# Providing document\_id in function beat for decode\_json\_fields results in effectively no updates to any records

**URL:** <https://discuss.elastic.co/t/providing-document-id-in-function-beat-for-decode-json-fields-results-in-effectively-no-updates-to-any-records/263434>\
**Category:** Beats\
**Tags:** functionbeat\
**Created:** [February 5, 2021, 4:15pm UTC](https://discuss.elastic.co/t/providing-document-id-in-function-beat-for-decode-json-fields-results-in-effectively-no-updates-to-any-records/263434 "2021-02-05T16:15:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ryantomaselli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryantomaselli/32/83397_2.png) [@ryantomaselli](https://discuss.elastic.co/u/ryantomaselli)\
**Post date:** [February 5, 2021, 4:15pm UTC](https://discuss.elastic.co/t/providing-document-id-in-function-beat-for-decode-json-fields-results-in-effectively-no-updates-to-any-records/263434/1 "2021-02-05T16:15:34Z")

</div>

Hey guys;

I'm processing records from DynamoDB via a function beat and it's working great, if I specify the source record as the "document\_id" for the "decode\_json\_fields" process Elastic correctly uses this as the ID for the resulting document in ES.

But what I notice is that when that same record in the source database is updated and it passes through the function beat again ES doesn't seem to be doing an upsert. I don't get a dupe record which is good, but ES doesn't reflect the updated fields.

Any pointers greatly appreciated.

Thanks!

Reference:

> **[Decode JSON fields | Functionbeat Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/beats/functionbeat/current/decode-json-fields.html)**

---

<div class="post-metadata">

**Author:** ![ryantomaselli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryantomaselli/32/83397_2.png) [@ryantomaselli](https://discuss.elastic.co/u/ryantomaselli)\
**Post date:** [February 6, 2021, 2:34am UTC](https://discuss.elastic.co/t/providing-document-id-in-function-beat-for-decode-json-fields-results-in-effectively-no-updates-to-any-records/263434/2 "2021-02-06T02:34:37Z")

</div>

Found this old post which sounds relevant.

> <https://stackoverflow.com/questions/43034255/can-beats-update-existing-documents-in-elasticsearch>

"No, this is not something that Beats were intended to accomplish. Enrichment like you describe is one of the things that Logstash can help with."

---

<div class="post-metadata">

**Author:** ![ryantomaselli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryantomaselli/32/83397_2.png) [@ryantomaselli](https://discuss.elastic.co/u/ryantomaselli)\
**Post date:** [February 6, 2021, 10:00pm UTC](https://discuss.elastic.co/t/providing-document-id-in-function-beat-for-decode-json-fields-results-in-effectively-no-updates-to-any-records/263434/3 "2021-02-06T22:00:41Z")

</div>

> [@Functionbeat does not update documents with existing \_id](https://discuss.elastic.co/t/functionbeat-does-not-update-documents-with-existing-id/252901):
>
> Hello, I am currently deploying Functionbeat configured to accept events from an SQS queue. The goal is to use a processor/ingest pipeline to extract and set \_id from fields in the incoming messages. Documents with existing \_id do not appear to be pushed from functionbeat at all. I have attempted to isolate the behavior with the below steps: Write message to aws sqs queue i.e. aws sqs send-message --queue-url \<queue\_url\> --message-body '{ "val": "foo", }' --message-group-id f1 --message-de…

Hmmm looking like this is either a bug or just not supported. Seems like it should be a feature. What's the point of being able specify the id if it means the record can never recieve updates.

---

<div class="post-metadata">

**Author:** ![ryantomaselli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryantomaselli/32/83397_2.png) [@ryantomaselli](https://discuss.elastic.co/u/ryantomaselli)\
**Post date:** [February 9, 2021, 3:46pm UTC](https://discuss.elastic.co/t/providing-document-id-in-function-beat-for-decode-json-fields-results-in-effectively-no-updates-to-any-records/263434/4 "2021-02-09T15:46:49Z")

</div>

For anyone out there that has the same need: that being needing to do upserts on the index (by being able to control the document id).

The official word is that this is not supported by Function Beat. In order to do this one needs to either use Logstash or write to ES directly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2021, 5:47pm UTC](https://discuss.elastic.co/t/providing-document-id-in-function-beat-for-decode-json-fields-results-in-effectively-no-updates-to-any-records/263434/5 "2021-03-09T17:47:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
