# Count of DeDuplicated Message from Logstash in ElasticSearch

**URL:** <https://discuss.elastic.co/t/count-of-deduplicated-message-from-logstash-in-elasticsearch/39608>\
**Category:** Logstash\
**Created:** [January 20, 2016, 12:32am UTC](https://discuss.elastic.co/t/count-of-deduplicated-message-from-logstash-in-elasticsearch/39608 "2016-01-20T00:32:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulnadella](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahulnadella/32/22117_2.png) [@rahulnadella](https://discuss.elastic.co/u/rahulnadella)\
**Post date:** [January 20, 2016, 12:32am UTC](https://discuss.elastic.co/t/count-of-deduplicated-message-from-logstash-in-elasticsearch/39608/1 "2016-01-20T00:32:50Z")

</div>

Currently using ElasticSearch 2.1.1, Logstash 2.1.1, and FileBeat 1.0.

I have implemented the document\_id and am wondering if it is possible to keep track of the count of these records.

I am planning on having another index that only has IPAddress's based hourly index and would rather keep track of the count rather than duplicating the same record. This way my index would have far fewer documents in it over the customer given time period.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:15am UTC](https://discuss.elastic.co/t/count-of-deduplicated-message-from-logstash-in-elasticsearch/39608/2 "2017-07-06T05:15:09Z")

</div>


