# Posting document to alias instead of index

**URL:** <https://discuss.elastic.co/t/posting-document-to-alias-instead-of-index/203125>\
**Category:** Logstash\
**Created:** [October 10, 2019, 11:46pm UTC](https://discuss.elastic.co/t/posting-document-to-alias-instead-of-index/203125 "2019-10-10T23:46:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [October 10, 2019, 11:46pm UTC](https://discuss.elastic.co/t/posting-document-to-alias-instead-of-index/203125/1 "2019-10-10T23:46:51Z")

</div>

I'm not quite sure why this isn't working but I'm trying to post to an alias instead of an index and it's not working. I have indexes called  
`index-september` & `index-october` and they are both under the alias `index`. When I put my logstash `index => "index"` it fails but when I put `index => "index-september"` it succeeds. Can I post to an alias?

I'm doing post processing on data in my indices and I'd like the documents to reroute via their \_id to the correct index. I'm pulling them in via the elasticsearch input plugin. Any suggestion on how to do this?

Thanks!

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 11, 2019, 12:44am UTC](https://discuss.elastic.co/t/posting-document-to-alias-instead-of-index/203125/2 "2019-10-11T00:44:46Z")

</div>

I think you have to set is\_write\_alias: true on one index referenced by the alias for writing, even if there is only one.

---

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [October 11, 2019, 12:52am UTC](https://discuss.elastic.co/t/posting-document-to-alias-instead-of-index/203125/3 "2019-10-11T00:52:34Z")

</div>

Will it automatically send events that get pulled in from index-september to index-september when I input and output to elasticsearch via an alias?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 11, 2019, 1:16am UTC](https://discuss.elastic.co/t/posting-document-to-alias-instead-of-index/203125/4 "2019-10-11T01:16:59Z")

</div>

If you had indices index-january thru index-september (the is\_write\_alias: true). Read via the alias "index" would read from all of them, just like using a wildcard "index-\*". Writes to "index" would go to index-september. I think if you post directly to any, (index-june) you could write to them (unless set to read only).

The idea of rollover is at 01/01/2019 00:00:00 you create index-october and set is\_write\_alias: true, writes to "index" go to the new month. (I don't think the rollover api or ILM can do rollover at a specific time however, they do it by size, age or # events.)

---

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [October 11, 2019, 5:00am UTC](https://discuss.elastic.co/t/posting-document-to-alias-instead-of-index/203125/5 "2019-10-11T05:00:15Z")

</div>

Hmm okay thanks for your help! I think I'll pull the metadata \_index and see if I can post to it's index like that! 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2019, 5:00am UTC](https://discuss.elastic.co/t/posting-document-to-alias-instead-of-index/203125/6 "2019-11-08T05:00:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
