# HTTP output plugin to update datastreams entire document

**URL:** <https://discuss.elastic.co/t/http-output-plugin-to-update-datastreams-entire-document/277487>\
**Category:** Logstash\
**Tags:** painless\
**Created:** [June 30, 2021, 4:53pm UTC](https://discuss.elastic.co/t/http-output-plugin-to-update-datastreams-entire-document/277487 "2021-06-30T16:53:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vijaykumar\_Gundavara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijaykumar_gundavara/32/43693_2.png) [@Vijaykumar\_Gundavara](https://discuss.elastic.co/u/Vijaykumar_Gundavara)\
**Post date:** [June 30, 2021, 4:53pm UTC](https://discuss.elastic.co/t/http-output-plugin-to-update-datastreams-entire-document/277487/1 "2021-06-30T16:53:24Z")

</div>

Hi,

MY use case is as follows. I have a document which is getting inserted into elasticsearch datastreams. The same document is getting updated multiple times in the application and I would like to use \_update\_query API to query and update the entire document using logstash http output plugin ( Since datastreams only support insert by default- It seems the only option for me is to use update\_query API plugin to update a datastream document.

I think my configuration works for most part, the only area where it is not working is trying to replace ctx.\_source with my entire input event document. I feel it is because the input json is getting parsed into fields and even though I used "target" in filter json, it still doesnt work. Any idea how to achieve this?

```auto
         input{
    beats{
        port => 5044
    }
  
} 
     
       
           
 
        filter{
           json {
             source => "message"
             target => "inputdoc"
               }
                                        
             }
        
              
          output {
    if[inputdoc][key] == "elasticsearch" and [inputdoc][sequence] > 0 {       
             http {
               url => "http://xxxxxxx/logs-rave-stage-stream-default/_update_by_query"
               http_method => "post"
               content_type => "application/json"
               format => "message"
               message => '{
  "script": {
    "source": "ctx._source = [inputdoc]",
    "lang": "painless"
   
  },
  "query": {
    "term": {
      "uuid": "0558fa46-c24b-46b9-a83d-d1c3c5ceb53e"
    }
  }
}'
                  }
             elasticsearch {
                hosts => ["xxxxxxxxxxxx"]
                index => "xxxxxxx"
                action => "index"
                doc_as_upsert => "true"
                document_id => "%{[inputdoc][uuid]}"
                version => "%{[inputdoc][sequence]}"
                version_type => "external_gte"
                                  }
                 }
             
     else if[inputdoc][key] == "elasticsearch" and [inputdoc][sequence] == 0 {

              elasticsearch {
                hosts => ["xxxxxxxxxxxx"]
                data_stream => "true"
                data_stream_dataset => "xxxxxx"
                 }
                elasticsearch {
                hosts => ["xxxxxxxxxx"]
                index => "xxxxxxxxxxx"
                action => "index"
                doc_as_upsert => "true"
                document_id => "%{[inputdoc][uuid]}"
                version => "%{[inputdoc][sequence]}"
                version_type => "external_gte"
                         }

     }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2021, 4:53pm UTC](https://discuss.elastic.co/t/http-output-plugin-to-update-datastreams-entire-document/277487/2 "2021-07-28T16:53:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
