# Logstash(6.5.4) elasticsearch output

**URL:** <https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219>\
**Category:** Elasticsearch\
**Created:** [December 1, 2022, 7:43am UTC](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219 "2022-12-01T07:43:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![gyrao\_72](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyrao_72/32/108254_2.png) [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Post date:** [December 1, 2022, 7:43am UTC](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219/1 "2022-12-01T07:43:39Z")

</div>

My filebeat is on two servers. let's say **app1** and **app2**

My logs are in the format

```auto
jobID status data

```

**Example:**  
app1 log

```auto
5hgsxyt3838 SCHEDULED data

```

app2 log

```auto
5hgsxyt3838 COMPLETE data

```

Here both these logs have the same jobID.  
I am using this jobID as the document \_id on elasticsearch

```auto
elasticsearch {
			hosts => ["localhost:9200"]
			index => "import-export-logger-%{index-name}"
			document_id => "%{jobID}"
		}

```

Now I want my final status in elasticsearch as _COMPLETE_ but sometimes there is a high load on app1 so app2 logs are processed first then app1.  
So the final status becomes _SCHEDULED_

Is there a way to prevent this from happening i.e I want my document to be updated only when the status is not COMPLETE?  
When the status is COMPLETE document must not update itself

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 1, 2022, 8:05am UTC](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219/2 "2022-12-01T08:05:14Z")

</div>

Are you running 6.X? If so that's very much [EOL](https://www.elastic.co/support/eol) and you will need to upgrade.

---

<div class="post-metadata">

**Author:** ![gyrao\_72](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyrao_72/32/108254_2.png) [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Post date:** [December 1, 2022, 8:14am UTC](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219/3 "2022-12-01T08:14:04Z")

</div>

This is what my org is using.  
So I have to configure for this version only

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 1, 2022, 8:26am UTC](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219/4 "2022-12-01T08:26:28Z")

</div>

> [@gyrao\_72](#):
>
> Is there a way to prevent this from happening i.e I want my document to be updated only when the status is not COMPLETE?  
> When the status is COMPLETE document must not update itself

I do not think this is possible, at least not from Logstash. If you were on a newer vetsion it may have been possible to create a summary index using transform but your version is too old AFAIK.

---

<div class="post-metadata">

**Author:** ![gyrao\_72](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyrao_72/32/108254_2.png) [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Post date:** [December 1, 2022, 1:02pm UTC](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219/5 "2022-12-01T13:02:49Z")

</div>

Is there any other way to solve this .

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 1, 2022, 1:10pm UTC](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219/6 "2022-12-01T13:10:10Z")

</div>

Not that I am aware of or can think of.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2022, 1:11pm UTC](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219/7 "2022-12-29T13:11:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
