# Elasticsearch add new field in index by using update by query plugin

**URL:** <https://discuss.elastic.co/t/elasticsearch-add-new-field-in-index-by-using-update-by-query-plugin/51792>\
**Category:** Elasticsearch\
**Created:** [June 3, 2016, 11:26am UTC](https://discuss.elastic.co/t/elasticsearch-add-new-field-in-index-by-using-update-by-query-plugin/51792 "2016-06-03T11:26:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![r.ganeshbabu](https://avatars.discourse-cdn.com/v4/letter/r/4da419/32.png) [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Post date:** [June 3, 2016, 11:26am UTC](https://discuss.elastic.co/t/elasticsearch-add-new-field-in-index-by-using-update-by-query-plugin/51792/1 "2016-06-03T11:26:47Z")

</div>

Hi All,

I want to add a new field (with value) to all documents which is already indexed.

I guess we can possible to do it using bulk update\_by\_query plugin.

We are using Elasticsearch 1.7.3 version in DEV server and I installed update\_by\_plugin of version 2.6.0 and added dependency property in pom.xml & setting script.disable\_dynamic: false added in elasticsearch yml file

Is the version update\_by\_plugin 2.6.0 is correct?

Below is the link I followed,

> **[yakaz/elasticsearch-action-updatebyquery](https://github.com/yakaz/elasticsearch-action-updatebyquery)**
>
> elasticsearch-action-updatebyquery - ElasticSearch Update By Query action plugin

I here provided the sample data,

POST es\_item/item/15781272  
{  
"ITEM\_ID": 15781272,  
"ITEM\_CODE": "15781272",  
"ITEM\_DSCR": null,  
"ITEM\_SPECIFICITY\_REF\_ID": 184,  
"ITEM\_TYPE": "STANDARD ITEM",  
"MOD\_CHR\_VAL\_ID": 44632242,  
"MOD\_DSCR": "CANADIAN TRANSITION STANDARD MODULE",  
"SG\_CHR\_VAL\_ID": 44632240,  
"PG\_CHR\_VAL\_ID": 44632241  
"RELATIONSHIP": [  
{  
"REL\_TYP\_REF\_ID": -999,  
"REL\_TYPE": "NO RELATIONSHIP",  
"REL\_CTGRY": "NIL"  
}  
],  
"ITEM\_MISUSED\_GTIN\_FLG": "N",  
"CRT\_DTTM": "2012-04-03 00:00:00",  
"UPD\_DTTM": "2016-02-03 15:18:44",  
"ICV": {  
"C21472": 45465553  
}  
}

I want to add the new field "GLBL\_CTGRY\_ID":456 in the existing index next to the ICV part.

Is it possible to do in Elasticsearch Update by query plugin?

Please provide your feedback and it would be very helpful.

Thanks,  
Ganeshbabu R

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 3, 2016, 2:23pm UTC](https://discuss.elastic.co/t/elasticsearch-add-new-field-in-index-by-using-update-by-query-plugin/51792/2 "2016-06-03T14:23:48Z")

</div>

Since you are changing _every_ document and not just a subset it may make more sense to just reindex into a new index. An update in elasticsearch is essentially a delete and an insert and the deleted documents aren't physically deleted until background housekeeping tasks clear those marked as deleted away.

It might be more efficient to reindex the content into a new index following the guidelines here: [https://www.elastic.co/guide/en/elasticsearch/guide/current/reindex.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/reindex.html)

---

<div class="post-metadata">

**Author:** ![r.ganeshbabu](https://avatars.discourse-cdn.com/v4/letter/r/4da419/32.png) [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Post date:** [June 3, 2016, 2:39pm UTC](https://discuss.elastic.co/t/elasticsearch-add-new-field-in-index-by-using-update-by-query-plugin/51792/3 "2016-06-03T14:39:33Z")

</div>

Hi @Mark_Harwood

Thanks for the clarifications.

As I checked in the ES documentation using logstash we can reindex the data to the new index at that time can we add the new fields to the document with the value?

Is it possible in logstash?

Let us know your suggestions

Thanks,  
Ganeshbabu R

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 3, 2016, 2:42pm UTC](https://discuss.elastic.co/t/elasticsearch-add-new-field-in-index-by-using-update-by-query-plugin/51792/4 "2016-06-03T14:42:45Z")

</div>

I'm not a Logstash expert I'm afraid but it sounds like the sort of thing that should be possible. I suggest asking in the Logstash forum.

Cheers  
Mark

---

<div class="post-metadata">

**Author:** ![r.ganeshbabu](https://avatars.discourse-cdn.com/v4/letter/r/4da419/32.png) [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Post date:** [June 3, 2016, 2:54pm UTC](https://discuss.elastic.co/t/elasticsearch-add-new-field-in-index-by-using-update-by-query-plugin/51792/5 "2016-06-03T14:54:14Z")

</div>

Okay @Mark_Harwood

Hi @magnusbaeck/@dadoonet

Could you please share you thoughts on this request?

It would be very helpful.

Thanks  
Ganeshbabu R

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:46pm UTC](https://discuss.elastic.co/t/elasticsearch-add-new-field-in-index-by-using-update-by-query-plugin/51792/6 "2017-07-05T22:46:23Z")

</div>


