# \_id like var in output email

**URL:** <https://discuss.elastic.co/t/id-like-var-in-output-email/272696>\
**Category:** Logstash\
**Created:** [May 11, 2021, 12:24pm UTC](https://discuss.elastic.co/t/id-like-var-in-output-email/272696 "2021-05-11T12:24:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cassiopee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cassiopee/32/88597_2.png) [@cassiopee](https://discuss.elastic.co/u/cassiopee)\
**Post date:** [May 11, 2021, 12:24pm UTC](https://discuss.elastic.co/t/id-like-var-in-output-email/272696/1 "2021-05-11T12:24:43Z")

</div>

hi everyone,

I would use \_id (metadata) like variable in my output mail.  
I make my output on this way :

```
`output {
elasticsearch {
     hosts => ["https://192.168.1.160:9200"]
     ssl => true
     ssl_certificate_verification => false
     user => "admin"
     password => "admin"
     index => "apache"

```

}  
stdout { codec =\> rubydebug }

if [tags] {  
email {  
to =\> "xxx"  
address =\> "[smtp.gmail.com](http://smtp.gmail.com)"  
port =\> 587  
username =\> "xxx"  
password =\> "xxx"  
use\_tls =\> true  
body =\> "something happened: %{message} [http://xxx/5601/app/discover#/doc/82de0080-acd9-11eb-a4b8-614232a13000/indexname?id=%{id}](http://xxx/5601/app/discover#/doc/82de0080-acd9-11eb-a4b8-614232a13000/indexname?id=%25%7Bid%7D)"  
}  
}  
}`

but it wouldn't work because it can't considerate \_id like variable.

someone have idea ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 11, 2021, 1:37pm UTC](https://discuss.elastic.co/t/id-like-var-in-output-email/272696/2 "2021-05-11T13:37:12Z")

</div>

The `_id` does not exist in your logstash document, it will be created by elasticsearch when it receives the document.

To do what you want you would need to set the document id in logstash using the `document_id` option, but how to do that will depend on your document, if you have any field or combination of fields that it is unique.

---

<div class="post-metadata">

**Author:** ![cassiopee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cassiopee/32/88597_2.png) [@cassiopee](https://discuss.elastic.co/u/cassiopee)\
**Post date:** [May 11, 2021, 1:54pm UTC](https://discuss.elastic.co/t/id-like-var-in-output-email/272696/3 "2021-05-11T13:54:48Z")

</div>

yes I understood my mistake. I guess my last challenge it's syntaxic. I generated \_id in logstash by this way :

````auto
    source => "message"
    target => "[@metadata][fingerprint]"
    method => "MURMUR3"
  } ```

``` output {
    elasticsearch {
         hosts => ["https://192.168.1.160:9200"]
         ssl => true
         ssl_certificate_verification => false
         user => "admin"
         password => "admin"
         index => "apache"
         document_id => "%{[@metadata][fingerprint]}"
         fields => { "document_id" => "refid" }
 }
  stdout { codec => rubydebug } } ```

but it's occure errore when I add this line: ``` fields => { "document_id" => "refid" } ```
````

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 11, 2021, 2:00pm UTC](https://discuss.elastic.co/t/id-like-var-in-output-email/272696/4 "2021-05-11T14:00:09Z")

</div>

This `fields => { "document_id" => "refid" }` does not exists in logstash, what are you trying to do?

The `document_id` option in the elasticsearch output will tell elasticsearch to use this value as the value for the `_id` field.

If you want to add another field named `refid` with this same value, you need to add it before the output block, in the filter block.

```auto
mutate {
    add_field => { "refid" => "%{[@metadata][fingerprint]}" }
}

```

Since this will be the value of the `_id` of your document, you could use it in your e-mail output without the need to create another field.

```auto
body => "something happened: %{message} http://xxx/5601/app/discover#/doc/82de0080-acd9-11eb-a4b8-614232a13000/indexname?id=%{[@metadata][fingerprint]}"

```

---

<div class="post-metadata">

**Author:** ![cassiopee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cassiopee/32/88597_2.png) [@cassiopee](https://discuss.elastic.co/u/cassiopee)\
**Post date:** [May 11, 2021, 2:09pm UTC](https://discuss.elastic.co/t/id-like-var-in-output-email/272696/5 "2021-05-11T14:09:46Z")

</div>

I was trying to to give name of \_id for call him in variable like  
document\_id = refid  
` http://xxx/5601/app/discover#/doc/82de0080-acd9-11eb-a4b8-614232a13000/indexname?id=%refid`

thank's it's finally work with your sentence

`body => "something happened: %{message} http://xxx/5601/app/discover#/doc/82de0080-acd9-11eb-a4b8-614232a13000/indexname?id=%{[@metadata][fingerprint]}"`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2021, 2:10pm UTC](https://discuss.elastic.co/t/id-like-var-in-output-email/272696/6 "2021-06-08T14:10:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
