# How to loop or iterate in Logstash output plugin

**URL:** <https://discuss.elastic.co/t/how-to-loop-or-iterate-in-logstash-output-plugin/142991>\
**Category:** Logstash\
**Created:** [August 3, 2018, 10:50pm UTC](https://discuss.elastic.co/t/how-to-loop-or-iterate-in-logstash-output-plugin/142991 "2018-08-03T22:50:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pushanbhattacharya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pushanbhattacharya/32/34104_2.png) [@pushanbhattacharya](https://discuss.elastic.co/u/pushanbhattacharya)\
**Post date:** [August 3, 2018, 10:50pm UTC](https://discuss.elastic.co/t/how-to-loop-or-iterate-in-logstash-output-plugin/142991/1 "2018-08-03T22:50:25Z")

</div>

So, if I have prepared a list or array of string data in LogStash filter using ElasticSearch plugin. I can save that array or list directly in another elasticsearch index from logstash output plugin.

But that list actually contains document\_id of another related index which I would like to update. So basically I need a handle on that list or array to iterate and call elasticsearch from logstash output to update each and every document\_id from that list.

Can you suggest me how to do this? I am unable to find a way around this.

e.g.,

'book' index has an array of 'person\_id' and 'person\_name'  
'person' index also has an array of 'book\_id' and 'book\_name'

Now, if a book or person gets updated, I need to update the other index also, which will be an array.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 5, 2018, 12:01pm UTC](https://discuss.elastic.co/t/how-to-loop-or-iterate-in-logstash-output-plugin/142991/2 "2018-08-05T12:01:48Z")

</div>

Use a split filter to split the array with document ids into multiple events, then use an elasticsearch filter to obtain the current contents of the document and use it to put together the new document which you'll send to an elasticsearch output. Depending on what kind of update you want to perform maybe you can do a scripted update.

---

<div class="post-metadata">

**Author:** ![pushanbhattacharya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pushanbhattacharya/32/34104_2.png) [@pushanbhattacharya](https://discuss.elastic.co/u/pushanbhattacharya)\
**Post date:** [August 15, 2018, 9:38pm UTC](https://discuss.elastic.co/t/how-to-loop-or-iterate-in-logstash-output-plugin/142991/3 "2018-08-15T21:38:00Z")

</div>

Thank you @magnusbaeck for your suggestion. I already resolved it using ruby filter and event cloning.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2018, 9:38pm UTC](https://discuss.elastic.co/t/how-to-loop-or-iterate-in-logstash-output-plugin/142991/4 "2018-09-12T21:38:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
