# Updating data

**URL:** <https://discuss.elastic.co/t/updating-data/143186>\
**Category:** Logstash\
**Created:** [August 6, 2018, 2:49pm UTC](https://discuss.elastic.co/t/updating-data/143186 "2018-08-06T14:49:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Olha1](https://avatars.discourse-cdn.com/v4/letter/o/9f8e36/32.png) [@Olha1](https://discuss.elastic.co/u/Olha1)\
**Post date:** [August 6, 2018, 2:49pm UTC](https://discuss.elastic.co/t/updating-data/143186/1 "2018-08-06T14:49:14Z")

</div>

Hi! I have a problem with updating my data in elasticsearch.  
I use a postgresql. When I transfer the data from database to elasticsearch through logstash, I have problem with update my data again and again.  
If I have, for example, 1000 hits in database, across a few time I have 2000, and 3000, and ... 1000\*n hist.  
But, If I had in logstash OUTPUT in elasticsearch the field: document\_id =\> "%{[ID]}", then I have only 1000 hits, but this hits updating again and again.  
Please, give me the advice about this problem.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 6, 2018, 5:58pm UTC](https://discuss.elastic.co/t/updating-data/143186/2 "2018-08-06T17:58:39Z")

</div>

I don't understand what the problem is. How many rows do you want to have? What should happen with the rows you fetch from the database?

---

<div class="post-metadata">

**Author:** ![Olha1](https://avatars.discourse-cdn.com/v4/letter/o/9f8e36/32.png) [@Olha1](https://discuss.elastic.co/u/Olha1)\
**Post date:** [August 7, 2018, 9:59am UTC](https://discuss.elastic.co/t/updating-data/143186/3 "2018-08-07T09:59:32Z")

</div>

My logstash adding data from database again and again. If I have 100 rows in database, logstash adding 100 rows, then 100 more rows, etc.  
If I have in logstash OUTPUT in elasticsearch the field: document\_id =\> "%{[ID]}, then program update my data again and again. It is like 88 rows, f5 99 rows, f5 3 rows, f5 45 rows, etc.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 7, 2018, 10:05am UTC](https://discuss.elastic.co/t/updating-data/143186/4 "2018-08-07T10:05:00Z")

</div>

So you want to update the document only when the corresponding database row has actually been updated?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 7, 2018, 11:10am UTC](https://discuss.elastic.co/t/updating-data/143186/6 "2018-08-07T11:10:54Z")

</div>

If your table has a column with a "last modified" timestamp you can use the `sql_last_value` query parameter to select only those rows that have been modified since the last run (see the jdbc input documentation).

If you don't have such a column and you can't add one you're going to have to continue updating all documents all the time.

Logstash will not handle deletions of database rows.

---

<div class="post-metadata">

**Author:** ![Olha1](https://avatars.discourse-cdn.com/v4/letter/o/9f8e36/32.png) [@Olha1](https://discuss.elastic.co/u/Olha1)\
**Post date:** [August 7, 2018, 11:15am UTC](https://discuss.elastic.co/t/updating-data/143186/7 "2018-08-07T11:15:21Z")

</div>

What I need, if logstash adding to elastic data with each updating? excess data.  
For example, I have 10 rows in database, but after upload it in elastic, with time, I will have 10, 20, 30,...., 200 rows, which are repeated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2018, 11:15am UTC](https://discuss.elastic.co/t/updating-data/143186/8 "2018-09-04T11:15:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
