# Snow API to avoid duplicates

**URL:** <https://discuss.elastic.co/t/snow-api-to-avoid-duplicates/213074>\
**Category:** Logstash\
**Created:** [December 26, 2019, 12:23pm UTC](https://discuss.elastic.co/t/snow-api-to-avoid-duplicates/213074 "2019-12-26T12:23:11Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [December 27, 2019, 4:53pm UTC](https://discuss.elastic.co/t/snow-api-to-avoid-duplicates/213074/3 "2019-12-27T16:53:11Z")

</div>

Hi, you can check previous issues with servicenow in the forum:

In this thread, there is a JSON response with a `records` field that contains an array of entries. So json input codec and split filter are used to get the information of each entry.

> [@ServiceNow Incident Table data in ELK](https://discuss.elastic.co/t/servicenow-incident-table-data-in-elk/130216/13):
>
> Thank you very much @magnusbaeck for you guidance.....i'll go through docs. Thanks Gautham

Maybe you can work on something similar for your case, although your response seems XML instead of JSON.

On the other hand, your configuration of

```
action=>update
document_id => "%{number}"
doc_as_upsert =>true

```

will update the existing document if a new one is indexed with the same `number`

- New fields (not present in the existing document) will be added to the same document;
- Existing fields will have their values updated with the latest ones.

---

_[View the full topic](https://discuss.elastic.co/t/snow-api-to-avoid-duplicates/213074)._
