# Aggregate problem

**URL:** <https://discuss.elastic.co/t/aggregate-problem/142572>\
**Category:** Logstash\
**Created:** [August 1, 2018, 12:44pm UTC](https://discuss.elastic.co/t/aggregate-problem/142572 "2018-08-01T12:44:18Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 2, 2018, 6:33pm UTC](https://discuss.elastic.co/t/aggregate-problem/142572/7 "2018-08-02T18:33:06Z")

</div>

OK, the use case where I did this was parsing SiteMinder trace logs, where every line has a correlation id and one piece of information about the request. I needed to gather all the information about one request into a single document. I did this by doing a bulk update using doc\_as\_upsert. One update for each input line.

So, provided that you can use the 'ID appelSVI' as the document id, what you could do is something like

```
output {
    if [Type] == "SVI" {
        file { path => "/some/path/out.txt" codec => plain { format => '{ "update" : {"_id" : "%{ID appelSVI}", "_type" : "doc", "_index" : "someindex"} }
{ "doc": "Passage par SVI": true, "doc_as_upsert" : true }
' } }
    }
}

```

Then

```
curl -X POST 'localhost:9200/someindex/doc/_bulk' -H "Content-Type:application/json" --data-binary @/some/path/out.txt
```

---

_[View the full topic](https://discuss.elastic.co/t/aggregate-problem/142572)._
