# Handling related logs

**URL:** <https://discuss.elastic.co/t/handling-related-logs/106420>\
**Category:** Logstash\
**Created:** [November 5, 2017, 11:44am UTC](https://discuss.elastic.co/t/handling-related-logs/106420 "2017-11-05T11:44:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![novoselrok](https://avatars.discourse-cdn.com/v4/letter/n/b3f665/32.png) [@novoselrok](https://discuss.elastic.co/u/novoselrok)\
**Post date:** [November 5, 2017, 11:44am UTC](https://discuss.elastic.co/t/handling-related-logs/106420/1 "2017-11-05T11:44:59Z")

</div>

I have three types of logs, e.g. A, B and C, where A is the parent of both B and C.

The A log comes first and is saved into elastic search, but B and C can come minutes or hours later. B and C contain the reference to A (their parent).

I want to update the log A in elastic search with B and C when they come, so the schema looks like:

```auto
{
dataA: A,
dataB: B,
dataC: C
}

```

I tried using parent/child relationship in elastic search, but since the relationships are one-to-one, it does  
not make sense to use it (also the querying is slow) - I would rather have denormalized structure.

Is there any way to partialy update the elastic search document from logstash? Or have I gone about this  
all wrong? I would love some suggestions 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 5, 2017, 8:45pm UTC](https://discuss.elastic.co/t/handling-related-logs/106420/2 "2017-11-05T20:45:04Z")

</div>

You could define your own `_id` for the event when you send it to Elasticsearch, that would be for the parent document, A.  
Then for document B, you could do an Elasticsearch filter to lookup A and then merge the two docs, making sure the output uses the same `_id` as the step above in the output.  
Then repeat for document C.

Basically you store the first doc and then update it with the next two 🙂

---

<div class="post-metadata">

**Author:** ![novoselrok](https://avatars.discourse-cdn.com/v4/letter/n/b3f665/32.png) [@novoselrok](https://discuss.elastic.co/u/novoselrok)\
**Post date:** [November 6, 2017, 7:20am UTC](https://discuss.elastic.co/t/handling-related-logs/106420/3 "2017-11-06T07:20:21Z")

</div>

Thank you, I'll try this approach.  
Are there any performance consideration using it?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 6, 2017, 8:16am UTC](https://discuss.elastic.co/t/handling-related-logs/106420/4 "2017-11-06T08:16:13Z")

</div>

There is delays due to the lookups but I can't think it'd be worth worrying about given the end value.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2017, 8:16am UTC](https://discuss.elastic.co/t/handling-related-logs/106420/5 "2017-12-04T08:16:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
