# \[Logstash\] Can't update document for status (entity-centric)

**URL:** <https://discuss.elastic.co/t/logstash-cant-update-document-for-status-entity-centric/261692>\
**Category:** Logstash\
**Created:** [January 20, 2021, 7:17pm UTC](https://discuss.elastic.co/t/logstash-cant-update-document-for-status-entity-centric/261692 "2021-01-20T19:17:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joao\_Palma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joao_palma/32/45243_2.png) [@Joao\_Palma](https://discuss.elastic.co/u/Joao_Palma)\
**Post date:** [January 20, 2021, 7:17pm UTC](https://discuss.elastic.co/t/logstash-cant-update-document-for-status-entity-centric/261692/1 "2021-01-20T19:17:26Z")

</div>

Hello,

I have this logs:

```auto
{"process": "123", "status:red", "@timestamp":"2020-12-31T16:14:13.886+0000" }
{"process": "122", "status:red", "@timestamp":"2020-12-31T16:14:14.886+0000" }
{"process": "123", "status:green", "@timestamp":"2020-12-31T16:15:13.886+0000" }

```

(this is storaged in one index filebeat-_)  
and I want to make a new index (status-_) with last one, like this:

```auto
{"process": "122", "status:red", "timestamp":"2020-12-31T16:14:14.886+0000" }
{"process": "123", "status:green", "timestamp":"2020-12-31T16:15:13.886+0000" } 

```

but now I can't update the log in elastic  
I have this pipeline

```auto
input {
	elasticsearch {
		hosts => ["elasticsearch:9200"]
		index => ["filebeat-*"] # ORIGINAL INDEX
		docinfo => true
                schedule => "*/1 * * * *"
                size => 500
                query => (take all logs not processed)
         }
}
filter {
     elasticsearch {
		hosts => ["elasticsearch:9200"]
		index => ["status-*"] #STATUS INDEX
                query => "process:%{[process]}"´
               fields => {
                          "status"=>"old_status"
                          "timestamp"=>"old_timestamp"
               }
         }

    if (!([old_status])) {
        clone {
            clones => ["status_metadata"]
        }
        if [type] == "status_metadata" {
            prune {
                whitelist_names => ["status", "timestamp"]
            } 
        }
    }
    if ( [timestamp] > [old_timestamp]) {
        aggregate {
            task_id => "%{[@message][processInstId]}"
            code => 'map["@message"] = event.get("[@message]")'
        }
            
    }  
}
output {
    stdout {
        codec => rubydebug
    }
    if ([@metadata][type] == "status_metadata") {
        elasticsearch {
            hosts => ["elasticsearch:9200"]
            manage_template => false
            index => "status-%{+YYYY.MM.dd}"
            action => "update"
            doc_as_upsert => true
            document_type => "%{[@metadata][_type]}"
            document_id => "%{[@message][processInstId]}"
        }
    }
    else {
        elasticsearch {
			hosts => ["elasticsearch:9200"]
			index => "%{[@metadata][_index]}"
			document_type => "%{[@metadata][_type]}"
			document_id => "%{[@metadata][_id]}"
		}
    }
    
}

```

My problem it's the document never is updated in elasticsearch... Can You help? pls

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2021, 7:17pm UTC](https://discuss.elastic.co/t/logstash-cant-update-document-for-status-entity-centric/261692/2 "2021-02-17T19:17:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
