# Parent/child with logstash 2.1.1

**URL:** <https://discuss.elastic.co/t/parent-child-with-logstash-2-1-1/37769>\
**Category:** Logstash\
**Created:** [December 22, 2015, 3:37pm UTC](https://discuss.elastic.co/t/parent-child-with-logstash-2-1-1/37769 "2015-12-22T15:37:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![fchantrel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fchantrel/32/6204_2.png) [@fchantrel](https://discuss.elastic.co/u/fchantrel)\
**Post date:** [December 22, 2015, 3:37pm UTC](https://discuss.elastic.co/t/parent-child-with-logstash-2-1-1/37769/1 "2015-12-22T15:37:47Z")

</div>

Hi,  
i've tried to index child documents with logstash but it doesn't work since I use the 2.1.1 version.  
Here is my config :

'''  
...  
filter {  
mutate {  
add\_field =\> { "\_parent" =\> "%{\_id}" }  
remove\_field =\> ["@timestamp","message","@version","host","path"]  
convert =\> ["goals", "integer"]  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9202"]  
index =\> "myindex"  
document\_type =\> "mychildtype"  
document\_id =\> "%{\_id}"  
}  
stdout { codec =\> rubydebug }  
}  
'''

I've got 4 shards and it works for about 25% of my docs.  
Somebody told me that "When you use routing the type and id no longer control which shard gets  
the document. Instead Elasticsearch just hashes the routing. Parent/child just uses the parent as the routing."  
So what is the solution to index child documents with logstash ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 22, 2015, 8:14pm UTC](https://discuss.elastic.co/t/parent-child-with-logstash-2-1-1/37769/2 "2015-12-22T20:14:54Z")

</div>

You can't do P/C with Logstash.  
Changes in ES 2.X mean that you need to provide the parent ID in the URL, you cannot just extract the parent value from a field in the document.

---

<div class="post-metadata">

**Author:** ![fchantrel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fchantrel/32/6204_2.png) [@fchantrel](https://discuss.elastic.co/u/fchantrel)\
**Post date:** [December 25, 2015, 7:29pm UTC](https://discuss.elastic.co/t/parent-child-with-logstash-2-1-1/37769/3 "2015-12-25T19:29:14Z")

</div>

Are you sure ?  
I understood that it was possible since version 2.1.1 with the release notes who pointed to this : [https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/297](https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/297)

Thanks.

---

<div class="post-metadata">

**Author:** ![alaviamir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alaviamir/32/10167_2.png) [@alaviamir](https://discuss.elastic.co/u/alaviamir)\
**Post date:** [June 28, 2016, 7:33pm UTC](https://discuss.elastic.co/t/parent-child-with-logstash-2-1-1/37769/4 "2016-06-28T19:33:58Z")

</div>

Any luck with this?

---

<div class="post-metadata">

**Author:** ![fchantrel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fchantrel/32/6204_2.png) [@fchantrel](https://discuss.elastic.co/u/fchantrel)\
**Post date:** [July 7, 2016, 8:48pm UTC](https://discuss.elastic.co/t/parent-child-with-logstash-2-1-1/37769/5 "2016-07-07T20:48:59Z")

</div>

No, finally i decided to replace child documents with nested.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:49am UTC](https://discuss.elastic.co/t/parent-child-with-logstash-2-1-1/37769/6 "2017-07-06T04:49:03Z")

</div>


