# Update\_by\_query and

**URL:** <https://discuss.elastic.co/t/update-by-query-and/317020>\
**Category:** Logstash\
**Tags:** painless\
**Created:** [October 19, 2022, 3:13pm UTC](https://discuss.elastic.co/t/update-by-query-and/317020 "2022-10-19T15:13:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![reed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reed/32/122863_2.png) [@reed](https://discuss.elastic.co/u/reed)\
**Post date:** [October 19, 2022, 3:13pm UTC](https://discuss.elastic.co/t/update-by-query-and/317020/1 "2022-10-19T15:13:48Z")

</div>

Hi all,

I have a problem with update\_by\_query in a pipeline but I noticed that the same query used into dev tools works fine:

PIPELINE

```auto
	http { url => "http://crsinsightdev.icc.crifnet.com:9200/loyd-crs_insight_s1_agos-processcode-*-main/_update_by_query"
			headers => ["Authorization", "Basic ZWxhc3RpYzplbGFzdGlj"]
			http_method => "post"
			format => "message"
			content_type	=> "application/json"
			message => '{
                                      "script": {
                                        "source": "ctx._source.flg_old_data = params.flg_old_data",
                                        "lang": "painless",
                                        "params": {
                                          "flg_old_data": "Y"
                                        }
                                      },
                                      "query": {
                                        "bool": {
                                          "must": [],
                                          "filter": [
                                            {
                                              "bool": {
                                                "filter": [
                                                  { "bool": { "should": [{ "match_phrase": { "h.req-id": "%{req-id}" } }] } },
                                                  { "bool": { "should": [{ "match_phrase": { "h.process-code": "%{process-code}" } }] } },
                                                  { "bool": { "should": [{ "match_phrase": { "fields.s1env": "%{s1env}" } }] } },
                                                  { "bool": { "should": [{ "range": { "h.req-timestamp": { "lt": "%{req-timestamp}" } } }] } }
                                                ]
                                              }
                                            }
                                          ],
                                          "should": [],
                                          "must_not": []
                                        }
                                      }
                                    }
                                 }'
		}

```

DEV TOOLS

```auto
POST /loyd-crs_insight_s1_agos-processcode-panda_check-main/_update_by_query
{
  "script": {
    "source": "ctx._source.flg_old_data = params.flg_old_data",
    "lang": "painless",
    "params": {
      "flg_old_data": "Y"
    }
  },
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "bool": {
            "filter": [
              { "bool": { "should": [{ "match_phrase": { "h.req-id": "Test3GrpA" } }] } },
              { "bool": { "should": [{ "match_phrase": { "h.process-code": "panda_check" } }] } },
              { "bool": { "should": [{ "match_phrase": { "fields.s1env": "design" } }] } },
              { "bool": { "should": [{ "range": { "h.req-timestamp": { "lt": "1663665372100" } } }] } }
            ]
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

```

\*\*I have an index similar to this:\*\*I need to implement AND condition with all fields.

My index is similar to this:

```auto
req-id process-code req-timestamp s1env flg_old_data
----------------------------------------------------------------
Test3GrpA panda_check 1663665372200 design   
Test3GrpA panda_check 1663665372200 design   
Test3GrpA panda_check 1663665372200 design   
Test3GrpA panda_check 1663665372200 design   
Test3GrpA panda_check 1663665372200 design   
Test3GrpA panda_check 1663665372100 design Y
Test3GrpA panda_check 1663665372100 design Y
Test3GrpA panda_check 1663665372100 design Y
Test3GrpA panda_check 1663665372100 design Y
Test3GrpA panda_check 1663665372100 design Y

```

my query has to flags all documents with "req-timestamp" less then the current one, and it works, but when I load other documents with different "s1env" = "production" and "req-timestamp" = 1663665372100 even the "req-timestamp" = 1663665372200 is updated with "flg\_old\_data" = Y.

But if I execute the same update indicated above the update works fine and I don't understand why.

Can someone help me with this?

Thanks in advance.  
D.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2022, 3:14pm UTC](https://discuss.elastic.co/t/update-by-query-and/317020/2 "2022-11-16T15:14:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
