# Using multiple template inside the logstash'selasticsearch output plugin

**URL:** <https://discuss.elastic.co/t/using-multiple-template-inside-the-logstashselasticsearch-output-plugin/43317>\
**Category:** Logstash\
**Created:** [March 2, 2016, 11:36pm UTC](https://discuss.elastic.co/t/using-multiple-template-inside-the-logstashselasticsearch-output-plugin/43317 "2016-03-02T23:36:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![faitlezen](https://avatars.discourse-cdn.com/v4/letter/f/13edae/32.png) [@faitlezen](https://discuss.elastic.co/u/faitlezen)\
**Post date:** [March 2, 2016, 11:36pm UTC](https://discuss.elastic.co/t/using-multiple-template-inside-the-logstashselasticsearch-output-plugin/43317/1 "2016-03-02T23:36:38Z")

</div>

Hi, I'm trying to use the template option of the ES output plugin but I'm parsing 2 types of logs... traditional logs and another type called aws\_billing\_hourly.  
I tried to put them together in the json template but logstash seem to ignore the 2nd one... what am I doing that's wrong ?  
[elasticsearch-template.json](http://hastebin.com/dagidotati.cpp)  
Is it not the proper way to define multiple template ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 3, 2016, 6:47am UTC](https://discuss.elastic.co/t/using-multiple-template-inside-the-logstashselasticsearch-output-plugin/43317/2 "2016-03-03T06:47:03Z")

</div>

The first and immediate problem is that your template file isn't valid JSON.

You can certainly list mappings for multiple _types_ in the same index template, but you can't have multiple _index patterns_. For that you need separate templates, and you can support that by splitting your elasticsearch output in two or by managing your templates outside of Logstash (and set `manage\_template =\> false" for your elasticsearch outputs).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 3, 2016, 7:14am UTC](https://discuss.elastic.co/t/using-multiple-template-inside-the-logstashselasticsearch-output-plugin/43317/3 "2016-03-03T07:14:35Z")

</div>

> [@magnusbaeck](#):
>
> You can certainly list mappings for multiple types in the same index template

Correct. But we are discouraging this in favour of putting different types in different indices.

---

<div class="post-metadata">

**Author:** ![faitlezen](https://avatars.discourse-cdn.com/v4/letter/f/13edae/32.png) [@faitlezen](https://discuss.elastic.co/u/faitlezen)\
**Post date:** [March 3, 2016, 11:04pm UTC](https://discuss.elastic.co/t/using-multiple-template-inside-the-logstashselasticsearch-output-plugin/43317/4 "2016-03-03T23:04:26Z")

</div>

Ok, I was kind of reluctant putting some logic on the template to use but it seems like the best solution for my problem...

Thanks for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:08am UTC](https://discuss.elastic.co/t/using-multiple-template-inside-the-logstashselasticsearch-output-plugin/43317/5 "2017-07-06T05:08:25Z")

</div>


