# Templates for Elastic Search

**URL:** <https://discuss.elastic.co/t/templates-for-elastic-search/46781>\
**Category:** Logstash\
**Created:** [April 8, 2016, 8:51am UTC](https://discuss.elastic.co/t/templates-for-elastic-search/46781 "2016-04-08T08:51:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![PCO](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@PCO](https://discuss.elastic.co/u/PCO)\
**Post date:** [April 8, 2016, 8:51am UTC](https://discuss.elastic.co/t/templates-for-elastic-search/46781/1 "2016-04-08T08:51:44Z")

</div>

I have a full configuration running (logstash/elastic search/kibana)

As I would like to set dynamic fields as not\_analyzed, I created a template on logstash side (with a name matching the index name used in elastic search output section of logstash)

As for now, the fields are still analyzed.

I am a little bit puzzled by the template management, do I need to upload it also on the elastic search side ?

```
{
  "template" : ""elk-xyz-logs-*",
  "settings" : {
    "index.refresh_interval" : "5s"
  },
  "mappings" : {
    "_default_" : {
      "_all" : {"enabled" : true, "omit_norms" : true},
      "dynamic_templates" : [ {
        "message_field" : {
          "match" : "message",
          "match_mapping_type" : "string",
          "mapping" : {
            "type" : "string", "index" : "analyzed", "omit_norms" : true,
            "fielddata" : { "format" : "disabled" }
          }
        }
      }, {
        "string_fields" : {
          "match" : "*",
          "match_mapping_type" : "string",
          "mapping" : {
            "type" : "string", "index" : "not_analyzed", "omit_norms" : true
          }
        }
      }, {

```

* * *

```
output {
 file {
  path => "/var/log/logstash/output.log"
 }
 elasticsearch {
  index => "elk-xyz-logs-%{+YYYY.MM.dd}"
  template => "/etc/logstash/templates/elk-xyz-logstash.json"
  template_overwrite => true
  manage_template => false
 }
}

```

* * *

Side note:  
My first attempt was to create my template file in conf.d directory =\> that is a bad idea as it looks like all the files in this directory are merged when logstash starts...

---

<div class="post-metadata">

**Author:** ![Alex\_6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_6/32/1330_2.png) [@Alex\_6](https://discuss.elastic.co/u/Alex_6)\
**Post date:** [April 8, 2016, 9:47am UTC](https://discuss.elastic.co/t/templates-for-elastic-search/46781/2 "2016-04-08T09:47:52Z")

</div>

Templates are nothing to do with Logstash, they are only for the Elasticsearch side. [More info here](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html).

[Kopf](https://github.com/lmenezes/elasticsearch-kopf) (an Elasticsearch admin tool plugin) has a nice Index Template editor.

---

<div class="post-metadata">

**Author:** ![PCO](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@PCO](https://discuss.elastic.co/u/PCO)\
**Post date:** [April 8, 2016, 10:11am UTC](https://discuss.elastic.co/t/templates-for-elastic-search/46781/3 "2016-04-08T10:11:48Z")

</div>

I understand that the templates are only useful on the ES side but using the elastic search plugin output, they are kind of managed by logstash (or at least the plugin as it looks like you can define a template file and it will be uploaded automatically to ES )

---

<div class="post-metadata">

**Author:** ![Alex\_6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_6/32/1330_2.png) [@Alex\_6](https://discuss.elastic.co/u/Alex_6)\
**Post date:** [April 8, 2016, 10:21am UTC](https://discuss.elastic.co/t/templates-for-elastic-search/46781/4 "2016-04-08T10:21:07Z")

</div>

Ah sorry, misread your message. I've never used that feature myself. Have you verified that [Elasticsearch has your template stored](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html#getting)?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 8, 2016, 11:04am UTC](https://discuss.elastic.co/t/templates-for-elastic-search/46781/5 "2016-04-08T11:04:30Z")

</div>

You're disabling `manage_template` so Logstash won't upload the template you're pointing it at. Either enable `manage_template` again or take over the template ownership by uploading the template yourself outside of Logstash.

---

<div class="post-metadata">

**Author:** ![PCO](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@PCO](https://discuss.elastic.co/u/PCO)\
**Post date:** [April 8, 2016, 12:04pm UTC](https://discuss.elastic.co/t/templates-for-elastic-search/46781/6 "2016-04-08T12:04:35Z")

</div>

Thanks to your information, I modified the configuration file.

My first try was still failing but enabling verbose output in logstash pointed me to the right direction, during startup a parsing error was raised during the import of my template file. I fixed the typo and made some other tests and curiously sometimes it was working sometimes not.  
I was using a host array in my logstash elasticsearch output config and 2 my nodes are currently turned off, so some of the requests were failing (I initially thought the array was there for fail-over but I RTFM and it's more for load-balancing ^^), listing only up&running hosts was the good configuration, the template is correctly uploaded (and listed using the curl -XGET http://:/\_template command)

So , thanks a lot for your quick feedback.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:03am UTC](https://discuss.elastic.co/t/templates-for-elastic-search/46781/7 "2017-07-06T05:03:07Z")

</div>


