# Keeping same log events once instead of multiple time

**URL:** <https://discuss.elastic.co/t/keeping-same-log-events-once-instead-of-multiple-time/239301>\
**Category:** Logstash\
**Created:** [June 30, 2020, 12:49pm UTC](https://discuss.elastic.co/t/keeping-same-log-events-once-instead-of-multiple-time/239301 "2020-06-30T12:49:35Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 30, 2020, 4:07pm UTC](https://discuss.elastic.co/t/keeping-same-log-events-once-instead-of-multiple-time/239301/2 "2020-06-30T16:07:40Z")

</div>

If you only want to keep one copy of an event where certain fields are the same you could use a fingerprint filter to hash those fields and use the result as the document\_id in elasticsearch. The document will keep getting overwritten with the most recent event. See [here](https://discuss.elastic.co/t/remove-duplicate-documents-that-have-the-same-field-value/193604) for an example, although I would not recommend using SHA1 for _anything_ these days.

---

_[View the full topic](https://discuss.elastic.co/t/keeping-same-log-events-once-instead-of-multiple-time/239301)._
