# How to use elasticsearch input plugin in logstash to get more than 10000 results from ES

**URL:** <https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586>\
**Category:** Logstash\
**Created:** [June 5, 2018, 10:15am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586 "2018-06-05T10:15:18Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Moka](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Moka](https://discuss.elastic.co/u/Moka)\
**Post date:** [June 5, 2018, 10:15am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/1 "2018-06-05T10:15:18Z")

</div>

Hello,

I want to copy the data in a distant Es (which I have a limited access ) to another ES where I have full rights.  
So,the input Es index contains 50000 documents , and I manage to get only 10000 hits using the following configuration:

```
input {

elasticsearch {
hosts => ["xxxx:9200"]
index => "forxx"
user => "kibxx"
password =>"xxx!"
query => '{ "query": {"match_all": {}} }'
tags => "table_elastic_to_elastic"
ssl_certificate_verification => false
ssl => true
size => 10000

}
output {

stdout {}
if "table_elastic_to_elastic" in [tags] {
elasticsearch {
    index => "newindex"
    document_id => "%{ID}"
    hosts => ["localhost:9200"]
    }
} 

```

}\*\*

---

<div class="post-metadata">

**Author:** ![npontes](https://avatars.discourse-cdn.com/v4/letter/n/ba8739/32.png) [@npontes](https://discuss.elastic.co/u/npontes)\
**Post date:** [June 5, 2018, 3:04pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/2 "2018-06-05T15:04:36Z")

</div>

Is it because you're defining the size to 10000?

---

<div class="post-metadata">

**Author:** ![Moka](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Moka](https://discuss.elastic.co/u/Moka)\
**Post date:** [June 5, 2018, 3:22pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/3 "2018-06-05T15:22:18Z")

</div>

If don't specify size=10000 , logstash will use the default value which is equal to 1000

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [June 5, 2018, 3:24pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/4 "2018-06-05T15:24:56Z")

</div>

increase the size to 50000

---

<div class="post-metadata">

**Author:** ![Moka](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Moka](https://discuss.elastic.co/u/Moka)\
**Post date:** [June 5, 2018, 3:29pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/5 "2018-06-05T15:29:53Z")

</div>

the maximum size is 10000

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [June 5, 2018, 3:34pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/6 "2018-06-05T15:34:12Z")

</div>

use the scroll API, search the forums here and you will get answers. Its always a good practice to search the forum before posting or google it 🙂  
If still need help please ask here

---

<div class="post-metadata">

**Author:** ![Moka](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Moka](https://discuss.elastic.co/u/Moka)\
**Post date:** [June 5, 2018, 3:53pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/7 "2018-06-05T15:53:16Z")

</div>

if I don't specify scroll , then logstash will use the default value which is equal to "1m".  
I've searched google and forums but I didn't find any answers

---

<div class="post-metadata">

**Author:** ![npontes](https://avatars.discourse-cdn.com/v4/letter/n/ba8739/32.png) [@npontes](https://discuss.elastic.co/u/npontes)\
**Post date:** [June 5, 2018, 4:01pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/8 "2018-06-05T16:01:11Z")

</div>

Have you tried on Postman perform a GET to see if you're receiving 50k or just 10k?

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [June 5, 2018, 9:01pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/9 "2018-06-05T21:01:50Z")

</div>

Any reason why you can't use [Reindex from Remote](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html#reindex-from-remote) instead of Logstash?

---

<div class="post-metadata">

**Author:** ![Moka](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Moka](https://discuss.elastic.co/u/Moka)\
**Post date:** [June 6, 2018, 7:52am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/10 "2018-06-06T07:52:36Z")

</div>

I chose Logstash to run the job everyday at a certain time using Logstash "schedule"

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [June 6, 2018, 8:38am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/11 "2018-06-06T08:38:53Z")

</div>

You could use `cron` or similar to schedule a script that calls the reindex API once a day. The reindex API supports queries, which would allow you to only transfer those entries that were done since the last run (if your data contains timestamps).

When transferring large result sets, you should also look into using the [scroll API](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-scroll.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2018, 8:38am UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-input-plugin-in-logstash-to-get-more-than-10000-results-from-es/134586/12 "2018-07-04T08:38:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
