# Logstash read previous events fields from elasticsearch in case of high events rate

**URL:** <https://discuss.elastic.co/t/logstash-read-previous-events-fields-from-elasticsearch-in-case-of-high-events-rate/260756>\
**Category:** Logstash\
**Created:** [January 11, 2021, 6:40pm UTC](https://discuss.elastic.co/t/logstash-read-previous-events-fields-from-elasticsearch-in-case-of-high-events-rate/260756 "2021-01-11T18:40:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Post date:** [January 11, 2021, 6:40pm UTC](https://discuss.elastic.co/t/logstash-read-previous-events-fields-from-elasticsearch-in-case-of-high-events-rate/260756/1 "2021-01-11T18:40:54Z")

</div>

Hello

In case of high events rate, if I have multiple events (with predefined order) and I want to copy field from the first event to the subsequent events using logstash elasticsearch filter

Is there a way to guarantee that the first event is being indexed before copying its field to the subsequent events?

because I have tried this and I have noticed the next events are not being updated all the times with this field (some are updated and some are not)

I have tried using aggregate filter but in case the events rate is not high (maybe the subsequent events will come hours after the first one as this is not predictable), it would not be the best approach to use aggregate filter and using the elasticsearch filter is better

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 11, 2021, 6:51pm UTC](https://discuss.elastic.co/t/logstash-read-previous-events-fields-from-elasticsearch-in-case-of-high-events-rate/260756/2 "2021-01-11T18:51:15Z")

</div>

logstash generally does not preserve event order. To retain the order you will need to set pipeline.workers to 1. Also, pipeline.ordered will need to be true or auto (the default). In future versions (8.x) auto may no longer be the default, then you will have to set it to true.

Also, the logstash pipeline works in batches, so a group (by default 125) events go through a filter, are passed to the next filter, and so on until they reach the output. So you may need to set pipeline.batch.size to 1.

Even then there is no guarantee that the output will index the event before the next event is flushed to the pipeline.

---

<div class="post-metadata">

**Author:** ![mostafaelsayed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mostafaelsayed/32/82057_2.png) [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Post date:** [January 17, 2021, 4:10am UTC](https://discuss.elastic.co/t/logstash-read-previous-events-fields-from-elasticsearch-in-case-of-high-events-rate/260756/3 "2021-01-17T04:10:40Z")

</div>

Thanks for the reply

The reason I want to do this is that I want to display the following in a data table in kibana:

if I have two events of this format

```auto
event1 => { "id" => "1", "shared_field" => "shared_value", "field" => "test_value1" }
event2 => { "id" => "1", "field" => "test_value2" }

```

and "shared\_field" is common (shared) for all of the events having a specific "id" but it's only present in the first event for that id

I want to show in the data table the following

```auto
id shared_field field
1 shared_value test_value1 => event1
1 shared_value test_value2 => event2

```

and the only way I could think of it is to denormalize the events (copy "shared\_field" into the next events)

Is there a way to display in this format in Kibana given this format of the events?

---

<div class="post-metadata">

**Author:** ![Joao\_Palma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joao_palma/32/45243_2.png) [@Joao\_Palma](https://discuss.elastic.co/u/Joao_Palma)\
**Post date:** [January 17, 2021, 6:29pm UTC](https://discuss.elastic.co/t/logstash-read-previous-events-fields-from-elasticsearch-in-case-of-high-events-rate/260756/4 "2021-01-17T18:29:06Z")

</div>

Try post processing with logstash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2021, 6:29pm UTC](https://discuss.elastic.co/t/logstash-read-previous-events-fields-from-elasticsearch-in-case-of-high-events-rate/260756/5 "2021-02-14T18:29:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
