# How Can I parse logs that are already indexed in elasticsearch with logstash?

**URL:** https://discuss.elastic.co/t/how-can-i-parse-logs-that-are-already-indexed-in-elasticsearch-with-logstash/166578
**Category:** Logstash
**Created:** [January 31, 2019, 2:28pm UTC](https://discuss.elastic.co/t/how-can-i-parse-logs-that-are-already-indexed-in-elasticsearch-with-logstash/166578 "2019-01-31T14:28:47Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 31, 2019, 2:40pm UTC](https://discuss.elastic.co/t/how-can-i-parse-logs-that-are-already-indexed-in-elasticsearch-with-logstash/166578/2 "2019-01-31T14:40:09Z")

</div>

You could use an elasticsearch input and an elasticsearch output, preserving the index name and document id from the [docinfo](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html#plugins-inputs-elasticsearch-docinfo) metadata. Alternatively, if you are just adding new fields use an elasticsearch input and write out a file using the bulk and update APIs and then use curl to POST that into elasticsearch. [This](https://discuss.elastic.co/t/aggregate-problem/142572) thread has some discussion of that.

---

_[View the full topic](https://discuss.elastic.co/t/how-can-i-parse-logs-that-are-already-indexed-in-elasticsearch-with-logstash/166578)._
