# Query field value to reindex existing indexes

**URL:** <https://discuss.elastic.co/t/query-field-value-to-reindex-existing-indexes/307367>\
**Category:** Logstash\
**Created:** [June 16, 2022, 9:07am UTC](https://discuss.elastic.co/t/query-field-value-to-reindex-existing-indexes/307367 "2022-06-16T09:07:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dapmI](https://avatars.discourse-cdn.com/v4/letter/d/96bed5/32.png) [@dapmI](https://discuss.elastic.co/u/dapmI)\
**Post date:** [June 16, 2022, 9:07am UTC](https://discuss.elastic.co/t/query-field-value-to-reindex-existing-indexes/307367/1 "2022-06-16T09:07:52Z")

</div>

Hello,

I'm trying to achieve a complex action where we currently have a common index filebeat-%{beat version}-%{YY-mm-dd} type of index with multiple `log.file.path` different. The idea is to have them in other index depending on this log.file.path.

Ex:  
From:

```auto
filebeat-7.17.1-2022.01
      log.file.path: /var/log/log1
      log.file.path: /var/log/log2
      log.file.path: /var/log/log3

```

To:

```auto
filebeat-log1-2022.01
      log.file.path: /var/log/log1
filebeat-log2-2022.01
      log.file.path: /var/log/log2
filebeat-log3-2022.01
      log.file.path: /var/log/log3

```

Here I tried with the following setup in logstash to try

```auto
input {
  elasticsearch {
    hosts => "http://localhost:9200"
    index => "filebeat-7*"
    query => '{
      "query":{
          "match":{
              "log.file.path" : "/var/log/log1"
          }
        }
    }'
    size => 10000
    scroll => "20s"
  }
}

output {
  elasticsearch {
      hosts => "http://localhost:9200"
      index => "filebeat-log1-%{+YYYY.MM}"
    }
}

```

```auto
input{
  elasticsearch {
    hosts => ["http://localhost:9200"]
  }
}

filter {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => ["filebeat-7*"]
    query => "log.file.path:/var/log/log1"
  }
}

output {
  elasticsearch {
      hosts => "http://localhost:9200"
      index => "filebeat-log1-%{+YYYY.MM}"
    }
}

```

In my first setup, index are created correctly for other log comes into picture and in the second case, nothing is done.

Do you have any suggestion on this topic ?

Thank you in advance for your help.

Best regards,  
Benjamin

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2022, 9:08am UTC](https://discuss.elastic.co/t/query-field-value-to-reindex-existing-indexes/307367/2 "2022-07-14T09:08:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
