# Logstash elasticsearch output, parent/child

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-output-parent-child/47667>\
**Category:** Logstash\
**Created:** [April 18, 2016, 2:38pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-parent-child/47667 "2016-04-18T14:38:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![raleel](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@raleel](https://discuss.elastic.co/u/raleel)\
**Post date:** [April 18, 2016, 2:38pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-parent-child/47667/1 "2016-04-18T14:38:05Z")

</div>

It appears to me that the elasticsearch output module is not properly passing at least the parent parameter along with it. I'm not sure why. The document\_id and parent parameters are in the data, and confirmed to be consistent between them and between runs.

Log message in ES says -

> [2016-04-18 10:21:26,853][INFO][rest.suppressed] /\_bulk Params: {}  
> java.lang.IllegalArgumentException: Can't specify parent if no parent field has been configured

logstash config elasticsearch section is

> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> index =\> "relationship"  
> parent =\> "%{fingerprint}"  
> routing =\> "%{fingerprint}"  
> #template =\> "iprel-basic.template"  
> #template\_name =\> "relationships"  
> #template\_overwrite =\> true  
> }

logstash config elasticsearch config for the parent document

> elasticsearch {  
> action =\> "update"  
> doc\_as\_upsert =\> true  
> document\_id =\> "%{fingerprint}"  
> routing =\> "%{fingerprint}"  
> hosts =\> ["localhost:9200"]  
> index =\> "relationship"  
> template =\> "iprel-basic.template"  
> template\_name =\> "relationships"  
> template\_overwrite =\> true  
> }

My mapping is

> {  
> "template" : "relationships",  
> "settings" : {  
> "index": {  
> "number\_of\_shards" : "1",  
> "number\_of\_replicas" : "0",  
> "refresh\_interval" : "1s"  
> }  
> },  
> "mappings" : {  
> "ip-relationship": {  
> "\_type": "ip\_relationship",  
> "\_all" : {"enabled" : true}  
> },  
> "ip-conversation" : {  
> "\_type": "ip-conversation",  
> "\_all" : {"enabled" : true},  
> "\_routing": {  
> "required": true  
> },  
> "\_parent": {  
> "type": "ip-relationship"  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![raleel](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@raleel](https://discuss.elastic.co/u/raleel)\
**Post date:** [May 6, 2016, 5:33pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-parent-child/47667/2 "2016-05-06T17:33:32Z")

</div>

Can I get a hand here? 3 weeks, still have not been able to find a solution or even a cause.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-parent-child/47667/3 "2017-07-06T04:59:01Z")

</div>


