# I need add field, and do value counter, how do it?

**URL:** <https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005>\
**Category:** Elasticsearch\
**Created:** [February 11, 2022, 5:20pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005 "2022-02-11T17:20:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![VK345](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@VK345](https://discuss.elastic.co/u/VK345)\
**Post date:** [February 11, 2022, 5:20pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/1 "2022-02-11T17:20:08Z")

</div>

My config is:

======================================

```auto
input {
        file{
          path => "/home/elk/domains/rf_domains_test"
          start_position => "beginning"
          sincedb_path => "/dev/null"
        }
}

filter {
        grok {
                match => { "message" => "%{HOSTNAME:Domain}%{SPACE}%{USERNAME:Registrator}%{SPACE}%{DATE_EU:Created}%{SPACE}%{DATE_EU:Paid-till}%{SPACE}%{DATE_EU:Free-date}" }
                add_field => { "ID" => "Hello world" }
        }

        mutate {
                remove_field => ["message", "@timestamp", "path", "host", "@version"]
                }

        date {
                match => ["Created","DD.MM.YYYY"]
                target => "Created"
             }

        date {
                match => ["Paid-till","DD.MM.YYYY"]
                target => "Paid-till"
                }

        date {
                match => ["Free-date","DD.MM.YYYY"]
                target => "Free-date"
                }

}

output {
        elasticsearch {
            hosts => "localhost:9200"
            index =>"domains_rf_test"
        }
        stdout {
           codec => rubydebug
        }
}

```

======================================

Now every document i add field - "ID" =\> "Hello world"

Me need:

"ID" =\> "1"  
"ID" =\> "2"  
"ID" =\> "3"  
"ID" =\> "4"  
"ID" =\> "5"  
.......

How do it?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 11, 2022, 5:57pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/2 "2022-02-11T17:57:22Z")

</div>

You need to hold state in Logstash, but it is not explicitly supported.

> [@How to hold a state in Logstash?](https://discuss.elastic.co/t/how-to-hold-a-state-in-logstash/120887):
>
> Hi, I'm trying to apply a state (with a field in ES) to subsequent log lines after seeing [message] =~ "foo" but have not had luck using class variables with the ruby filter (@@classVariable) as described in [Keeping global variables in LS?!](https://discuss.elastic.co/t/keeping-global-variables-in-ls/39908) with logstash 6.0.1. I find that the class variable does not hold the correct value when exploring the data on discover in Kibana. Specifically, I want the state to change when I see [message] =~ "bar" and then hold that value until [message] =~ "foo" is …

What is your purpose of using such incremental ids? Elasticsearch default `_id` is not enough?

---

<div class="post-metadata">

**Author:** ![VK345](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@VK345](https://discuss.elastic.co/u/VK345)\
**Post date:** [February 11, 2022, 6:16pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/3 "2022-02-11T18:16:00Z")

</div>

> [@How to hold a state in Logstash?](https://discuss.elastic.co/t/how-to-hold-a-state-in-logstash/120887/1):
>
> Hi, I'm trying to apply a state (with a field in ES) to subsequent log lines after seeing [message] =~ "foo" but have not had luck using class variables with the ruby filter (@@classVariable) as described in [Keeping global variables in LS?!](https://discuss.elastic.co/t/keeping-global-variables-in-ls/39908) with logstash 6.0.1. I find that the class variable does not hold the correct value when exploring the data on discover in Kibana. Specifically, I want the state to change when I see [message] =~ "bar" and then hold that value until [message] =~ "foo" is …

1. Thank you for you replay.
2. May be you khow different solve this task?
3. May be you know how not use standart -  
id for example\_id:o\_TT6X4B7HVNK6zt50Q8

i need

\_id:1  
\_id:2

Not has this data (1,2,3...) in input ?

---

<div class="post-metadata">

**Author:** ![VK345](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@VK345](https://discuss.elastic.co/u/VK345)\
**Post date:** [February 11, 2022, 6:40pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/4 "2022-02-11T18:40:45Z")

</div>

> [@Tomo\_M](#):
>
> What is your purpose of using such incremental ids? Elasticsearch default `_id` is not enough?

I need to get each document one by one, if incremental ids this is easy.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 11, 2022, 11:31pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/5 "2022-02-11T23:31:26Z")

</div>

As it is difficult, you may need some alternatives. If you would fully explain the situation and the necessity, there could be some proposal.

---

<div class="post-metadata">

**Author:** ![VK345](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@VK345](https://discuss.elastic.co/u/VK345)\
**Post date:** [February 12, 2022, 12:47pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/6 "2022-02-12T12:47:18Z")

</div>

Ok

1. I has index, my index for example Contain 1000 docs
2. I took 1 docs, took need me field, use it for my #bash script, get output my bash script, and POST new data in this doc.

I need do it for my 1000 docs.

I tnink my me i can use it -

> **[Paginate search results | Elasticsearch Guide \[8.0\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/paginate-search-results.html)**

---

<div class="post-metadata">

**Author:** ![VK345](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@VK345](https://discuss.elastic.co/u/VK345)\
**Post date:** [February 12, 2022, 12:48pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/7 "2022-02-12T12:48:28Z")

</div>

Thank you, please answer for my question.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 12, 2022, 12:57pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/8 "2022-02-12T12:57:28Z")

</div>

There is no need for incremental id.

If the size is only 1000, you can get the whole document with

```auto
{
  "size": 10000
  "query": {"match_all": {}}
}

```

If you need pagination, any sort should be ok. See NOTE in [Search after](https://www.elastic.co/guide/en/elasticsearch/reference/current/paginate-search-results.html#search-after).

Anyway, there are \_id fields (something like `{"_id" : "FaslK3QBySSL_rrj9zM5"}`), where unique values are automatically assigned by Elasticsearch, to identify documents.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2022, 12:58pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/9 "2022-03-12T12:58:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
