# Reindexing to apply logic to existing data?

**URL:** <https://discuss.elastic.co/t/reindexing-to-apply-logic-to-existing-data/177921>\
**Category:** Elasticsearch\
**Created:** [April 23, 2019, 1:49am UTC](https://discuss.elastic.co/t/reindexing-to-apply-logic-to-existing-data/177921 "2019-04-23T01:49:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![T\_way](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/t_way/32/56636_2.png) [@T\_way](https://discuss.elastic.co/u/T_way)\
**Post date:** [April 23, 2019, 1:49am UTC](https://discuss.elastic.co/t/reindexing-to-apply-logic-to-existing-data/177921/1 "2019-04-23T01:49:31Z")

</div>

Hi experts, I'm indexing Netflow data via logstash that does the logic to create new fields.  
However If the data already exists in ES is there a way to reindex it in order to create these new fields based on the same conditions as Logstash would during data collection?  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 23, 2019, 3:09am UTC](https://discuss.elastic.co/t/reindexing-to-apply-logic-to-existing-data/177921/2 "2019-04-23T03:09:48Z")

</div>

Yep. You can use either the reindex API, or use Logstash to do this.

---

<div class="post-metadata">

**Author:** ![T\_way](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/t_way/32/56636_2.png) [@T\_way](https://discuss.elastic.co/u/T_way)\
**Post date:** [April 23, 2019, 2:01pm UTC](https://discuss.elastic.co/t/reindexing-to-apply-logic-to-existing-data/177921/3 "2019-04-23T14:01:01Z")

</div>

Thanks Mark for your reply. Could you please clarify how to "replay" the existing data and apply a logic to add new fields via the reindex API? my basic understanding is it only copies from existing to target index.  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 25, 2019, 11:59pm UTC](https://discuss.elastic.co/t/reindexing-to-apply-logic-to-existing-data/177921/4 "2019-04-25T23:59:52Z")

</div>

You can use a script with reindex, but it might not be worth the hassle. Just use Logstash again.

---

<div class="post-metadata">

**Author:** ![T\_way](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/t_way/32/56636_2.png) [@T\_way](https://discuss.elastic.co/u/T_way)\
**Post date:** [April 26, 2019, 2:26pm UTC](https://discuss.elastic.co/t/reindexing-to-apply-logic-to-existing-data/177921/5 "2019-04-26T14:26:52Z")

</div>

Thanks Mark!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2019, 2:34pm UTC](https://discuss.elastic.co/t/reindexing-to-apply-logic-to-existing-data/177921/6 "2019-05-24T14:34:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
