# Graylog and OpenSearch Index Templates

**URL:** <https://community.graylog.org/t/graylog-and-opensearch-index-templates/36879>\
**Category:** Documentation Campfire\
**Created:** [January 21, 2026, 10:22pm UTC](https://community.graylog.org/t/graylog-and-opensearch-index-templates/36879 "2026-01-21T22:22:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![edp](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@edp](https://community.graylog.org/u/edp)\
**Post date:** [January 21, 2026, 10:22pm UTC](https://community.graylog.org/t/graylog-and-opensearch-index-templates/36879/1 "2026-01-21T22:22:14Z")

</div>

Does Graylog use OpenSearch Index Templates? I’m not seeing any.

I need to set up an OpenSearch index template pattern to apply a setting to all new indices that are created in one of our index sets… can I do this without affecting the normal settings that Graylog specifies when the index set is rotated and it creates the next index for writing? I’m not sure exactly how Graylog creates new indices.

What happens with I create a field type mapping or apply a field type profile - does Graylog put these in an OpenSearch index template, or just incorporate the field type settings when it creates each new index directly?

Thanks,

– Ed

---

<div class="post-metadata">

**Author:** ![edp](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@edp](https://community.graylog.org/u/edp)\
**Post date:** [January 22, 2026, 10:24pm UTC](https://community.graylog.org/t/graylog-and-opensearch-index-templates/36879/2 "2026-01-22T22:24:45Z")

</div>

I found what looks to be the OpenSearch legacy templates maintained by Graylog for our index sets in [http://localhost:9200/\_template](http://localhost:9200/_template). There is one for each index set named “index\_set\_prefix-template”.

Can we alter these and not have Graylog overwrite them and remove the extra settings I put in?

Thanks,

– Ed

---

<div class="post-metadata">

**Author:** ![frantz](https://avatars.discourse-cdn.com/v4/letter/f/dbc845/32.png) [@frantz](https://community.graylog.org/u/frantz)\
**Post date:** [January 27, 2026, 10:26am UTC](https://community.graylog.org/t/graylog-and-opensearch-index-templates/36879/3 "2026-01-27T10:26:58Z")

</div>

As far as I know Graylog overwrite its templates if you modify them.

If you need to add some settings or field mappings to your indices, you should create a template with a different name than the Graylog ones.

Multiple templates can apply to a same index. There are priorities.

---

<div class="post-metadata">

**Author:** ![Alex2](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@Alex2](https://community.graylog.org/u/Alex2)\
**Post date:** [January 29, 2026, 5:23pm UTC](https://community.graylog.org/t/graylog-and-opensearch-index-templates/36879/4 "2026-01-29T17:23:39Z")

</div>

5.2 docs cover this here [Elasticsearch](https://go2docs.graylog.org/5-2/setting_up_graylog/elasticsearch.htm?Highlight=index%20mappings#CustomIndexMappings) (Custom Index Mappings section toward the bottom). I’ve done this in the past and it works as intended. You don’t overwrite the existing default template but add a new one with a different name, using the `index_patterns` param to apply to the graylog indices.

You install templates using the opensearch/elasticsearch REST api, the docs have an example but you can find more info in the opensearch/elasticsearch docs.

Side note: these days they use the term [Index Set Templates](https://go2docs.graylog.org/6-3/setting_up_graylog/index_set_templates.htm) for a completely different feature, data tiering configuration. I was initially confused by that!
