# Best practice for updating fields for a log message

**URL:** <https://discuss.elastic.co/t/best-practice-for-updating-fields-for-a-log-message/53369>\
**Category:** Elasticsearch\
**Created:** [June 20, 2016, 8:52pm UTC](https://discuss.elastic.co/t/best-practice-for-updating-fields-for-a-log-message/53369 "2016-06-20T20:52:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![abordia](https://avatars.discourse-cdn.com/v4/letter/a/9fc29f/32.png) [@abordia](https://discuss.elastic.co/u/abordia)\
**Post date:** [June 20, 2016, 8:52pm UTC](https://discuss.elastic.co/t/best-practice-for-updating-fields-for-a-log-message/53369/1 "2016-06-20T20:52:14Z")

</div>

I have a scenario where i need user to update field for a log entry which is stored in elastic search. Field size and data type is well defined. What are best practice around this? Does ES re-index that message? Can we query the new field? Can i stop re-indexing of the message after update to avoid cpu issue? Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 9, 2016, 4:01pm UTC](https://discuss.elastic.co/t/best-practice-for-updating-fields-for-a-log-message/53369/2 "2016-07-09T16:01:19Z")

</div>

> Does ES re-index that message?

Yes.

> Can we query the new field?

Yes.

> Can i stop re-indexing of the message after update to avoid cpu issue?

What issue would that be?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:36pm UTC](https://discuss.elastic.co/t/best-practice-for-updating-fields-for-a-log-message/53369/3 "2017-07-05T22:36:49Z")

</div>


