# Get exiting in ES index documents to Logstash pipeline to make calculations

**URL:** <https://discuss.elastic.co/t/get-exiting-in-es-index-documents-to-logstash-pipeline-to-make-calculations/165050>\
**Category:** Logstash\
**Created:** [January 21, 2019, 1:05pm UTC](https://discuss.elastic.co/t/get-exiting-in-es-index-documents-to-logstash-pipeline-to-make-calculations/165050 "2019-01-21T13:05:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dfesenko](https://avatars.discourse-cdn.com/v4/letter/d/a9adbd/32.png) [@dfesenko](https://discuss.elastic.co/u/dfesenko)\
**Post date:** [January 21, 2019, 1:05pm UTC](https://discuss.elastic.co/t/get-exiting-in-es-index-documents-to-logstash-pipeline-to-make-calculations/165050/1 "2019-01-21T13:05:43Z")

</div>

Hello  
I need to create documents in ES index based on the unique IDs of the events. And when the ID of the new event will be the same as the ID of the documents already stored in the ES index, I want NOT TO overwrite it, but to add numeric values from fields in the existing document to the numeric fields of the new event. How can I do this?  
I saw that different calculations can be done using ruby filter. But how I can retrieve information about existing in index document and push this information to logstash pipeline again?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 21, 2019, 1:22pm UTC](https://discuss.elastic.co/t/get-exiting-in-es-index-documents-to-logstash-pipeline-to-make-calculations/165050/2 "2019-01-21T13:22:38Z")

</div>

You might be able to use an elasticsearch filter to fetch fields from an index if you want to add fields to an existing document. Alternatively, instead of writing directly to ES, you could use logstash to generate a text file that could be added to ES using the update/bulk APIs _via_ curl.

---

<div class="post-metadata">

**Author:** ![dfesenko](https://avatars.discourse-cdn.com/v4/letter/d/a9adbd/32.png) [@dfesenko](https://discuss.elastic.co/u/dfesenko)\
**Post date:** [January 29, 2019, 2:37pm UTC](https://discuss.elastic.co/t/get-exiting-in-es-index-documents-to-logstash-pipeline-to-make-calculations/165050/3 "2019-01-29T14:37:30Z")

</div>

Thanks for recommending elasticsearch filter!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2019, 2:37pm UTC](https://discuss.elastic.co/t/get-exiting-in-es-index-documents-to-logstash-pipeline-to-make-calculations/165050/4 "2019-02-26T14:37:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
