# Map index creation\_date to new field in existing documents

**URL:** <https://discuss.elastic.co/t/map-index-creation-date-to-new-field-in-existing-documents/351235>\
**Category:** Elasticsearch\
**Created:** [January 17, 2024, 6:48am UTC](https://discuss.elastic.co/t/map-index-creation-date-to-new-field-in-existing-documents/351235 "2024-01-17T06:48:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![es236908](https://avatars.discourse-cdn.com/v4/letter/e/b4bc9f/32.png) [@es236908](https://discuss.elastic.co/u/es236908)\
**Post date:** [January 17, 2024, 6:48am UTC](https://discuss.elastic.co/t/map-index-creation-date-to-new-field-in-existing-documents/351235/1 "2024-01-17T06:48:55Z")

</div>

Every day I create an index of my file system with Diskover so I have a large amount of indexes one for every day. Each of those indexes has documents for each file but there is no field for the time the index/document was created. Is there a way to map the creation\_date of the index to a new timestamp field in all the existing documents. It looks like for future indexes I can create a default pipeline and use that to automatically do this. But right now I have around 200 existing indexes with a total of ~800 million documents that would need to be updated.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 17, 2024, 9:00am UTC](https://discuss.elastic.co/t/map-index-creation-date-to-new-field-in-existing-documents/351235/2 "2024-01-17T09:00:16Z")

</div>

Welcome!

I don't think you can do that easily. But I'm curious about the use case. I'm suspecting a use case which you could solve in another way.

---

<div class="post-metadata">

**Author:** ![es236908](https://avatars.discourse-cdn.com/v4/letter/e/b4bc9f/32.png) [@es236908](https://discuss.elastic.co/u/es236908)\
**Post date:** [January 17, 2024, 9:26am UTC](https://discuss.elastic.co/t/map-index-creation-date-to-new-field-in-existing-documents/351235/3 "2024-01-17T09:26:08Z")

</div>

Each index has a document for a folder with the size of that folder on the day it was indexed. I want to have a query to get that document in each index that has the size and graph that in Grafana. This would graph the size of the folder over time. The problem is none of the dates in the document work because they are dates like the time that folder was created/modified which does not change that often even if files in that folder were added/removed. So I need a way to go back and add a new field that is the time that index was created.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 17, 2024, 9:52am UTC](https://discuss.elastic.co/t/map-index-creation-date-to-new-field-in-existing-documents/351235/4 "2024-01-17T09:52:20Z")

</div>

And when are you running your index job? Everyday?

It remembers me a bit this blog post: [Building a directory map with ELK - David Pilato](https://david.pilato.fr/blog/2015-12-10-building-a-directory-map-with-elk/)

Where basically I can run everyday a `ls -lr`. In which case you can add the date of the run to the document you are indexing.

I mean, that you need that field for a business reason. Son you should control that field on your side and not rely on an internal technical Elasticsearch field.

Could you share a bit more, like:

- A typical document
- The index names

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2024, 9:52am UTC](https://discuss.elastic.co/t/map-index-creation-date-to-new-field-in-existing-documents/351235/5 "2024-02-14T09:52:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
