# How to prevent duplicate events which is already pushed into elastic using watcher action?

**URL:** <https://discuss.elastic.co/t/how-to-prevent-duplicate-events-which-is-already-pushed-into-elastic-using-watcher-action/118399>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 5, 2018, 8:05am UTC](https://discuss.elastic.co/t/how-to-prevent-duplicate-events-which-is-already-pushed-into-elastic-using-watcher-action/118399 "2018-02-05T08:05:39Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [February 9, 2018, 11:36pm UTC](https://discuss.elastic.co/t/how-to-prevent-duplicate-events-which-is-already-pushed-into-elastic-using-watcher-action/118399/2 "2018-02-09T23:36:54Z")

</div>

Hi there,

According to [this Discuss thread](https://discuss.elastic.co/t/how-to-stop-duplicate-entries-using-elasticsearch-plugin/87880/2), if id, type, and destination index of the documents are the same, then Elasticsearch will automatically avoid duplicating the documents for you.

However if that's problematic, I think you can configure your Watcher with a [webhook action](https://www.elastic.co/guide/en/x-pack/current/actions-webhook.html) to send the document to Logstash instance. You can configure Logstash to use a concept called "fingerprinting" to de-duplicate documents. Take a look at the section called "De-duplicating similar content" in this ["Handling Duplicates"](https://www.elastic.co/blog/logstash-lessons-handling-duplicates) blog post.

Thanks,  
CJ

---

_[View the full topic](https://discuss.elastic.co/t/how-to-prevent-duplicate-events-which-is-already-pushed-into-elastic-using-watcher-action/118399)._
