# Elasticseach as input in logstash? - From the beginning

**URL:** <https://discuss.elastic.co/t/elasticseach-as-input-in-logstash-from-the-beginning/230671>\
**Category:** Logstash\
**Created:** [May 1, 2020, 7:20am UTC](https://discuss.elastic.co/t/elasticseach-as-input-in-logstash-from-the-beginning/230671 "2020-05-01T07:20:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rysiu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rysiu/32/61919_2.png) [@Rysiu](https://discuss.elastic.co/u/Rysiu)\
**Post date:** [May 1, 2020, 7:20am UTC](https://discuss.elastic.co/t/elasticseach-as-input-in-logstash-from-the-beginning/230671/1 "2020-05-01T07:20:41Z")

</div>

Hi,

I have a big problem.

Is there any way to configure Logstash input (elasticsearch) so that after rebooting Logstash does not load the whole elasticsearch index (input) from the beginning?

So that it will load the index from the last document it reads...

I think it always starts reading from the beginning...

Are there any possibilities for manipulation?

I'm not sure if persisted queue here solves the problem...

---

<div class="post-metadata">

**Author:** ![Rahul\_Kumar4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_kumar4/32/67369_2.png) [@Rahul\_Kumar4](https://discuss.elastic.co/u/Rahul_Kumar4)\
**Post date:** [May 1, 2020, 12:27pm UTC](https://discuss.elastic.co/t/elasticseach-as-input-in-logstash-from-the-beginning/230671/2 "2020-05-01T12:27:01Z")

</div>

It seems the `elasticsearch` input plugin in Logstash lacks a checkpointing feature for it to remember the last doc that it queried. Something similar exists in the `jdbc` input plugin - see the `tracking_column` and `last_run_metadata_path` on this link - [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-jdbc.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-jdbc.html)

You could try creating a similar `last_queried_doc` metadata index in Elasticsearch by using the `elasticsearch` output plugin or store that in any other persistent datastore such as `Dynamodb` or `Mongodb` and then during the boot of your Logstash process you could look up that value and inject that value as an environment variable which can be set into the `query` setting of the Elasticsearch input plugin.

Keep in mind that if you use `@timestamp` column to track the last doc queried, you possibly will have a situation where some of the docs may have updated (depending on how you write to your index) and they will not get updated in your output index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2020, 12:27pm UTC](https://discuss.elastic.co/t/elasticseach-as-input-in-logstash-from-the-beginning/230671/3 "2020-05-29T12:27:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
