# Where is the template that elasticsearch uses for syslog indexes? I am using logstash for ingestion

**URL:** <https://discuss.elastic.co/t/where-is-the-template-that-elasticsearch-uses-for-syslog-indexes-i-am-using-logstash-for-ingestion/138248>\
**Category:** Elasticsearch\
**Created:** [July 2, 2018, 6:00pm UTC](https://discuss.elastic.co/t/where-is-the-template-that-elasticsearch-uses-for-syslog-indexes-i-am-using-logstash-for-ingestion/138248 "2018-07-02T18:00:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikjsmith](https://avatars.discourse-cdn.com/v4/letter/e/48db29/32.png) [@erikjsmith](https://discuss.elastic.co/u/erikjsmith)\
**Post date:** [July 2, 2018, 6:00pm UTC](https://discuss.elastic.co/t/where-is-the-template-that-elasticsearch-uses-for-syslog-indexes-i-am-using-logstash-for-ingestion/138248/1 "2018-07-02T18:00:47Z")

</div>

I am getting the following error:  
[2018-07-02T13:53:58,975][DEBUG][o.e.a.b.TransportShardBulkAction] [syslog-2018.07.02][3] failed to execute bulk item (index) BulkShardRequest [[syslog-2018.07.02][3]] containing [7] requests  
org.elasticsearch.index.mapper.MapperParsingException: object mapping for [host] tried to parse field [host] as object, but found a concrete value

When I do a GET /syslog-2018.07.02/\_mapping, I get for "host":  
},  
"host": {  
"properties": {  
"name": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}  
}  
},

Any idea what if this is the mapping I should be looking at and what I should be changing?

---

<div class="post-metadata">

**Author:** ![erikjsmith](https://avatars.discourse-cdn.com/v4/letter/e/48db29/32.png) [@erikjsmith](https://discuss.elastic.co/u/erikjsmith)\
**Post date:** [July 2, 2018, 7:35pm UTC](https://discuss.elastic.co/t/where-is-the-template-that-elasticsearch-uses-for-syslog-indexes-i-am-using-logstash-for-ingestion/138248/2 "2018-07-02T19:35:03Z")

</div>

As I am no longer able to delete index mapping, I deleted the index, but the issue is continuing. I also see the following error:  
Caused by: java.lang.IllegalStateException: Can't get text on a START\_OBJECT at 1:71

---

<div class="post-metadata">

**Author:** ![erikjsmith](https://avatars.discourse-cdn.com/v4/letter/e/48db29/32.png) [@erikjsmith](https://discuss.elastic.co/u/erikjsmith)\
**Post date:** [July 3, 2018, 4:23pm UTC](https://discuss.elastic.co/t/where-is-the-template-that-elasticsearch-uses-for-syslog-indexes-i-am-using-logstash-for-ingestion/138248/3 "2018-07-03T16:23:43Z")

</div>

I uninstalled and reinstalled the logstash plugin for syslog and the concrete error went away, however I'm still getting the "failed to parse [host]" error. When I do a search for today's syslog index mappings I can see where the host field is mapped, however I am unable to find the template that is being used to create the index mapping. Does anyone know where that template is? I'm unable to map it to anything that I find when I do a "GET /\_template".

---

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [July 12, 2018, 8:22am UTC](https://discuss.elastic.co/t/where-is-the-template-that-elasticsearch-uses-for-syslog-indexes-i-am-using-logstash-for-ingestion/138248/4 "2018-07-12T08:22:43Z")

</div>

I have the exact same problem, did you manage to solve it?

---

<div class="post-metadata">

**Author:** ![erikjsmith](https://avatars.discourse-cdn.com/v4/letter/e/48db29/32.png) [@erikjsmith](https://discuss.elastic.co/u/erikjsmith)\
**Post date:** [July 12, 2018, 1:44pm UTC](https://discuss.elastic.co/t/where-is-the-template-that-elasticsearch-uses-for-syslog-indexes-i-am-using-logstash-for-ingestion/138248/5 "2018-07-12T13:44:39Z")

</div>

I uninstalled and reinstall the syslog plugin for logstash and that resolved some of my issues, but I was never able to determine how to edit that template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2018, 1:44pm UTC](https://discuss.elastic.co/t/where-is-the-template-that-elasticsearch-uses-for-syslog-indexes-i-am-using-logstash-for-ingestion/138248/6 "2018-08-09T13:44:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
