# How to call mget from Logstash?

**URL:** <https://discuss.elastic.co/t/how-to-call-mget-from-logstash/269733>\
**Category:** Logstash\
**Created:** [April 9, 2021, 4:37pm UTC](https://discuss.elastic.co/t/how-to-call-mget-from-logstash/269733 "2021-04-09T16:37:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ice2021](https://avatars.discourse-cdn.com/v4/letter/i/c68b51/32.png) [@ice2021](https://discuss.elastic.co/u/ice2021)\
**Post date:** [April 9, 2021, 4:37pm UTC](https://discuss.elastic.co/t/how-to-call-mget-from-logstash/269733/1 "2021-04-09T16:37:20Z")

</div>

The REST request below works in Kibana.

Can this similarly be achieved in Logstash? I am trying to retrieve multiple documents from multiple indices(5 indices) in a single request to ElasticSearch in Logstash.

```auto
GET /_mget
    {
      "docs": [
        {
          "_index": "index1",
          "_id": "A"
        },
        {
          "_index": "index2",
          "_id": "B"
        }
      ]
    }

```

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2021, 4:55pm UTC](https://discuss.elastic.co/t/how-to-call-mget-from-logstash/269733/2 "2021-04-09T16:55:22Z")

</div>

I do not think the elasticsearch input can be configured to use an \_mget call. It might be possible with an http\_poller input. Obviously you lose access to all the options of the elasticsearch input if you do that.

---

<div class="post-metadata">

**Author:** ![ice2021](https://avatars.discourse-cdn.com/v4/letter/i/c68b51/32.png) [@ice2021](https://discuss.elastic.co/u/ice2021)\
**Post date:** [April 9, 2021, 5:07pm UTC](https://discuss.elastic.co/t/how-to-call-mget-from-logstash/269733/3 "2021-04-09T17:07:42Z")

</div>

Oh, let me clarify. I was intending for it to be a filter instead. The objective is to join 5 indices to the current event. I could use ElasticSearch as a filter but I can only query one index at a time. 5 indices would mean 5 queries. Is there a way to do this in a single query so essentially one network hop?

```auto
    input {
      #reading from a CSV file
    }

    filter {
    #retrieve documents from index1 and index2 and join with current event
    }

    output {
      elasticsearch {
        hosts => ES
        index => "index3"
       action => "update"
        document_id => "%{key)"
        doc_as_upsert => true
      }

    }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2021, 5:12pm UTC](https://discuss.elastic.co/t/how-to-call-mget-from-logstash/269733/4 "2021-04-09T17:12:09Z")

</div>

> [@ice2021](#):
>
> Oh, let me clarify. I was intending for it to be a filter instead.

Both the input and filter call Elasticsearch::Client.search, and I do not think that method can be told to \_mget. You have the option of using an http filter to make the call to elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2021, 5:13pm UTC](https://discuss.elastic.co/t/how-to-call-mget-from-logstash/269733/5 "2021-05-07T17:13:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
