# How do I 'Update All Fields Where'

**URL:** <https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293>\
**Category:** Elasticsearch\
**Created:** [May 12, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293 "2023-05-12T11:21:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ste1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ste1/32/119876_2.png) [@ste1](https://discuss.elastic.co/u/ste1)\
**Post date:** [May 12, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293/1 "2023-05-12T11:21:05Z")

</div>

I have a few different indicies that have logs in them that were digested using Logstash.

The filter in my config looks like this:

```auto
filter {
  csv {
    autodetect_column_names => false
    columns => ["uid", "ip"]
    separator => ":"
    target => "_tmp"
  }
  mutate {
    add_field => {
      "[data][uid]" => "%{[_tmp][uid]}"
      "[data][ip]" => "%{[_tmp][ip]}"
    }
  }
  mutate {
    remove_field => ["_tmp"]
  }
  prune {
    whitelist_names => ["data"]
  }
}

```

Because the config didnt have any checks to see if one of the columns is empty, it would instead digest the literal string "%{[\_tmp][uid]}".

I would like to update all fields in all indices where data.uid == %{[\_tmp][uid]}". Im not entirely sure how to do this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293/2 "2023-06-09T11:21:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
