# Elasticsearch transformation query

**URL:** <https://discuss.elastic.co/t/elasticsearch-transformation-query/366147>\
**Category:** Elastic Search\
**Tags:** transforms\
**Created:** [September 6, 2024, 10:36am UTC](https://discuss.elastic.co/t/elasticsearch-transformation-query/366147 "2024-09-06T10:36:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![venkatkumar229](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/venkatkumar229/32/104663_2.png) [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Post date:** [September 6, 2024, 10:36am UTC](https://discuss.elastic.co/t/elasticsearch-transformation-query/366147/1 "2024-09-06T10:36:02Z")

</div>

We are working on a data processing pipeline that involves multiple transformations. Specifically, we have a use case where the first transformation runs and calculates documents for various systems, including system1. In this transformation, we categorize documents based on their presence as either "Primary only", "Secondary only", or "Both".

In our second transformation, we need to calculate or process documents again for system1. I’m concerned about how changes from "Primary only" to "Both" from the first transformation will be managed. Specifically:

For example- We have 10 logs havings document as primary only now ,if for 2 logs the status changes to both from the first transform.

Since the documents with the "Primary only" status are already indexed, what’s the best approach to ensure these documents are properly updated or removed when their status changes to "Both"? We want to ensure that only "Primary only" documents are retained in the second transformation output.

---

<div class="post-metadata">

**Author:** ![QuentinH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quentinh/32/131177_2.png) [@QuentinH](https://discuss.elastic.co/u/QuentinH)\
**Post date:** [September 6, 2024, 1:22pm UTC](https://discuss.elastic.co/t/elasticsearch-transformation-query/366147/2 "2024-09-06T13:22:39Z")

</div>

Hi,

You may have multiple options to solve this problem. One that I can think of right now would be to chain transforms. Your logs would be your `source` for the first transform. This transform would write a new status (Primary/Secondary/Both) in your `destination` index. You could then use this `destination` index as the source of your second transform that would only consider updated status from your first transform. Depending on what you are trying to achieve, there may be better solutions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2024, 1:23pm UTC](https://discuss.elastic.co/t/elasticsearch-transformation-query/366147/3 "2024-10-04T13:23:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
