# Scripted\_upsert not working when logtash looses connection to ES and reconnects

**URL:** <https://discuss.elastic.co/t/scripted-upsert-not-working-when-logtash-looses-connection-to-es-and-reconnects/260651>\
**Category:** Logstash\
**Tags:** painless\
**Created:** [January 10, 2021, 4:27pm UTC](https://discuss.elastic.co/t/scripted-upsert-not-working-when-logtash-looses-connection-to-es-and-reconnects/260651 "2021-01-10T16:27:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pachidermus](https://avatars.discourse-cdn.com/v4/letter/p/8dc957/32.png) [@Pachidermus](https://discuss.elastic.co/u/Pachidermus)\
**Post date:** [January 10, 2021, 4:27pm UTC](https://discuss.elastic.co/t/scripted-upsert-not-working-when-logtash-looses-connection-to-es-and-reconnects/260651/1 "2021-01-10T16:27:01Z")

</div>

I am experiencing the exact same problem as here:

> [@Scripted Upsert with Logstash ES Output Plugin - overwrites array data with latest event instead of update on reconnection](https://discuss.elastic.co/t/scripted-upsert-with-logstash-es-output-plugin-overwrites-array-data-with-latest-event-instead-of-update-on-reconnection/232547):
>
> Scenario: We are adding object to array via logstash to elasticsearch using logstash's ES output plugin. Both are on version 6.8. It is a scripted upsert using stored script on Elasticsearch and here is the stored script on ES: "add\_script" : { "lang" : "painless", "source" : "if (ctx.\_source.tags != null ) { ctx.\_source.tags.add(params.event.get('tags')[0])} else {ctx.\_source.tags = params.event.get('tags')} " } Logstash output is: output { elasticse…

The setup is very basic. We are using the ES output plugin with a basic logic:

```auto
output {
 if [@metadata][scripted_upsert] == "true" {
    elasticsearch {
      ...
      scripted_upsert => true
      script => "custom_update"
    }
  }
}

```

and a basic painless script.

Problem: if logstash looses connection to ES for whatever reason (error\_message=\>"Elasticsearch Unreachable") then on reconnection ("Restored connection to ES instance"), the scripted\_upsert is ignored and a classic upsert is executed instead, which is not what we want.

Any idea why ? Last hypothesis I have to check is either the @metadata context is lost.

Edit: seems more a logstash elastic output plugin bug ?

---

<div class="post-metadata">

**Author:** ![Pachidermus](https://avatars.discourse-cdn.com/v4/letter/p/8dc957/32.png) [@Pachidermus](https://discuss.elastic.co/u/Pachidermus)\
**Post date:** [January 10, 2021, 6:40pm UTC](https://discuss.elastic.co/t/scripted-upsert-not-working-when-logtash-looses-connection-to-es-and-reconnects/260651/2 "2021-01-10T18:40:18Z")

</div>

This bug seems to be fixed by this pull request which has never been accepted:

> <https://github.com/logstash-plugins/logstash-output-elasticsearch/pull/800>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2021, 6:40pm UTC](https://discuss.elastic.co/t/scripted-upsert-not-working-when-logtash-looses-connection-to-es-and-reconnects/260651/3 "2021-02-07T18:40:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
