# Setting the Document ID

**URL:** <https://discuss.elastic.co/t/setting-the-document-id/154913>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 31, 2018, 6:41pm UTC](https://discuss.elastic.co/t/setting-the-document-id/154913 "2018-10-31T18:41:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Garry](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@Garry](https://discuss.elastic.co/u/Garry)\
**Post date:** [October 31, 2018, 6:41pm UTC](https://discuss.elastic.co/t/setting-the-document-id/154913/1 "2018-10-31T18:41:16Z")

</div>

I am looking to set the document id while ingesting data though filebeats.  
How would I achieve this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 31, 2018, 7:11pm UTC](https://discuss.elastic.co/t/setting-the-document-id/154913/2 "2018-10-31T19:11:39Z")

</div>

I think you would need to set the ID either in Logstash or in an ingest pipeline.

---

<div class="post-metadata">

**Author:** ![Garry](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@Garry](https://discuss.elastic.co/u/Garry)\
**Post date:** [October 31, 2018, 7:24pm UTC](https://discuss.elastic.co/t/setting-the-document-id/154913/3 "2018-10-31T19:24:36Z")

</div>

I'm looking to use the Filebeat\>ES route and miss out on Logstash

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 31, 2018, 7:27pm UTC](https://discuss.elastic.co/t/setting-the-document-id/154913/4 "2018-10-31T19:27:06Z")

</div>

Then you will probably need to use an ingest pipeline.

---

<div class="post-metadata">

**Author:** ![Garry](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@Garry](https://discuss.elastic.co/u/Garry)\
**Post date:** [November 2, 2018, 7:27am UTC](https://discuss.elastic.co/t/setting-the-document-id/154913/5 "2018-11-02T07:27:35Z")

</div>

Do you know how to, or can you point me in the right direction regarding doing this in a pipeline.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 2, 2018, 7:47am UTC](https://discuss.elastic.co/t/setting-the-document-id/154913/6 "2018-11-02T07:47:22Z")

</div>

I had a look at the fields available in the [ingest processor context](https://www.elastic.co/guide/en/elasticsearch/painless/6.4/painless-ingest-processor-context.html), and it seems the `_id` field might not be exposed (although It is exposed when you [reindex](https://www.elastic.co/guide/en/elasticsearch/painless/6.4/painless-reindex-context.html)). This might mean you will need to use Logstash.

Let's see if someone more familiar with Painless internals can comment on this.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 2, 2018, 8:17am UTC](https://discuss.elastic.co/t/setting-the-document-id/154913/7 "2018-11-02T08:17:04Z")

</div>

It seems it should be [possible to do it in a pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/accessing-data-in-pipelines.html#accessing-metadata-fields).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2018, 8:26am UTC](https://discuss.elastic.co/t/setting-the-document-id/154913/8 "2018-11-30T08:26:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
