# An elasticsearch index as logstash input

**URL:** <https://discuss.elastic.co/t/an-elasticsearch-index-as-logstash-input/170833>\
**Category:** Logstash\
**Created:** [March 5, 2019, 7:36am UTC](https://discuss.elastic.co/t/an-elasticsearch-index-as-logstash-input/170833 "2019-03-05T07:36:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [March 5, 2019, 7:36am UTC](https://discuss.elastic.co/t/an-elasticsearch-index-as-logstash-input/170833/1 "2019-03-05T07:36:25Z")

</div>

Hi all,  
I am using following configuration in logstash:

```
input {
jdbc {
    jdbc_driver_library => "F:\driver\sqljdbc_6.0\enu\jre8\sqljdbc42.jar"
    jdbc_driver_class => "com.microsoft.sqlserver.jdbc.SQLServerDriver"
    jdbc_connection_string => "jdbc:sqlserver://local:3333;databaseName=Total"
    jdbc_user => "***"
    jdbc_password => "***"
	schedule => "0 10-23/1 * * *"
    statement => "
	DECLARE @DDate1 CHAR(10)
   select @DDate1=REPLACE(MAX(Date),'/','') from Total.dbo.Total_Control
   select [BaseDate_Accept_Setel]
      ,[Financial_Date]
      from dbo.vw_Total where (BaseDate_Accept_Setel=@DDate1) AND (BaseDate_Accept_Setel> :sql_last_value) 
	"
use_column_value => "true"
tracking_column => "basedate_accept_setel"
}

}
filter {

jdbc_streaming {
 jdbc_driver_library => "F:\driver\sqljdbc_6.0\enu\jre8\sqljdbc42.jar"
    jdbc_driver_class => "com.microsoft.sqlserver.jdbc.SQLServerDriver"
    jdbc_connection_string => "jdbc:sqlserver://local:3333;databaseName=Total"
    jdbc_user => "***"
    jdbc_password => "***"
    parameters => {"mine" => "BaseDate_Accept_Setel"}
    statement => "
	DECLARE @ddate2 CHAR(10)
	set @ddate2=:mine
SELECT Total_OnLine.dbo.d2md(@ddate2) as gdate"
target => "gdate"
}
mutate { replace => { "gdate" => "%{[gdate][0][gdate]}" } }
    mutate { gsub => ["gdate", "/", "-"] }

}

output {
  elasticsearch { 
    hosts => ["http://192.168.170.153:9200"]
    index => "a2_%{gdate}"
    user => "logstash_internal25"
    password => "x-pack-test-password"
 }
  stdout { codec => rubydebug }
}

```

now, I want to load an index as "disp\_%{gdate}" , how can i add this? i found that we can load elasticsearch indices in input part as following:

```
input {
  elasticsearch {
    hosts => "http://192.168.170.153:9200"
    index => "disp-*"
}
}

```

but I want to load the index of date %{gdate}, how can i do it? the problem is that "gdate" is defined in filter part and i want to use it in input part, is it possible? many thanks.

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [March 6, 2019, 10:15am UTC](https://discuss.elastic.co/t/an-elasticsearch-index-as-logstash-input/170833/2 "2019-03-06T10:15:58Z")

</div>

> [@sahere37](#):
>
> jdbc\_driver\_library =\> "F:\driver\sqljdbc\_6.0\enu\jre8\sqljdbc42.jar"

Hello, in windows, you need to give path as shown below,

> jdbc\_driver\_library =\> "F:/driver/sqljdbc\_6.0/enu/jre8/sqljdbc42.jar"

---

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [March 6, 2019, 10:17am UTC](https://discuss.elastic.co/t/an-elasticsearch-index-as-logstash-input/170833/3 "2019-03-06T10:17:40Z")

</div>

sorry, its my mistake , the path in config file is correct just the paste one is wrong

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2019, 10:26am UTC](https://discuss.elastic.co/t/an-elasticsearch-index-as-logstash-input/170833/4 "2019-04-03T10:26:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
