# Updating existing documents with a new field

**URL:** <https://discuss.elastic.co/t/updating-existing-documents-with-a-new-field/225701>\
**Category:** Elasticsearch\
**Created:** [March 30, 2020, 3:09pm UTC](https://discuss.elastic.co/t/updating-existing-documents-with-a-new-field/225701 "2020-03-30T15:09:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kernelpanic](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Post date:** [March 30, 2020, 3:09pm UTC](https://discuss.elastic.co/t/updating-existing-documents-with-a-new-field/225701/1 "2020-03-30T15:09:37Z")

</div>

Hello all, we're ingesting Windows event logs via Logstash and to get specific field data from an application log I've got the following filter in Logstash:

```
if [log_name] == "CISAccess" {
   grok {
      match => { "message" => "Usr=>%{DATA:User}#.*\sStn=>%{DATA:Workstation}#.*"}
        }
    }

```

Can somebody tell me how I can apply this to existing documents? - would I need to use a painless script or do I need to change the Logstash output to `action => update` and if so how do I keep ingesting new documents if I do that?

Thanks

---

<div class="post-metadata">

**Author:** ![Mike.Barretta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike.barretta/32/16688_2.png) [@Mike.Barretta](https://discuss.elastic.co/u/Mike.Barretta)\
**Post date:** [April 1, 2020, 2:10pm UTC](https://discuss.elastic.co/t/updating-existing-documents-with-a-new-field/225701/2 "2020-04-01T14:10:39Z")

</div>

@kernelpanic I think you have two options:

1. build an [ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/current/pipeline.html) with the same grok logic inside of a [grok processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/grok-processor.html) and run an [\_update\_by\_query](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-update-by-query.html) which passes data through that pipeline like

```auto
PUT _ingest/pipeline/my-grok-pipeline
{
  "description" : "pulls more stuff from the message",
  "processors" : [ {
     "grok": {
        "field": "message",
        "patterns": ["Usr=>%{DATA:User}#.*\sStn=>%{DATA:Workstation}#.*"]
     }
  }]
}
POST my-index/_update_by_query?pipeline=my-grok-pipeline
{
   "query": { "term": { "log_name": "CISAccess" } }  
}

```

2. Do the `_update_by_query` with a Painless script, requiring you to figure out how to map that grok logic to Java-style regex/Patterns

---

<div class="post-metadata">

**Author:** ![kernelpanic](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Post date:** [April 1, 2020, 2:35pm UTC](https://discuss.elastic.co/t/updating-existing-documents-with-a-new-field/225701/3 "2020-04-01T14:35:15Z")

</div>

Excellent, thankyou for getting back to me Mike.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2020, 2:35pm UTC](https://discuss.elastic.co/t/updating-existing-documents-with-a-new-field/225701/4 "2020-04-29T14:35:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
