# Input Elastic Plugin in Logstash Error

**URL:** <https://discuss.elastic.co/t/input-elastic-plugin-in-logstash-error/216188>\
**Category:** Logstash\
**Created:** [January 23, 2020, 6:59am UTC](https://discuss.elastic.co/t/input-elastic-plugin-in-logstash-error/216188 "2020-01-23T06:59:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![reyhanadp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reyhanadp/32/60990_2.png) [@reyhanadp](https://discuss.elastic.co/u/reyhanadp)\
**Post date:** [January 23, 2020, 6:59am UTC](https://discuss.elastic.co/t/input-elastic-plugin-in-logstash-error/216188/1 "2020-01-23T06:59:30Z")

</div>

Hello Everyone,  
I want to retrieve data from **elastic** using **logstash**. the data that I want to get is sorted by the value column. when I retrieve data from **elastic** without setting a **schedule** , the results of data output are sorted asc or desc. but if the **schedule** setting is activated, the output data is not sorted at all.

This is the logstash config that I use with additional **schedule** settings :

```
input {
elasticsearch {
    hosts => "localhost:9200"
    index => "tes-2020.01"
    schedule => "*/30 * * * * * "
    query => '
    {
        "sort": [
            {
                "value": {
                    "order": "asc"
                }
            }
        ],
        "query": {
            "bool": {
                "must": [
                    {
                        "match": {
                            "id.keyword": "abcdef1235"
                        }
                    }
                ],
                "filter": {
                    "range": {
                        "@timestamp": {
                            "gte": "now-1m",
                            "lte": "now"
                        }
                    }
                }
            }
        }
    }
    '
}
filter {
  mutate {
    convert => {
		"value" => "integer"
	}
  }
}

output {
    csv {
        # elastic field name
        fields => ["@timestamp","id", "service_name", "metric_type", "metric_info", "category","node","value"]
        path => "csv-export-desc.csv"
    }

	stdout {
		codec => "rubydebug"
	}
}

```

This is the output without **schedule** settings :  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/6/b655bc0a122d10cb8a8c9c21c52919d2c3ca4a5b.png)

This is a logstash configuration that I use without setting additional **schedule** :

```
input {
elasticsearch {
    hosts => "localhost:9200"
    index => "tes-2020.01"
    query => '
    {
        "sort": [
            {
                "value": {
                    "order": "asc"
                }
            }
        ],
        "query": {
            "bool": {
                "must": [
                    {
                        "match": {
                            "id.keyword": "abcdef1235"
                        }
                    }
                ],
                "filter": {
                    "range": {
                        "@timestamp": {
                            "gte": "now-1m",
                            "lte": "now"
                        }
                    }
                }
            }
        }
    }
    '
}
filter {
  mutate {
    convert => {
		"value" => "integer"
	}
  }
}

output {
    csv {
        # elastic field name
        fields => ["@timestamp","id", "service_name", "metric_type", "metric_info", "category","node","value"]
        path => "csv-export-desc.csv"
    }

	stdout {
		codec => "rubydebug"
	}
}

```

This is output with setting **schedule** :  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6c7e1b33ad4633e3b39446b27166c717f6f8a3e4.png)

help please. thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 23, 2020, 1:23pm UTC](https://discuss.elastic.co/t/input-elastic-plugin-in-logstash-error/216188/2 "2020-01-23T13:23:31Z")

</div>

> [@reyhanadp](#):
>
> the data that I want to get is sorted by the value column

logstash generally does not preserve the order of events. If you set pipeline.workers to 1 and [disable](https://github.com/elastic/logstash/issues/10938) the java\_execution engine then it will preserve order.

---

<div class="post-metadata">

**Author:** ![reyhanadp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reyhanadp/32/60990_2.png) [@reyhanadp](https://discuss.elastic.co/u/reyhanadp)\
**Post date:** [January 24, 2020, 1:01am UTC](https://discuss.elastic.co/t/input-elastic-plugin-in-logstash-error/216188/3 "2020-01-24T01:01:42Z")

</div>

thank you, it works for me

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2020, 1:01am UTC](https://discuss.elastic.co/t/input-elastic-plugin-in-logstash-error/216188/4 "2020-02-21T01:01:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
