after your jdbc , you can use elasticsearch filter to query the existing document in ES, add the new field and use update mode on elasticsearch output.
elasticsearch {
hosts => ["elkdev01:9200"]
index => "fw_lifespan"
user => "${elastic_user}"
password => "${elastic_password}"
#here I want to also compare fw_vendor.keyword
query => 'fw_version.keyword:"%{[firmware]}"'
# if match would like to take this two field from fw_lifespan index
fields => [ "fw_recommended","fw_expiration_date"] }
}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.