# Reindexing Logstash indices to use new index template

**URL:** <https://discuss.elastic.co/t/reindexing-logstash-indices-to-use-new-index-template/238917>\
**Category:** Elasticsearch\
**Created:** [June 26, 2020, 9:24pm UTC](https://discuss.elastic.co/t/reindexing-logstash-indices-to-use-new-index-template/238917 "2020-06-26T21:24:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vanessa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vanessa/32/66561_2.png) [@vanessa](https://discuss.elastic.co/u/vanessa)\
**Post date:** [June 26, 2020, 9:24pm UTC](https://discuss.elastic.co/t/reindexing-logstash-indices-to-use-new-index-template/238917/1 "2020-06-26T21:24:20Z")

</div>

Hi. We have some existing logstash logs in our elasticsearch cluster. Their pattern is `logstash-imu-logs-*`. We have a template for that pattern, but unfortunately it was missing the mapping for one of our fields. As the docs state, we can't retroactively apply changes we make to the `logstash-imu-logs-*` index template to our indices. So we want to reindex, but not clear on how to do that in that case. We've been looking at the documentation to reindex an existing index to a new index, but what about existing logs to a new index template? We thought perhaps we'd create a new template called `logstash-imu-logs-reindexed-*` with all the required mapping and settings, but now we don't know how to proceed from here.

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [June 26, 2020, 11:55pm UTC](https://discuss.elastic.co/t/reindexing-logstash-indices-to-use-new-index-template/238917/2 "2020-06-26T23:55:47Z")

</div>

Vanessa,  
Depending on type of data you need to employ different strategies. Can you provide more information on the data

1. Are indices append only? or does logstash updates existing log entries?
2. Are you using time based indices? Key characteristic is logstash creates new indices daily/weekly/monthly and older indices do not get updated.
3. If logstash updates docs, do log entries have the last updated timestamp which is updated by logstash at the time of update?

For typical append only and time based indices

1. Update template so future indices will be created with correct mapping
2. Take snapshot of old (non-updatable) indices
3. Create a new empty index logstash-imu-logs- **reindexed-XYZ** for existing index logstash-imu-logs- **XYZ**. Assuming existing template pattern matches the new index name it will have revised mapping. `curl -XPUT http://localhost:9200/logstash-imu-logs-reindexed-XYZ`
4. Use reindex API to reindex [https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html)
5. Verify all data copied. Verify snapshot in step #2 has the old index.
6. Drop the old index
7. Create alias index logstash-imu-logs- **XYZ** for the index logstash-imu-logs- **reindexed-XYZ**
8. Wait for the current index to roll over. Then follow same steps for this index.

---

<div class="post-metadata">

**Author:** ![vanessa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vanessa/32/66561_2.png) [@vanessa](https://discuss.elastic.co/u/vanessa)\
**Post date:** [July 13, 2020, 10:05pm UTC](https://discuss.elastic.co/t/reindexing-logstash-indices-to-use-new-index-template/238917/3 "2020-07-13T22:05:53Z")

</div>

Hi @Vinayak_Sapre - apologies for the very late reply. I was working on some other things. I should mention we are using Elastic Cloud.

1. Yes, indices are append only
2. We have one index per day
3. n/a

We did do something similar to what you described, but found that not all of our indices got reindexed. We also noticed that there were fewer documents in the reindexed indices - but that's probably a separate issue where our Logstash trial and error generated duplicates. Do you know why not all indices would be reindexed? Do the steps you describe have to be done one index at a time?

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [July 13, 2020, 11:26pm UTC](https://discuss.elastic.co/t/reindexing-logstash-indices-to-use-new-index-template/238917/4 "2020-07-13T23:26:09Z")

</div>

@vanessa

> [@vanessa](#):
>
> Do you know why not all indices would be reindexed? Do the steps you describe have to be done one index at a time?

Depending on how much your cluster can handle you can reindex multiple indices in parallel. See Elastic recommendation here [Reindex API | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html#docs-reindex-many-indices)

> [@vanessa](#):
>
> We also noticed that there were fewer documents in the reindexed indices - but that's probably a separate issue where our Logstash trial and error generated duplicates.

If your source has duplicates your destination should have duplicates too. Count should match. Count mismatch indicate error occurred while copying some documents or new documents got added to the source index after reindexing started. Check elasticsearch logs for reindexing errors.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2020, 11:34pm UTC](https://discuss.elastic.co/t/reindexing-logstash-indices-to-use-new-index-template/238917/5 "2020-08-10T23:34:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
