# Pointing index name to alias

**URL:** <https://discuss.elastic.co/t/pointing-index-name-to-alias/171267>\
**Category:** Elasticsearch\
**Created:** [March 7, 2019, 10:12am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267 "2019-03-07T10:12:30Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 7, 2019, 10:12am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/1 "2019-03-07T10:12:30Z")

</div>

Hi,

I would like to point alias name in indexing to update a document in multiple daily indices using logstash with the id of the document. But when i provide the alias name it throws error and when i give index name with wildcard (\*) character no error but the document is not indexed.

Is there any solution to update documents with additional field in multiple indices by passing the id of the document?

---

<div class="post-metadata">

**Author:** ![mjunaidmuzammil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mjunaidmuzammil/32/56910_2.png) [@mjunaidmuzammil](https://discuss.elastic.co/u/mjunaidmuzammil)\
**Post date:** [March 7, 2019, 10:52am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/2 "2019-03-07T10:52:09Z")

</div>

> [@Chelambarasan\_CR](#):
>
> I would like to point alias name in indexing to update a document in multiple daily indices using logstash with the id of the document. But when i provide the alias name it throws error and when i give index name with wildcard (\*) character no error but the document is not indexed.

What is the exact error that you getting? Can you provide more details?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2019, 12:08pm UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/3 "2019-03-07T12:08:11Z")

</div>

You can run update by query on multiple indices but you can't run update document api on multiple indices.

---

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 7, 2019, 6:23pm UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/4 "2019-03-07T18:23:16Z")

</div>

Hi,

How to use update by query in logstash ? I could able to find only update api for logstash.

Should I use http output plugin?

---

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 7, 2019, 6:25pm UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/5 "2019-03-07T18:25:05Z")

</div>

Illegal argument exception: alias has more than 1 indice associated with it.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2019, 7:07pm UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/6 "2019-03-07T19:07:25Z")

</div>

I guess so.  
Is that a frequent operation actually? I thought it was a one time operation.

---

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 8, 2019, 4:39am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/7 "2019-03-08T04:39:17Z")

</div>

Yes it is a frequent update on daily basis for old records

---

<div class="post-metadata">

**Author:** ![mjunaidmuzammil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mjunaidmuzammil/32/56910_2.png) [@mjunaidmuzammil](https://discuss.elastic.co/u/mjunaidmuzammil)\
**Post date:** [March 8, 2019, 4:41am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/8 "2019-03-08T04:41:56Z")

</div>

@Chelambarasan_CR Can you share output of \_aliases for your index. I believe you have a single alias connected to multiple physical indices.

---

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 8, 2019, 6:27am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/9 "2019-03-08T06:27:43Z")

</div>

output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {

```
	hosts => ["localhost:9200"] 

	index => "alias1"
	document_type => "data"
	action => "update"
	document_id => "1"

```

}  
}

---

<div class="post-metadata">

**Author:** ![mjunaidmuzammil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mjunaidmuzammil/32/56910_2.png) [@mjunaidmuzammil](https://discuss.elastic.co/u/mjunaidmuzammil)\
**Post date:** [March 8, 2019, 7:21am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/10 "2019-03-08T07:21:35Z")

</div>

Can you share the output from below mentioned endpoint?

`curl -XGET localhost:9200/_aliases?pretty`

---

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 8, 2019, 10:04am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/11 "2019-03-08T10:04:03Z")

</div>

> [@mjunaidmuzammil](#):
>
> GET localhost:9200/\_aliases?pretty

{  
".kibana": {  
"aliases": {}  
},

"test2": {  
"aliases": {  
"aliastest": {}  
}  
},  
"test1": {  
"aliases": {  
"aliastest": {}  
}  
}  
}

aliastest is the alias name

---

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 8, 2019, 10:07am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/12 "2019-03-08T10:07:18Z")

</div>

output {  
stdout {  
codec =\> rubydebug  
}  
http {

```
	url => "http:localhost:9200/test1/_update_by_query?q=id:1"
	http_method => "post"
	format => "json"

```

}  
}

Tried this but getting error"Could not able to fetch the url."

Just want to confirm whether the http url for update by query is right?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 8, 2019, 10:18am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/13 "2019-03-08T10:18:47Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Here the URL seems wrong to me. It should be something like:

```auto
url => "http://localhost:9200/test1/_update_by_query?q=id:1"

```

or

```auto
url => "localhost:9200/test1/_update_by_query?q=id:1"

```

---

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 8, 2019, 10:27am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/14 "2019-03-08T10:27:28Z")

</div>

Getting this error on removing http`

`[HTTP Output Failure] Could not fetch URL {:url=>"localhost:9200/test1/_update_by_query?q=_id:1",`

"URI does not specify a valid host name: localhost:9200/test1/\_update\_by\_query?q=\_id:1", :class=\>"Manticore::ClientProtocolException", :backtrace=\>nil,`

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 8, 2019, 10:43am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/15 "2019-03-08T10:43:11Z")

</div>

What about:

```auto
url => "http://localhost:9200/test1/_update_by_query?q=id:1"

```

?

---

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 8, 2019, 10:43am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/16 "2019-03-08T10:43:53Z")

</div>

```
[2019-03-08T16:17:34,642][ERROR][logstash.outputs.http] [HTTP Output Failure] Encountered non-2xx HTTP code 400 {:response_code=>400, :url=>"http://localhos
, :will_retry=>false}by_query?q=_id:1", :event=>2019-03-08T10:47:33.712Z CHNMCT123553L 1,samplexml
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 8, 2019, 10:57am UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/17 "2019-03-08T10:57:16Z")

</div>

The response is not complete.

Anyway, I'd recommend asking this in #logstash forum instead.

---

<div class="post-metadata">

**Author:** ![Chelambarasan\_CR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chelambarasan_cr/32/62592_2.png) [@Chelambarasan\_CR](https://discuss.elastic.co/u/Chelambarasan_CR)\
**Post date:** [March 8, 2019, 12:25pm UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/18 "2019-03-08T12:25:20Z")

</div>

ok. opening a thread in logstash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2019, 12:25pm UTC](https://discuss.elastic.co/t/pointing-index-name-to-alias/171267/19 "2019-04-05T12:25:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
