# Update document on multiple indices

**URL:** <https://discuss.elastic.co/t/update-document-on-multiple-indices/81316>\
**Category:** Logstash\
**Created:** [April 5, 2017, 1:35pm UTC](https://discuss.elastic.co/t/update-document-on-multiple-indices/81316 "2017-04-05T13:35:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![shaharmor](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@shaharmor](https://discuss.elastic.co/u/shaharmor)\
**Post date:** [April 5, 2017, 1:35pm UTC](https://discuss.elastic.co/t/update-document-on-multiple-indices/81316/1 "2017-04-05T13:35:36Z")

</div>

Hi,

I'm tracking user sessions as docs in ES.  
Each session is a single doc that gets updated when ever the session state changes.

I'm using daily based indices, and the ID of the doc is the session ID (UUID).  
If a session starts before the end of a day, but continues on to the next day, the update will look for it only in the next day's index and thus won't find it and will create a new doc, right?

How can I make logstash look up the doc in multiple indices so I will really only have a single doc per session? Or is there a better way to handle this?

---

<div class="post-metadata">

**Author:** ![TWalter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/twalter/32/41239_2.png) [@TWalter](https://discuss.elastic.co/u/TWalter)\
**Post date:** [April 5, 2017, 11:24pm UTC](https://discuss.elastic.co/t/update-document-on-multiple-indices/81316/2 "2017-04-05T23:24:58Z")

</div>

Hi shaharmor,

i have an Idea, but it's a little bit complicated. I think the decission in which Index the event is written depends on the timestamp of the doc or other specific fields.

To solve your Problem you can do this:

1. You lookup your ES if there is already an entry with the same UUID. You can do this with the Elasticsearch-Filter-Plugin (here the documentation: [https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html)).

2. Configure the filter plugin, so that you "join" specific fields (that are responsible for writing in the time based index) from the existing entry in ES. If there is no existing entry with the same UUID, the filter plugin doesn' join anything (because ther is nothing to join) and the doc won't be modified.

3. If the filter plugin joined the fields of the existing entry, delete the unnecessary and keep the necessary fields for the correct updating to the "old" index.

I hope i could help you a little bit =)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2017, 11:24pm UTC](https://discuss.elastic.co/t/update-document-on-multiple-indices/81316/3 "2017-05-03T23:24:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
