_of_replicas": "0",
      "refresh_interval": "10s",
      "codec": "best_compression",
      "lifecycle": {
        "name": "bjb-test"
      },
      "mapping": {
        "total_fields": {
          "limit": "50"
        }
      }
    },
    "mappings": {
      "dynamic": true,
      "numeric_detection": false,
      "date_detection": true,
      "dynamic_date_formats": [
        "strict_date_optional_time",
        "yyyy/MM/dd HH:mm:ss Z||yyyy/MM/dd Z"
      ],
      "_source": {
        "enabled": true,
        "includes": [],
        "excludes": []
      },
      "_routing": {
        "required": false
      },
      "dynamic_templates": []
    }
  },
  "index_patterns": [
    "bjb-test-*"
  ],
  "data_stream": {}
}

```

when I run docker-compose up -d logstash-test, i received the following error:

```auto
    [2021-03-08T20:45:59,983][ERROR][logstash.outputs.elasticsearch][main] Failed to install template. {:message=>"Got response code '400' contacting Elasticsearch at URL 'http://10.6.226.80:9200/_template/bjb-test'", :class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError", :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client/manticore_adapter.rb:80:in `perform_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:332:in `perform_request_to_url'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:319:in `block in perform_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:414:in `with_connection'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:318:in `perform_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:326:in `block in Pool'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client.rb:352:in `template_put'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/http_client.rb:86:in `template_install'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/template_manager.rb:28:in `install'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/template_manager.rb:16:in `install_template'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/common.rb:205:in `install_template'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.5.1-java/lib/logstash/outputs/elasticsearch/common.rb:49:in `block in setup_after_successful_connection'"]}

```

From the error message above, the URL is **/\_template/**

While if I try to create index template using Kibana 7.11.1 Create Template wizard, the URL is **PUT \_index\_template/bjb-test** , and successful.

Why Logstash is calling /\_template/... instead of \_index\_template?  
Is this the main source of error?

Please enlighten me.  
Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 8, 2021, 5:06pm UTC](https://discuss.elastic.co/t/template-or-index-template/266567/2 "2021-03-08T17:06:07Z")

</div>

> [@thesn](#):
>
> Why Logstash is calling /\_template/... instead of \_index\_template?

The code is using the [legacy](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates-v1.html) template feature rather than [composable](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html) templates. It [decides](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/9401759a165f51e4b10dd195b1394760dc70dd92/lib/logstash/outputs/elasticsearch/http_client.rb#L357) which to use based on the elasticsearch version.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [March 8, 2021, 6:57pm UTC](https://discuss.elastic.co/t/template-or-index-template/266567/3 "2021-03-08T18:57:12Z")

</div>

> [@thesn](#):
>
> `template => "/usr/share/logstash/config/logstash-test-template.json"`

can you do it without this one?

because if you put the template with  
"index\_patterns": ["bjp-test-\*"] then when you write to that index it will automatically uses that template.

---

<div class="post-metadata">

**Author:** ![thesn](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@thesn](https://discuss.elastic.co/u/thesn)\
**Post date:** [March 9, 2021, 6:19am UTC](https://discuss.elastic.co/t/template-or-index-template/266567/4 "2021-03-09T06:19:52Z")

</div>

Hi @Badger ,

Thanks for your response.  
Ok, so we should be using the new index template instead of the legacy one (since it is deprecated).

I still want to define it via **logstash-test-template.json** file which is referred by the output section in my **logstash-test.conf** , instead of defining it manually via Kibana.

Any reference on how to achieve that? and would be great if there is a valid template.json I can refer to.

Thank you.

---

<div class="post-metadata">

**Author:** ![thesn](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@thesn](https://discuss.elastic.co/u/thesn)\
**Post date:** [March 10, 2021, 4:20am UTC](https://discuss.elastic.co/t/template-or-index-template/266567/5 "2021-03-10T04:20:09Z")

</div>

Hi @elasticforme ,

I do want to define the index-template in a file (instead of defining it manually in Kibana.  
That way, I can keep all the configuration in a git repo.  
I used ES / Logstash 7.8 with the mentioned index-template, and it was running.

But when I try to setup the same config in ES / Logstash 7.11.1, it failed.  
I wonder if there is any reference I can look into.

Thank you,

Satria

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2021, 4:20am UTC](https://discuss.elastic.co/t/template-or-index-template/266567/6 "2021-04-07T04:20:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
