# Elasticsearch Filter 404 not found

**URL:** <https://discuss.elastic.co/t/elasticsearch-filter-404-not-found/151423>\
**Category:** Logstash\
**Created:** [October 8, 2018, 9:49am UTC](https://discuss.elastic.co/t/elasticsearch-filter-404-not-found/151423 "2018-10-08T09:49:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pierre2](https://avatars.discourse-cdn.com/v4/letter/p/da6949/32.png) [@Pierre2](https://discuss.elastic.co/u/Pierre2)\
**Post date:** [October 8, 2018, 9:49am UTC](https://discuss.elastic.co/t/elasticsearch-filter-404-not-found/151423/1 "2018-10-08T09:49:30Z")

</div>

Hello,

I try to use the Elasticsearch filter [Elasticsearch filter plugin | Logstash Reference [6.3] | Elastic](https://www.elastic.co/guide/en/logstash/6.3/plugins-filters-elasticsearch.html#plugins-filters-elasticsearch-add_field)

There is the situation. I have two indexes : "svi" and "cdr\_sbc"

The is an example of one document in the "svi" index :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/9/d9dda4c1d049f52169c44e149df52d028804f925.png)

In the second index ("cdr\_sbc") I have some fields including IDAppelSVI that contain exactly the same value that in the "svi" index.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/8/9870c2a6bf86e178f4458d731ca0490c981a084e.png)

The common field between the the indexis is IDAppelSVI.

Now, I want to use the elasticsearch filter in my logstash config to add the field UD\_CODESVI that is located in the "svi" index into the document in the "cdr\_sbc" index where the IDAppelSVI is the same.

There is my logstash filter config for the "cdr\_sbc" :

> elasticsearch{  
> hosts =\> ["localhost:9200"]  
> index=\> "svi"  
> query =\> "IDAppelSVI:%{IDAppelSVI}"  
> add\_field =\>{  
> "UD\_CODESVI" =\> "%{UD\_CODESVI}"  
> }  
> }

There is the error that is printed :  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/f/bfeb2c6c044f372ea737fb1f3ad83b419d6162b2.png)

For information I'm shure that when I execute the logstash config file for "cdr\_sbc" the document in the "svi" index already exists.

Why elasticsearch can't find the document that contains the googd "IDAppelSVI" and coppy the content of the "UD\_CODESVI" in my document located in the "cdr\_sbc" index ?

If I try to execute the query bellow I obtain the document that I looked for. That is the proof that ELK can find my document that contains the "IDAppelSVI' that I provide.

> GET svi/\_search  
> {  
> "query": {  
> "query\_string": {  
> "query": "IDAppelSVI:SDusk6701-309d91a4e54bb0dea337d210f6a30178-v300g00060"  
> }  
> },  
> "\_source": ["UD\_CODESVI", "UD\_CODESVI"]  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2018, 9:59am UTC](https://discuss.elastic.co/t/elasticsearch-filter-404-not-found/151423/2 "2018-11-05T09:59:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
