# How to create my own document\_id in logstash?

**URL:** <https://discuss.elastic.co/t/how-to-create-my-own-document-id-in-logstash/1416>\
**Category:** Logstash\
**Created:** [May 27, 2015, 6:42pm UTC](https://discuss.elastic.co/t/how-to-create-my-own-document-id-in-logstash/1416 "2015-05-27T18:42:30Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![elastic\_paul](https://avatars.discourse-cdn.com/v4/letter/e/ebca7d/32.png) [@elastic\_paul](https://discuss.elastic.co/u/elastic_paul)\
**Post date:** [May 28, 2015, 5:49am UTC](https://discuss.elastic.co/t/how-to-create-my-own-document-id-in-logstash/1416/3 "2015-05-28T05:49:24Z")

</div>

Thanks very much for this. Just what I wanted. Just to help anyone finding this question, here is the code I actually used:

```
ruby {
  code => "require 'digest/md5';
  event['computed_id'] = Digest::MD5.hexdigest(event['ip'] + event['sha1_fingerprint'])"
}

```

Then

```
document_id => "%{computed_id}"

```

Can I ask two more related questions:

1. How can I remove the field after I have set the document\_id? I don't want it in my stored data. eg; remove event['computed\_id']

2. Its seems that my index is BIGGER doing it this way? Any ideas? I thought that deduplication would save space? It can't be because of the extra 'computed\_id' field can it?

Thanks

---

_[View the full topic](https://discuss.elastic.co/t/how-to-create-my-own-document-id-in-logstash/1416)._
