# Problem updating counter on elastic document

**URL:** <https://discuss.elastic.co/t/problem-updating-counter-on-elastic-document/231722>\
**Category:** Logstash\
**Created:** [May 8, 2020, 12:41pm UTC](https://discuss.elastic.co/t/problem-updating-counter-on-elastic-document/231722 "2020-05-08T12:41:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gpolini](https://avatars.discourse-cdn.com/v4/letter/g/e9a140/32.png) [@gpolini](https://discuss.elastic.co/u/gpolini)\
**Post date:** [May 8, 2020, 12:41pm UTC](https://discuss.elastic.co/t/problem-updating-counter-on-elastic-document/231722/1 "2020-05-08T12:41:18Z")

</div>

Hi  
I populate ELK database reading log files by logstash.  
Each document is populated using many log rows, each one inserts specific fileds.

When logstash read a specific action, it update a boolean filed "action\_done" to true and it works perfectly.

Now, I'd like to have another field that counts number of occurrences of action.  
So I write a script in elasticsearch output in this way:

```auto
      if [action] == 'my action' {
        elasticsearch {
          hosts => ["my_host"]
          user => "logstash_user"
          password => "logstash_pwd"
          ssl => false
          manage_template => true
          template_overwrite => true
          template_name => "mytemplate"
          template => "my-template.json"
          id => "specific_output_id"
          index => "my_index"
          action => "update"
          doc_as_upsert => true
          document_id => "my_id"
          script_type => "inline"
          script_lang => ""
          script => "if (ctx._source.action_counter == null) { ctx._source.action_counter = 1 } else { ctx._source.action_counter++ }"
        }
      } else {
        elasticsearch {
          hosts => ["my_host"]
          user => "logstash_user"
          password => "logstash_pwd"
          ssl => false
          manage_template => true
          template_overwrite => true
          template_name => "mytemplate"
          template => "my-template.json"
          id => "my_output_id"
          index => "my_index"
          action => "update"
          doc_as_upsert => true
          document_id => "my_id"
        }
      }

```

With this new output configuration, action\_counter is almost always not present in the documents and it never has the correct value.  
Also action\_done field is not always set to true.

Where is the error?  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![gpolini](https://avatars.discourse-cdn.com/v4/letter/g/e9a140/32.png) [@gpolini](https://discuss.elastic.co/u/gpolini)\
**Post date:** [May 8, 2020, 1:39pm UTC](https://discuss.elastic.co/t/problem-updating-counter-on-elastic-document/231722/2 "2020-05-08T13:39:28Z")

</div>

Specifically, in a certain time interval there should be 435 documents with action\_done field set to true and action\_counter field greater than 0.  
I have 331 documents with action\_counter field that has the right value of occurrences and action\_done field is set to false.  
I have 95 documents with action\_done field set to true and action\_counter field is not present.  
I have only 9 documents where both action\_done and action\_counter are present and in these documents action\_counter fileds are not correct.

Other fileds that I insert in documents when [action] == "my\_action", are present only if action\_done field is set to true (in 104 documents).

---

<div class="post-metadata">

**Author:** ![gpolini](https://avatars.discourse-cdn.com/v4/letter/g/e9a140/32.png) [@gpolini](https://discuss.elastic.co/u/gpolini)\
**Post date:** [May 8, 2020, 1:44pm UTC](https://discuss.elastic.co/t/problem-updating-counter-on-elastic-document/231722/3 "2020-05-08T13:44:27Z")

</div>

I set action\_done to true in logstash filter in this way:

```auto
if [action] == 'my_action' {
  mutate {
    replace => {
      "[action_done]" => true
    }
    convert => {
       "[action_done]" => "boolean"
    }
  }
}

```

In my-template.json, I set the action\_count field type in this way:

```auto
...
  "mappings": {
    "properties": {
      "action_counter": {
        "type": "integer"
      }
    }
  }
...

```

---

<div class="post-metadata">

**Author:** ![gpolini](https://avatars.discourse-cdn.com/v4/letter/g/e9a140/32.png) [@gpolini](https://discuss.elastic.co/u/gpolini)\
**Post date:** [May 12, 2020, 2:14pm UTC](https://discuss.elastic.co/t/problem-updating-counter-on-elastic-document/231722/4 "2020-05-12T14:14:45Z")

</div>

I changed the script syntax to:

```auto
script => "if (ctx._source['action_counter'] == null) { ctx._source['action_counter'] = 1 } else { ctx._source.action_counter++ }"

```

Same result...

---

<div class="post-metadata">

**Author:** ![gpolini](https://avatars.discourse-cdn.com/v4/letter/g/e9a140/32.png) [@gpolini](https://discuss.elastic.co/u/gpolini)\
**Post date:** [May 20, 2020, 3:48pm UTC](https://discuss.elastic.co/t/problem-updating-counter-on-elastic-document/231722/5 "2020-05-20T15:48:43Z")

</div>

Resolved with two changes:

1. I delete the "else" from logstash output, so in case with [action] == 'my action'  
elatsicsearch-output is performed twice.

2. In the my\_action-elasticsearch-output, I added the parameter:

```auto
retry_on_conflict => 10

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2020, 3:48pm UTC](https://discuss.elastic.co/t/problem-updating-counter-on-elastic-document/231722/6 "2020-06-17T15:48:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
