# Accessing \_version metadata field from elasticsearch using logstash

**URL:** <https://discuss.elastic.co/t/accessing-version-metadata-field-from-elasticsearch-using-logstash/151307>\
**Category:** Elasticsearch\
**Created:** [October 6, 2018, 9:18am UTC](https://discuss.elastic.co/t/accessing-version-metadata-field-from-elasticsearch-using-logstash/151307 "2018-10-06T09:18:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lana](https://avatars.discourse-cdn.com/v4/letter/l/d2c977/32.png) [@lana](https://discuss.elastic.co/u/lana)\
**Post date:** [October 6, 2018, 9:18am UTC](https://discuss.elastic.co/t/accessing-version-metadata-field-from-elasticsearch-using-logstash/151307/1 "2018-10-06T09:18:14Z")

</div>

Hi,  
I'm using the ELK- Stack to import CSV files. Each time the CSV files are imported the "\_version" field of a document increases, which is as expected. However, because the \_version field is a metadata field, is not indexed by Elasticsearch. Therefore the field is not searchable and cannot be used in the Dashboard.

I've created a second logstash configuration where both the input as well as the output are Elasticsearch.

Filter configuration:

```auto
filter {
mutate {
   add_field => {"Version" => "{[@metadata][_version]}"}
 }
}

```

Input configuration:

```auto
input {
elasticsearch {
  hosts => ["localhost:9200"]
  index => "test_csv"
  query => '{"query":{"match_all" : {}}}'
  size => 1000
  scroll => "1s"
  docinfo => true
  docinfo_fields => ["_index", "_type", "_id", "_version"]
  schedule => "/1 * * * *" 
}
}

```

I cannot get the value from the \_version field. The Output in Kibana looks like:

```auto
Version {[@metadata][_version]}

```

If I replace the \_version field in the filter with \_id or \_index I get information back.

Any ideas on how to get value out of the \_version field? Any thoughts on the matter are highly appreciated.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 6, 2018, 9:45am UTC](https://discuss.elastic.co/t/accessing-version-metadata-field-from-elasticsearch-using-logstash/151307/2 "2018-10-06T09:45:44Z")

</div>

> [@lana](#):
>
> mutate { add\_field =\> {"Version" =\> "{[@metadata][\_version]}"} }

I have not tested it, but believe this is supposed to be:

```auto
mutate {
  add_field => {"Version" => "%{[@metadata][_version]}"}
}

```

---

<div class="post-metadata">

**Author:** ![lana](https://avatars.discourse-cdn.com/v4/letter/l/d2c977/32.png) [@lana](https://discuss.elastic.co/u/lana)\
**Post date:** [October 6, 2018, 10:09am UTC](https://discuss.elastic.co/t/accessing-version-metadata-field-from-elasticsearch-using-logstash/151307/3 "2018-10-06T10:09:44Z")

</div>

Hi Christian,

If I change the Logstash configuration as you mentioned, the output in Kibana looks like:

```
Version_Scrapy %{[@metadata][_version]}

```

Actually I am not sure if it is possible to access the data from this field. Because it depends on the view if I can see the"\_version" field in JSON or not.

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e1dccd6ae8d9fca7bda8184337890c871458faac.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dcf8c7d993d52dc630c1c042537e54c17ad68b66.png)

Regards,

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 6, 2018, 10:11am UTC](https://discuss.elastic.co/t/accessing-version-metadata-field-from-elasticsearch-using-logstash/151307/4 "2018-10-06T10:11:02Z")

</div>

If you need a version, I would recommend you add a field to represent this rather than rely on the internal one that you can not control.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2018, 10:11am UTC](https://discuss.elastic.co/t/accessing-version-metadata-field-from-elasticsearch-using-logstash/151307/5 "2018-11-03T10:11:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
