Please also share some code snippet you have right now for us to come with some suggestions / improvements.
From what you have written and my understanding is:
you have logs coming to your system and you somehow parse them
you want to have a field lookup for the past value if existed and do some action
You can accomplish that by placing in a filter section elasticsearch {}, execute a query and work with the return value. Make sure that you control the ID of the data insertion as well that could allow you to do the proper data lookup.
Side note:
Could you put next time at least minimal effort into writing properly your question that follows some logical order? I am not a English native speaker but at least obeying some basic grammar rules would be great from respect reasons.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.