# Output: specify document id \*or\* allow elasticsearch to pick

**URL:** <https://discuss.elastic.co/t/output-specify-document-id-or-allow-elasticsearch-to-pick/221486>\
**Category:** Logstash\
**Created:** [February 28, 2020, 8:26pm UTC](https://discuss.elastic.co/t/output-specify-document-id-or-allow-elasticsearch-to-pick/221486 "2020-02-28T20:26:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)\
**Post date:** [February 28, 2020, 8:26pm UTC](https://discuss.elastic.co/t/output-specify-document-id-or-allow-elasticsearch-to-pick/221486/1 "2020-02-28T20:26:29Z")

</div>

Sometimes on injest we have an `id` we want to keep as the document id:

```auto
    if [trace_id] {
      mutate {
        copy => { "trace_id" => "[@metadata][document_id]" }
        remove_field => "trace_id"
      }
    }

```

so we specify as an output filter (for example):

```auto
  if [type] == "bbq" {
    elasticsearch {
      id => "bbq"
      hosts => ["elasticsearch-1", "elasticsearch-2", "elasticsearch-3"]
      index => "bbq-%{+YYYY.MM.dd}"
      document_id => "%{[@metadata][document_id]}"
    }
  }

```

And this works great, but there are certain logs generated where we do not have a `trace_id` and so want elastic to generate its own document ID. But if `[@metadata][document_id]` was not specified previously, we get a document in elastic with the literal text `[@metadata][document_id]` as its document ID.

Possible solutions to this:

- generate a document ID ourselves if not already specified (I don't like this as elastic should be handling this)
- have two separate output filters (I do not like the duplication of doing so)

Is there a better way of handling this? What is the best pattern?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2020, 8:26pm UTC](https://discuss.elastic.co/t/output-specify-document-id-or-allow-elasticsearch-to-pick/221486/2 "2020-03-27T20:26:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
