# How to get data from other index (indexb) and add it to current index (temp) based on common field

**URL:** <https://discuss.elastic.co/t/how-to-get-data-from-other-index-indexb-and-add-it-to-current-index-temp-based-on-common-field/206965>\
**Category:** Logstash\
**Created:** [November 7, 2019, 1:43pm UTC](https://discuss.elastic.co/t/how-to-get-data-from-other-index-indexb-and-add-it-to-current-index-temp-based-on-common-field/206965 "2019-11-07T13:43:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aasoft](https://avatars.discourse-cdn.com/v4/letter/a/90ced4/32.png) [@aasoft](https://discuss.elastic.co/u/aasoft)\
**Post date:** [November 7, 2019, 1:43pm UTC](https://discuss.elastic.co/t/how-to-get-data-from-other-index-indexb-and-add-it-to-current-index-temp-based-on-common-field/206965/1 "2019-11-07T13:43:59Z")

</div>

## I have two indexes:

## current one: **temp** PUT temp/doc/1 {"Field1" : "data1", "Field2" : "data2", "cnt\_no":"1"}

## and other index: **indexb** PUT indexb/doc/1 {"Field3" : "data3", "Field4" : "data4", "cnt\_no":"1"}

I would like to create the second index based on index **temp** but add columns from **indexb** to it. Common field in **cnt\_no**.

Basically I like to add field **Field3** and **Field4** from indexb based on cnt\_no and create **indexc**.

## I used the following logstash but it doesn't create **indexc**.

input {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
user =\> "user1"  
password =\> "pass1"  
index =\> "indexb"  
}  
}

filter {  
elasticsearch {  
hosts =\> ["[http://locahost:9200](http://locahost:9200)"]  
user =\> "user1"  
password =\> "pass1"  
index =\> "temp"  
query =\> "cnt\_no:%{cnt\_no}"  
fields =\> {  
"Field1" =\> "Field1"  
"Field2" =\> "Field2"  
}  
}  
}

## } output { elasticsearch { hosts =\> ["[http://locahost:9200](http://locahost:9200)"] user =\> "user1" password =\> "pass1" ssl\_certificate\_verification =\> "false" index =\> "indexc" document\_id =\> "%{cnt\_no}" doc\_as\_upsert =\> "true" action =\> "update" } }

I am getting error and indexc is not create. there is something wrong in the **filter** section.  
I need help on the filter section.  
How can I do this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 7, 2019, 2:55pm UTC](https://discuss.elastic.co/t/how-to-get-data-from-other-index-indexb-and-add-it-to-current-index-temp-based-on-common-field/206965/2 "2019-11-07T14:55:28Z")

</div>

> [@aasoft](#):
>
> I am getting error and indexc is not create.

What error?

---

<div class="post-metadata">

**Author:** ![aasoft](https://avatars.discourse-cdn.com/v4/letter/a/90ced4/32.png) [@aasoft](https://discuss.elastic.co/u/aasoft)\
**Post date:** [November 7, 2019, 4:08pm UTC](https://discuss.elastic.co/t/how-to-get-data-from-other-index-indexb-and-add-it-to-current-index-temp-based-on-common-field/206965/3 "2019-11-07T16:08:38Z")

</div>

[ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, input, filter, output at line 24, column 1 (byte 515) after ", :backtrace=\>["/logstash/compiler.rb:41:in `compile_imperative'", "/logstash/compiler.rb:49:in `compile\_graph'", "/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2577:in `map'", "/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:151:in `initialize'", "/logstash/pipeline.rb:22:in `initialize'", "/logstash/pipeline.rb:90:in `initialize'", "/logstash/pipeline\_action/create.rb:43:in `block in execute'", "/logstash/agent.rb:96:in `block in exclusive'", "org/jruby/ext/thread/Mutex.java:165:in `synchronize'", "/logstash/agent.rb:96:in `exclusive'", "/logstash/pipeline\_action/create.rb:39:in `execute'", "/logstash/agent.rb:334:in `block in converge\_state'"]}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 7, 2019, 4:26pm UTC](https://discuss.elastic.co/t/how-to-get-data-from-other-index-indexb-and-add-it-to-current-index-temp-based-on-common-field/206965/4 "2019-11-07T16:26:33Z")

</div>

You have an extra } just before the output section that you need to remove.

---

<div class="post-metadata">

**Author:** ![aasoft](https://avatars.discourse-cdn.com/v4/letter/a/90ced4/32.png) [@aasoft](https://discuss.elastic.co/u/aasoft)\
**Post date:** [November 7, 2019, 4:35pm UTC](https://discuss.elastic.co/t/how-to-get-data-from-other-index-indexb-and-add-it-to-current-index-temp-based-on-common-field/206965/5 "2019-11-07T16:35:22Z")

</div>

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2019, 4:36pm UTC](https://discuss.elastic.co/t/how-to-get-data-from-other-index-indexb-and-add-it-to-current-index-temp-based-on-common-field/206965/6 "2019-12-05T16:36:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
