# Updating elasticsearch document, without adding "doc"

**URL:** https://discuss.elastic.co/t/updating-elasticsearch-document-without-adding-doc/185880
**Category:** Logstash
**Created:** [June 14, 2019, 3:00pm UTC](https://discuss.elastic.co/t/updating-elasticsearch-document-without-adding-doc/185880 "2019-06-14T15:00:17Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![T1mmy](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@T1mmy](https://discuss.elastic.co/u/T1mmy)
#### Post date: [June 14, 2019, 3:00pm UTC](https://discuss.elastic.co/t/updating-elasticsearch-document-without-adding-doc/185880/1 "2019-06-14T15:00:17Z")

</div>

I'm trying to update my users in elasticsearch via logstash couchdb\_changes. But everytime a change is made to the user, logstatsh adds a "doc"-subarray with the new changes to my document in elasticsearch, instead of updating the document itself.

i.e. when i got:

```
[
user_id => 1,
username => franky,
firstname => frank,
lastname => mauer
]

```

and i change the lastname, i get

```
 [
   user_id => 1,
   username => franky,
   firstname => frank,
   lastname => mauer,
   doc => [ 
        user_id => 1,
        username => franky,
        firstname => frank,
        lastname => whatever,
   ]

```

]

this is my conf:

```
    couchdb_changes {
        host => "couchdb"
        db => "user"
        username => "name"
        password => "***"
        sequence_path=>"/usr/share/logstash/.couchdb_seq_user"
        initial_sequence => 0
    }

      elasticsearch { 
            hosts => "elasticsearch:9200"
            upsert => "%{[doc]}"
            index => "%{type}"
            document_id => "%{[doc][username]}"
            action => "%{[@metadata][action]}"
            template => "/usr/share/logstash/templates/template_user.json"
            template_name => "user"
        }

```

Any idea how i can stop this behavoir and just update the document like every normal thinking human would expect.  
Thanks.

---

<div class="post-metadata">

### Author: ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)
#### Post date: [June 14, 2019, 11:47pm UTC](https://discuss.elastic.co/t/updating-elasticsearch-document-without-adding-doc/185880/2 "2019-06-14T23:47:48Z")

</div>

I'm not familiar with that plugin, but as a change-stream provider my best guess is that it needs a way to tell the downstream that a document has been deleted, and it can't do that and also support all of the fields at top-level.

Once you've selected only new- and updated-updated documents, you can likely use a filter like the following ruby filter to move the contents of the `doc` field up to the root.

```auto
filter {
  ruby {
    code => "
      doc = event.get('doc')
      if doc.kind_of?(Hash)
        event.remove('doc')
        doc.each do |key, value|
          event.set(key, value)
        end
      end
    "
  }
}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 12, 2019, 11:47pm UTC](https://discuss.elastic.co/t/updating-elasticsearch-document-without-adding-doc/185880/3 "2019-07-12T23:47:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
