# Update by query using two indices

**URL:** <https://discuss.elastic.co/t/update-by-query-using-two-indices/107554>\
**Category:** Elasticsearch\
**Created:** [November 14, 2017, 1:34pm UTC](https://discuss.elastic.co/t/update-by-query-using-two-indices/107554 "2017-11-14T13:34:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [November 14, 2017, 1:34pm UTC](https://discuss.elastic.co/t/update-by-query-using-two-indices/107554/1 "2017-11-14T13:34:23Z")

</div>

I have a index named "netdata" and the document looks likes this.

```
  {
    "_index": "netdata",
    "_type": "logs",
    "_id": "AV-6k3aG0ecAB0dXdmTW",
    "_score": 1,
    "_source": {
        "Location": "Bangalore",
      "cpu.cpu14.idle": 99.53465,
      "Vendor": "TeleDNA",
     "cpu.cpu15.idle": 97.9726967,
      "cpu.cpu11.idle": 96.5880863,
      "Date": 1510663664939,
      "HOST": "10.225.253.137",
      "Product": "SMSC",
    }
  }

```

I Have one more index name tps and document looks like this

```
{
        "_index": "netdata-tps",
        "_type": "logs",
        "_id": "AV-6lE010ecAB0dXdmd7",
        "_score": 1,
        "_source": {
          "Product": "SMSC",
          "Vendor": "TeleDNA",
          "HOST": "10.225.253.137",
          "tps": 4500,
          "Location": "Bangalore",
          "Date": 1510663200000
        }
      }

```

Both are inserted with one minute interval(1 entry for 1 minute in both indices).

Now the problem is I need the tps key in tps indices into netdata indices based on the minutes. Is it possible to merge based on the date field using update\_by\_query or any other methods????

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [November 17, 2017, 9:06pm UTC](https://discuss.elastic.co/t/update-by-query-using-two-indices/107554/2 "2017-11-17T21:06:14Z")

</div>

Elasticsearch does not support this out of the box. That would need to be implemented outside of Elasticsearch, maybe using Spark (if you data is large enough to justify using it).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2017, 9:06pm UTC](https://discuss.elastic.co/t/update-by-query-using-two-indices/107554/3 "2017-12-15T21:06:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
