# Datastream with upsert

**URL:** <https://discuss.elastic.co/t/datastream-with-upsert/328266>\
**Category:** Logstash\
**Tags:** datastreams\
**Created:** [March 22, 2023, 3:15pm UTC](https://discuss.elastic.co/t/datastream-with-upsert/328266 "2023-03-22T15:15:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [March 22, 2023, 3:15pm UTC](https://discuss.elastic.co/t/datastream-with-upsert/328266/1 "2023-03-22T15:15:54Z")

</div>

Hello,

We are pulling data from MS SQL database into Elastic via Logstash which is working fine however some records get updated and so we want to update the existing entries in Elastic accordingly.

The data is stored as a datastream but it looks that these don't support doc\_as\_upsert and action parameters in elasticsearch output.

We can't find any documentation that confirms that so the question is are we missing something here or it is not supported? If the latter how can we go about it using logstash?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 22, 2023, 3:28pm UTC](https://discuss.elastic.co/t/datastream-with-upsert/328266/2 "2023-03-22T15:28:45Z")

</div>

> [@djkprojects](#):
>
> We can't find any documentation that confirms that so the question is are we missing something here or it is not supported?

Data streams are append-only, this is described in the [documentation about data streams](https://www.elastic.co/guide/en/elasticsearch/reference/current/data-streams.html#data-streams-append-only), so they do not support `doc_as_upsert`, the only action from logstash that it supports is `create` .

You will need to use normal indices with a rollover alias as explained in this [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/getting-started-index-lifecycle-management.html#manage-time-series-data-without-data-streams) or use time-based indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2023, 3:29pm UTC](https://discuss.elastic.co/t/datastream-with-upsert/328266/3 "2023-04-19T15:29:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
