# Add new field and updating index by changes in another index

**URL:** <https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492>\
**Category:** Logstash\
**Created:** [June 26, 2018, 6:16pm UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492 "2018-06-26T18:16:00Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![akapit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akapit/32/32490_2.png) [@akapit](https://discuss.elastic.co/u/akapit)\
**Post date:** [June 26, 2018, 6:16pm UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/1 "2018-06-26T18:16:00Z")

</div>

Hi,

I'm importing two csv files into two different indexes in elastic.

One of them is business data and the other are config parameters.

When importing the business data csv in elastic, I need that index to have added a new field dynamically which is a number calculated between some of its data with values that are in the other index (the config params one).

In addition to that, the config params index can change its values from time to time (gets overwriten) and I need the business data index to get updated (retroactively) when the parameters index get updated.

So I thought I could do "re-importing data" from elastic to elastic to be re-processed in logstash frequently, or may I use scripted fields on kibana for that…

but i'm still too new and I wonder what's the best way to approach this neither if that's possible at all.

I'd also like to know your opinion about whether it makes sense to do this on logstash/kibana or it should be done somehow before the data get inserted.

Can the Elasticsearch input plugin help on this situation? like importing through a query that contains data from different indexes and using the result in the output?

I'd appreciate any help

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 26, 2018, 11:23pm UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/2 "2018-06-26T23:23:51Z")

</div>

> [@akapit](#):
>
> One of them is pure data

What sort of data is it?

---

<div class="post-metadata">

**Author:** ![akapit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akapit/32/32490_2.png) [@akapit](https://discuss.elastic.co/u/akapit)\
**Post date:** [June 27, 2018, 7:03am UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/3 "2018-06-27T07:03:48Z")

</div>

It's a csv import, plan text fields and some numeric fields.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 27, 2018, 10:41pm UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/4 "2018-06-27T22:41:39Z")

</div>

I'd define the document `_id` to be a concatenation/hash of a few unique but stable values, and then when you get updated values you can just recreate that hash and it'll update the original document with the changes.

---

<div class="post-metadata">

**Author:** ![akapit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akapit/32/32490_2.png) [@akapit](https://discuss.elastic.co/u/akapit)\
**Post date:** [June 28, 2018, 8:11am UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/5 "2018-06-28T08:11:11Z")

</div>

I didn't actually understood that, could you elaborate that a bit more?  
Or there is anything I can read on that topic?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 28, 2018, 9:59am UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/6 "2018-06-28T09:59:22Z")

</div>

No worries!

The `_id` for a document in Elasticsearch is the unique identifier. You can let Elasticsearch define that automatically or you can create your own.

What I am suggesting is that you take a 1/2/3 unique, but static, parts of each piece of of the business data points and then join/hash them as the `_id`. Then, when you need to update that data because one of the other values changes, you can simply use the same `_id` and it will update the existing document instead of creating a new one.

---

<div class="post-metadata">

**Author:** ![akapit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akapit/32/32490_2.png) [@akapit](https://discuss.elastic.co/u/akapit)\
**Post date:** [July 8, 2018, 9:33am UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/7 "2018-07-08T09:33:21Z")

</div>

I think i got you, you mean to use "id's" in such a way I can later on reference to a "related" document to modify it by "knowing" him through its id, or at least a part of it, right?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 8, 2018, 9:34am UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/8 "2018-07-08T09:34:09Z")

</div>

Yep!

---

<div class="post-metadata">

**Author:** ![akapit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akapit/32/32490_2.png) [@akapit](https://discuss.elastic.co/u/akapit)\
**Post date:** [July 8, 2018, 9:34am UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/9 "2018-07-08T09:34:54Z")

</div>

Sounds cool!  
The question now is how do you "search" that very document? let's say I have one of the fields I used to hash its id.

Btw I thought there were an automated way of doing that, but here the approach is manual, am I right?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 8, 2018, 9:55am UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/10 "2018-07-08T09:55:44Z")

</div>

You can define an `_id` in the Elasticsearch output - [https://www.elastic.co/guide/en/logstash/6.3/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-document\_id](https://www.elastic.co/guide/en/logstash/6.3/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-document_id) - and In that you can then use field references. Which means you can build your `_id` using the values of fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2018, 9:55am UTC](https://discuss.elastic.co/t/add-new-field-and-updating-index-by-changes-in-another-index/137492/11 "2018-08-05T09:55:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
