# Where can I find the default template?

**URL:** <https://discuss.elastic.co/t/where-can-i-find-the-default-template/78618>\
**Category:** Logstash\
**Created:** [March 14, 2017, 11:27pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-default-template/78618 "2017-03-14T23:27:13Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![camkidman](https://avatars.discourse-cdn.com/v4/letter/c/d6d6ee/32.png) [@camkidman](https://discuss.elastic.co/u/camkidman)\
**Post date:** [March 14, 2017, 11:27pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-default-template/78618/1 "2017-03-14T23:27:13Z")

</div>

Hi there,

I've got the following in my elasticsearch configuration file:

```auto
output {
  elasticsearch { hosts => ["https://...."]
    index => "production-%{+YYYY.MM.dd}"
  }
  stdout { codec => rubydebug }
}

```

I'm running into the field limit of 1000 and I'm not sure how to increase that dynamically from logstash's configuration. It seems like I need to update the default index template, but I can't find logstash's default template _anywhere_, and I'd like to use that with the one modification. Is there a configuration option I can specify in the output right in the logstash config? The docs have very little information about template management: [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#\_template\_management\_for\_elasticsearch\_5\_x](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#_template_management_for_elasticsearch_5_x)

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [March 15, 2017, 12:07am UTC](https://discuss.elastic.co/t/where-can-i-find-the-default-template/78618/2 "2017-03-15T00:07:54Z")

</div>

The code is at [https://github.com/logstash-plugins/logstash-output-elasticsearch/tree/master/lib/logstash/outputs/elasticsearch](https://github.com/logstash-plugins/logstash-output-elasticsearch/tree/master/lib/logstash/outputs/elasticsearch)

On an installed Logstash, the default templates will be in the `vendor` subdirectory where Logstash is installed, in this path:

`vendor/bundle/jruby/#.#/gems/logstash-output-elasticsearch-#.#.#-java/lib/logstash/outputs/elasticsearch`

Logstash really _shouldn't_ be used for template management. We really only include these default templates to provide a better out-of-the-box experience. If you have many indices and figure on needing many templates, Logstash is not the recommended tool for template management. Get used to managing templates using the API.

**UPDATE:** JRuby version numbers differ, so the path was updated to reflect that.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 15, 2017, 3:54am UTC](https://discuss.elastic.co/t/where-can-i-find-the-default-template/78618/3 "2017-03-15T03:54:38Z")

</div>

I've raised [https://github.com/elastic/logstash/issues/6815](https://github.com/elastic/logstash/issues/6815) to see how we can make this easier.

---

<div class="post-metadata">

**Author:** ![camkidman](https://avatars.discourse-cdn.com/v4/letter/c/d6d6ee/32.png) [@camkidman](https://discuss.elastic.co/u/camkidman)\
**Post date:** [March 15, 2017, 3:26pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-default-template/78618/4 "2017-03-15T15:26:24Z")

</div>

Thanks all, I'll dig into it. Question about the template management @theuntergeek -- Right now logstash is creating a date index each day on elasticsearch, are you meaning that should also be managed from elasticsearch?

Everything I found said I should update logstash to configure whatever settings I want when it creates its index, so I'm just wondering if I'm doing it wrong by trying to edit the template on the logstash side.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [March 15, 2017, 3:49pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-default-template/78618/5 "2017-03-15T15:49:26Z")

</div>

@camkidman if you only ever plan to have `logstash-YYYY.MM.DD` indices, then Logstash will be an adequate choice for managing a single template. It really starts to get ridiculous when you have multiple types, and therefore have to manage multiple output blocks, each with their own template, that you begin to realize that Logstash isn't a great tool for that purpose.

I do not recommend editing the template "on the logstash side," in the `vendor` directory. Copy it out somewhere, and set `template =>` to point to that location in your output block.

---

<div class="post-metadata">

**Author:** ![camkidman](https://avatars.discourse-cdn.com/v4/letter/c/d6d6ee/32.png) [@camkidman](https://discuss.elastic.co/u/camkidman)\
**Post date:** [March 15, 2017, 3:51pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-default-template/78618/6 "2017-03-15T15:51:30Z")

</div>

Okay, that's good knowledge all around. Thanks a lot! I did copy the template already and put it in place and it works just fine. Thanks for your time!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2017, 3:51pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-default-template/78618/7 "2017-04-12T15:51:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
