# Copy data from old index/indice over to new one

**URL:** https://discuss.elastic.co/t/copy-data-from-old-index-indice-over-to-new-one/49995
**Category:** Elasticsearch
**Created:** [May 13, 2016, 11:41am UTC](https://discuss.elastic.co/t/copy-data-from-old-index-indice-over-to-new-one/49995 "2016-05-13T11:41:47Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)
#### Post date: [May 13, 2016, 11:41am UTC](https://discuss.elastic.co/t/copy-data-from-old-index-indice-over-to-new-one/49995/1 "2016-05-13T11:41:47Z")

</div>

Hi,

I implemented an ELK Stack in our environment a few days ago and originally created two indexes that I specified in both Logstash configuration files; "logstash\_syslogs" and "logstash\_netflow".

A few days later I realized that having two separate indexes aren't necessary and won't work out with having one main dashboard to visualize the data. I went ahead and changed the configurations to output to a single "logstash-events" index.

I had over 5 million logs on the old "logstash\_syslog" index and was wondering if I can transfer that data over to my new index "logstash-events".

Is this possible?

---

<div class="post-metadata">

### Author: ![sandros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandros/32/6348_2.png) [@sandros](https://discuss.elastic.co/u/sandros)
#### Post date: [May 13, 2016, 12:09pm UTC](https://discuss.elastic.co/t/copy-data-from-old-index-indice-over-to-new-one/49995/2 "2016-05-13T12:09:57Z")

</div>

Just fetch all from the old index and bulk index it into the new.  
On python I would do it like this:  
`from elasticsearch import Elasticsearch,helpers a=helpers.scan(es,query={"query":{"match_all": {}}},scroll='1m',index=INDEX_NAME_old,doc_type=TYPE_NAME) c=0#if you do not how many docs are too big for a bulk request then try and error ;-) for aa in a: if c%500=0: es.bulk(body=t2,request_timeout=30) t2=[] op_dict = { "index": { "_index": INDEX_NAME_new, "_type": TYPE_NAME, "_id": aa["_id"] } } data_dict=aa["_source"] t2.append(op_dict) t2.append(data_dict) c+=1`  
And last bulk:  
`es.bulk(body=t2,request_timeout=30)`

---

<div class="post-metadata">

### Author: ![sandros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandros/32/6348_2.png) [@sandros](https://discuss.elastic.co/u/sandros)
#### Post date: [May 13, 2016, 12:10pm UTC](https://discuss.elastic.co/t/copy-data-from-old-index-indice-over-to-new-one/49995/3 "2016-05-13T12:10:40Z")

</div>

Sorry I forgot how to get idndetation to work here

---

<div class="post-metadata">

### Author: ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)
#### Post date: [May 13, 2016, 12:20pm UTC](https://discuss.elastic.co/t/copy-data-from-old-index-indice-over-to-new-one/49995/4 "2016-05-13T12:20:20Z")

</div>

If you are on 2.3.x and these indexes are in the same cluster then have a  
look at reindex.

---

<div class="post-metadata">

### Author: ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)
#### Post date: [May 13, 2016, 12:52pm UTC](https://discuss.elastic.co/t/copy-data-from-old-index-indice-over-to-new-one/49995/5 "2016-05-13T12:52:26Z")

</div>

I am currently on 2.2.1 and running everything on Ubuntu 16.04, forgot to mention that sorry.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 10:51pm UTC](https://discuss.elastic.co/t/copy-data-from-old-index-indice-over-to-new-one/49995/6 "2017-07-05T22:51:47Z")

</div>


