# How to update elasticsearch index?

**URL:** https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547
**Category:** Kibana
**Created:** [January 2, 2020, 9:59am UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547 "2020-01-02T09:59:36Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![volcano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/volcano/32/46287_2.png) [@volcano](https://discuss.elastic.co/u/volcano)
#### Post date: [January 2, 2020, 9:59am UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547/1 "2020-01-02T09:59:37Z")

</div>

I have this output plugin in Logstash to create elastic search index.

```auto
output {
    amazon_es {
       hosts => ["https://xxxxxxxxxxxxxxxx.es.amazonaws.com/"]
       region => "ap-southeast-1"
       index => "studentservice-logs-%{+YYYY.MM.dd}"
   }
}

```

I want to update this index later because there will be some new fields added by _mutate_ for some log messages.

How to update index ?

---

<div class="post-metadata">

### Author: ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)
#### Post date: [January 2, 2020, 3:20pm UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547/2 "2020-01-02T15:20:15Z")

</div>

hi @volcano,

this seems more like a logstash question, so I will move this question there

As for adding new fields: you should be able to add a new field to an index at any time. afaik, I don't think logstash prevents you from doing this.

The configuration you are showing is the actual output-index though (?) Do you mean to change the elasticsearch-index itself?

---

<div class="post-metadata">

### Author: ![volcano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/volcano/32/46287_2.png) [@volcano](https://discuss.elastic.co/u/volcano)
#### Post date: [January 3, 2020, 11:25am UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547/3 "2020-01-03T11:25:10Z")

</div>

My Issue is :

I have added new fields in logstash.conf file by the mutate filter But these new fields are not visible in Kibana index pattern. I have already refreshed Kibana index pattern but still it is not visible.

what to look at to fix this issue ?

---

<div class="post-metadata">

### Author: ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)
#### Post date: [January 3, 2020, 10:52pm UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547/4 "2020-01-03T22:52:35Z")

</div>

is the `_mapping` of your index correctly updated as well?

ie. run `GET localhost:9200/logstashindex/_mapping` in Kibana dev-tools or in browser.

---

<div class="post-metadata">

### Author: ![volcano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/volcano/32/46287_2.png) [@volcano](https://discuss.elastic.co/u/volcano)
#### Post date: [January 4, 2020, 7:29am UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547/5 "2020-01-04T07:29:41Z")

</div>

> [@thomasneirynck](#):
>
> is the `_mapping` of your index correctly updated as well?

No.....Not updated.

I checked this  
`GET localhost:9200/logstashindex/_mapping` in Kibana dev-tools

I dont see the new fields in the result.

what to do next ?

---

<div class="post-metadata">

### Author: ![volcano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/volcano/32/46287_2.png) [@volcano](https://discuss.elastic.co/u/volcano)
#### Post date: [January 5, 2020, 6:09pm UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547/6 "2020-01-05T18:09:20Z")

</div>

although I find the fields in debug mode and in stdout.

---

<div class="post-metadata">

### Author: ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)
#### Post date: [January 5, 2020, 11:04pm UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547/7 "2020-01-05T23:04:11Z")

</div>

hmmm... it seems your fields are not added to the elasticsearch index.

Can you look at an example document? e.g. just do an `_search` against the index. Does that document contain the expected fields?

If that document does not contain the expected fields,, something is going wrong in the ingestion process..

---

<div class="post-metadata">

### Author: ![volcano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/volcano/32/46287_2.png) [@volcano](https://discuss.elastic.co/u/volcano)
#### Post date: [January 6, 2020, 4:01am UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547/8 "2020-01-06T04:01:50Z")

</div>

`_search` against the index

```
 GET /service-logs-2020.01.05/_search
{
    "query": {
        "match_all" : { }
    }
}

```

This does not also show new fields .

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 3, 2020, 4:02am UTC](https://discuss.elastic.co/t/how-to-update-elasticsearch-index/213547/9 "2020-02-03T04:02:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
