# Consolidating/aggregating ES documents on one ELK stack

**URL:** <https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428>\
**Category:** Elasticsearch\
**Created:** [December 2, 2020, 11:15pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428 "2020-12-02T23:15:24Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Asher](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Asher](https://discuss.elastic.co/u/Asher)\
**Post date:** [December 2, 2020, 11:15pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/1 "2020-12-02T23:15:24Z")

</div>

Hi all,

I'm trying to solve the following problem: I have data in RDSs (Aurora MySQL), a subset of which I'm going to map to Elasticsearch using the AWS Database Migration Service. Unfortunately, we have full deployments in 4 AWS regions, but need to consolidate the output onto one Elasticsearch instance. The source databases aren't publicly accessible and AWS DMS doesn't support Elasticsearch targets in different regions, so I need to forward all the ES documents to a primary ES instance in one region. Here's a simplified diagram:

 ![region 1](https://us1.discourse-cdn.com/elastic/original/3X/8/2/82d3b1a31024860e7e8a38291604da377bdc4e47.jpeg)  
The forwarding ES doesn't need to keep anything; all searching will be done on the primary ES. What's the best way to consolidate documents from multiple Elasticsearch instances onto this single primary instance?

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 3, 2020, 1:10am UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/2 "2020-12-03T01:10:16Z")

</div>

I'd look at either CCR or CCS to do what you want, would make things easier.

---

<div class="post-metadata">

**Author:** ![Asher](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Asher](https://discuss.elastic.co/u/Asher)\
**Post date:** [December 3, 2020, 9:38pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/3 "2020-12-03T21:38:40Z")

</div>

Thanks for the suggestion. Unfortunately, AWS's elasticsearch service doesn't support CCR or CCS across AWS regions, and the AWS Database Migration Service only supports the ES service, not a self-managed stack. Perhaps using CCR is still the way to go, but this would require mapping the RDS data to ES by some other method.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 3, 2020, 9:40pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/4 "2020-12-03T21:40:25Z")

</div>

You can always use Elastic Cloud, which can run on AWS and is available in their Marketplace, which will provide you with a heap more functionality.

---

<div class="post-metadata">

**Author:** ![Asher](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Asher](https://discuss.elastic.co/u/Asher)\
**Post date:** [December 3, 2020, 9:46pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/5 "2020-12-03T21:46:00Z")

</div>

As far as I can tell, Elastic Cloud isn't a supported DMS target, unfortunately.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 3, 2020, 9:46pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/6 "2020-12-03T21:46:42Z")

</div>

Not sure what that means sorry.

---

<div class="post-metadata">

**Author:** ![Asher](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Asher](https://discuss.elastic.co/u/Asher)\
**Post date:** [December 3, 2020, 9:50pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/7 "2020-12-03T21:50:13Z")

</div>

DMS is the AWS Database Migration Service, which provides a fairly simple way to replicate a subset of the data in the relational DBs to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 3, 2020, 9:57pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/8 "2020-12-03T21:57:43Z")

</div>

Ah right, what about using Logstash with the JDBC input then?

---

<div class="post-metadata">

**Author:** ![Asher](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Asher](https://discuss.elastic.co/u/Asher)\
**Post date:** [December 3, 2020, 10:17pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/9 "2020-12-03T22:17:09Z")

</div>

That might be the way to go, thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2020, 10:17pm UTC](https://discuss.elastic.co/t/consolidating-aggregating-es-documents-on-one-elk-stack/257428/10 "2020-12-31T22:17:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
