# Hook one elasticsearch with another ES using logstash

**URL:** <https://discuss.elastic.co/t/hook-one-elasticsearch-with-another-es-using-logstash/95308>\
**Category:** Logstash\
**Created:** [August 1, 2017, 10:03am UTC](https://discuss.elastic.co/t/hook-one-elasticsearch-with-another-es-using-logstash/95308 "2017-08-01T10:03:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sujeetKumar](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@sujeetKumar](https://discuss.elastic.co/u/sujeetKumar)\
**Post date:** [August 1, 2017, 10:03am UTC](https://discuss.elastic.co/t/hook-one-elasticsearch-with-another-es-using-logstash/95308/1 "2017-08-01T10:03:17Z")

</div>

**Is there any way we can hook an index from one Elasticsearch to another.**

input {  
elasticsearch {  
index =\> "student\_details"  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
}  
}

filter {  
date {  
match =\> ["joinDate", "UNIX\_MS", "MMM dd yyyy HH:mm:ss","MMM d yyyy HH:mm:ss", "ISO8601","UNIX\_MS"]  
target =\> "@timestamp"  
}

}

output {  
file {  
path =\> "C:/Users/sujeetk/Pictures/ELK\_5.5/logstash-5.5.0/output/sample.output"  
}  
elasticsearch {  
index =\> "student\_details\_backup"  
hosts =\> ["[http://localhost:9201](http://localhost:9201)"]  
}  
}

**Now logstash pipeline is getting stopped after passing all documents. But I want to keep connection alive so that if any document is inserted or updated in index1 , it should update the same in index2.**

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 3, 2017, 12:05pm UTC](https://discuss.elastic.co/t/hook-one-elasticsearch-with-another-es-using-logstash/95308/2 "2017-08-03T12:05:22Z")

</div>

That kind of continuous operation is not supported by the elasticsearch input plugin.

---

<div class="post-metadata">

**Author:** ![jogoinar10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jogoinar10/32/20068_2.png) [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)\
**Post date:** [August 11, 2017, 9:53am UTC](https://discuss.elastic.co/t/hook-one-elasticsearch-with-another-es-using-logstash/95308/3 "2017-08-11T09:53:52Z")

</div>

I'm rooting for this also.

> [@magnusbaeck](#):
>
> That kind of continuous operation is not supported by the elasticsearch input plugin.

So it means it is not like another logs which the logstash gets any changes of that logs/file?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 11, 2017, 11:12am UTC](https://discuss.elastic.co/t/hook-one-elasticsearch-with-another-es-using-logstash/95308/4 "2017-08-11T11:12:04Z")

</div>

> So it means it is not like another logs which the logstash gets any changes of that logs/file?

Correct.

---

<div class="post-metadata">

**Author:** ![jogoinar10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jogoinar10/32/20068_2.png) [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)\
**Post date:** [August 11, 2017, 11:12am UTC](https://discuss.elastic.co/t/hook-one-elasticsearch-with-another-es-using-logstash/95308/5 "2017-08-11T11:12:59Z")

</div>

Thanks for your confirmation @magnusbaeck.  
Do you have any suggestions or workaround for this? hmmm

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2017, 11:13am UTC](https://discuss.elastic.co/t/hook-one-elasticsearch-with-another-es-using-logstash/95308/6 "2017-09-08T11:13:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
