# Updating the datastream from logstash

**URL:** <https://discuss.elastic.co/t/updating-the-datastream-from-logstash/366446>\
**Category:** Elasticsearch\
**Tags:** datastreams\
**Created:** [September 12, 2024, 5:55am UTC](https://discuss.elastic.co/t/updating-the-datastream-from-logstash/366446 "2024-09-12T05:55:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![venkatkumar229](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/venkatkumar229/32/104663_2.png) [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Post date:** [September 12, 2024, 5:55am UTC](https://discuss.elastic.co/t/updating-the-datastream-from-logstash/366446/1 "2024-09-12T05:55:44Z")

</div>

Hi Team,

we are trying to lookup the data in one datastream with anothe data in another datastream based on a key using logstash elasticseach input plugin and elasticsearch filter as shown in the sample config below.

My both indexes - index1, index2 are datastreams. Could you please help me how can i achieve the requirement to update the index1 datastream.

```auto
input {
  elasticsearch {
    cloud_id => "xxxxxxxxxxxxxxxxxxxx"
    index => "index1"
    query => '{"query": {"match_phrase": {"shop": "12345"}},"_source": ["Price", "shop", "source"]}'
    ssl => true
    user => "xxxxxxxxxx"
    password => "xxxxxxxxxxxxx"
  }
}
 
 
filter {
    mutate {
      add_field => {
        "common_key" => "%{shop}"
        "Secondary" => "%{source}"
        "price" => "%{price}"
        "amount" => "%{amount}"
      }
    }
 
 elasticsearch {
        cloud_id => "xxxxxxxxxx"
    user => "xxxxxxxxxx"
    password => "xxxxxxxxxxxxx"
        index => "index2"
        query => "sourcecode:%{[source]}"
        ssl => true
        fields => {
                "[shop]" => "[shop]"
                "[price]" => "[price]"
                "[amount]" => "[amount]"
                }
    }
}
 
output {
   stdout {
        codec => rubydebug
   }
    elasticsearch {
        cloud_id => "xxxxxxxxxxxx"
        proxy => "xxxxxxxxxxxx"
        index => "index1"
        ssl => true
        user => "xxxxxxxxxxxx"
        password => "xxxxxxxxxxx"
        action => "update"
    }
}

```

i am getting below error while trying  
"reason"=\>"only write ops with an op\_type of create are allowed in data streams"

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 12, 2024, 6:13am UTC](https://discuss.elastic.co/t/updating-the-datastream-from-logstash/366446/2 "2024-09-12T06:13:35Z")

</div>

[Data streams are designed for immutable data](https://www.elastic.co/guide/en/elasticsearch/reference/current/data-streams.html#should-you-use-a-data-stream) so if you need to update your data you may be better off switching to normal indices. If you need to perform updates you may need to use update-by-query which can not be triggered from Logstash.
