# Logstash elasticsearch output, expand variables in data stream parameters

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-output-expand-variables-in-data-stream-parameters/275276>\
**Category:** Logstash\
**Created:** [June 8, 2021, 9:39am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-expand-variables-in-data-stream-parameters/275276 "2021-06-08T09:39:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ebourlon](https://avatars.discourse-cdn.com/v4/letter/e/a6a055/32.png) [@ebourlon](https://discuss.elastic.co/u/ebourlon)\
**Post date:** [June 8, 2021, 9:39am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-expand-variables-in-data-stream-parameters/275276/1 "2021-06-08T09:39:20Z")

</div>

Hello,

I am using logstash 7.13.1 that has support for datastreams in the elasticsearch output.  
As far as I looked at it is not possible to specify a variable in one of the datastream related parameter like below:

```auto
  elasticsearch {
	hosts => "localhost"
	data_stream => "true"
	data_stream_type => "metrics"
	data_stream_dataset => "iib"
	data_stream_namespace => "%{[@metadata][namespace]}"
  }

```

This will use "%{[@metadata][namespace]}" as a string.  
Am I correct? Maybe an e.sprintf() to add there?

Br,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 8, 2021, 8:02pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-expand-variables-in-data-stream-parameters/275276/2 "2021-06-08T20:02:36Z")

</div>

Take a look at [data\_stream\_auto\_routing](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-data_stream_auto_routing). Looking at the [code](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/2f8ebf0340e678d0c60c077fd54a58427675a0b4/lib/logstash/outputs/elasticsearch/data_stream_support.rb#L29) it expects a field called [data\_stream]

```
{ "data_stream": { "type": "foo", "dataset": "bar", "namespace": "baz" } }

```

You could build that using sprintf references in a mutate filter.

---

<div class="post-metadata">

**Author:** ![ebourlon](https://avatars.discourse-cdn.com/v4/letter/e/a6a055/32.png) [@ebourlon](https://discuss.elastic.co/u/ebourlon)\
**Post date:** [June 9, 2021, 6:13am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-expand-variables-in-data-stream-parameters/275276/3 "2021-06-09T06:13:01Z")

</div>

Thanks. This is indeed the solution.  
That's what's happening when people don't read the manual 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2021, 6:13am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-expand-variables-in-data-stream-parameters/275276/4 "2021-07-07T06:13:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
