# Where is my \_rev field

**URL:** https://discuss.elastic.co/t/where-is-my--rev-field/44860
**Category:** Elasticsearch
**Created:** [March 18, 2016, 7:15pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860 "2016-03-18T19:15:04Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 18, 2016, 7:15pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/1 "2016-03-18T19:15:04Z")

</div>

Hi,

I am using logstash to put my data from couchdb into elasticsearch. I just noticed that my \_rev field in not ported to elasticsearch. Do I need to do something special to have that in elasticsearch. Prompt help will be appreciated.

Thanks,  
imad.

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 18, 2016, 8:22pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/2 "2016-03-18T20:22:01Z")

</div>

Can someone please help me with this?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [March 19, 2016, 2:53am UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/3 "2016-03-19T02:53:35Z")

</div>

ES will simply store whatever is passed, if it's not there then chances are it's not being extracted from couchbase.

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 21, 2016, 1:36pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/4 "2016-03-21T13:36:29Z")

</div>

Yes I know that. Is there anything in logstash config file that I can set so that \_rev field also goes to my ES indices. I only have input and output sections in my logstash config file.  
Here is my input in logstash config file:

```
couchdb_changes {
    db => "users"
    sequence_path => "seq_files\users_couchdb_seq"
    tags => ["users"]
}

```

and here is my output:

```
if "users" in [tags] {
   elasticsearch { 
    document_id => "%{[@metadata][_id]}"
    index => "users_index"
    hosts => ["127.0.0.1:9200"]
}
```

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [March 21, 2016, 1:56pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/5 "2016-03-21T13:56:49Z")

</div>

As far as I recall, user defined fields are not allowed to start with an underscore, as this indicates an Elasticsearch internal field. Can you try renaming it in Logstash and see if that makes a difference?

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 21, 2016, 2:19pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/6 "2016-03-21T14:19:39Z")

</div>

@Christian_Dahlqvist, \_id from couchdb documents was also put in my ES indices as id in \_source field of ES index  
automatically then why \_rev is omitted.

Anyways I added this to my logstash config file:  
filter{  
mutate {  
convert =\> { "\_rev" =\> "rev" }  
}  
}  
but after that none of the indices were getting created at all.

PS: \_rev is a default/intrinsic field for every document in couchdb like \_id.

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 21, 2016, 2:28pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/7 "2016-03-21T14:28:04Z")

</div>

Now tried this:

```
filter{
mutate {
   rename => { "_rev" => "rev" }
}
}

```

but that also didn't put rev field in elasticserch indices.  
Could it be that logstash coucdb plugin is not handing over \_rev field to logstash to put it in ES indices?  
It should be a very basic question for logstash/elasticsearch guys. I'll really appreciate a prompt solution as I am close to release, thanks!

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [March 21, 2016, 7:08pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/8 "2016-03-21T19:08:30Z")

</div>

> [@imad](#):
>
> Could it be that logstash coucdb plugin is not handing over \_rev field to logstash to put it in ES indices?

Yes, so that is what you need to check, maybe with a stdout.

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 21, 2016, 7:33pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/9 "2016-03-21T19:33:21Z")

</div>

But why would it do that since \_id is also coming through.  
What would be the solution of this?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [March 21, 2016, 7:37pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/10 "2016-03-21T19:37:32Z")

</div>

Ok I will spell it out.

If it's not in LS then either it's not coming from CB, or it is and LS is not carrying it over for some reason, or something else. You need to get visibility into the pipeline and you should start by adding `{stdout {codec => rubydebug}}` to the `output` section of your LS config, then see what is actually coming through.  
From there, you can make your next move.

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 22, 2016, 1:58pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/11 "2016-03-22T13:58:49Z")

</div>

In stdout, I didn't see \_rev field coming through. Any idea what could be the problem then?

can you please clarify if this is the default behavior of logstash/logstash couchdb plugin to omit \_rev since I am not doing anything non regular to get data from couchdb.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [March 22, 2016, 10:22pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/12 "2016-03-22T22:22:48Z")

</div>

Righto then, start super basic. Have the CB input, no filters, then stdout and see if it's there

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 23, 2016, 2:05pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/13 "2016-03-23T14:05:15Z")

</div>

did that, here is my config file:

```
 input { 
     couchdb_changes {
     db => "folder"
     tags => ["folder"]
   }
}
output {
    if "folder" in [tags] {
     stdout { codec => rubydebug }
  }
}

```

But still didn't see \_rev field.

---

<div class="post-metadata">

### Author: ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)
#### Post date: [March 23, 2016, 2:19pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/14 "2016-03-23T14:19:28Z")

</div>

You aren't using the [`keep_revision`](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-couchdb_changes.html#plugins-inputs-couchdb_changes-keep_revision) flag in your input. Sending `_rev` is not always desired, so it is omitted by default, unless this flat is set to `true`.

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 23, 2016, 2:36pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/15 "2016-03-23T14:36:24Z")

</div>

@theuntergeek thanks for the help.  
Just want to confirm that keep\_revision only includes \_rev field in index or does it maintain all revisions in ES index. For example, if a document A is inserted and then updated in couchDB, would ES index has only one copy of document A with correct/latest \_rev, or would it save two copies of document one with insert \_rev and the 2nd with update \_rev?  
In other words is there any side effect of setting keep\_revision to true, since its false by default?

---

<div class="post-metadata">

### Author: ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)
#### Post date: [March 23, 2016, 3:08pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/16 "2016-03-23T15:08:32Z")

</div>

Elasticsearch won't keep revisions of a document, only the most recent you indexed.

Using the `keep_revision` flag will simply keep the `_rev` field in the indexed document so you can verify which version Elasticsearch has.

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 23, 2016, 3:10pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/17 "2016-03-23T15:10:29Z")

</div>

@theuntergeek you are awesome, thanks for the help!

---

<div class="post-metadata">

### Author: ![imad](https://avatars.discourse-cdn.com/v4/letter/i/f08c70/32.png) [@imad](https://discuss.elastic.co/u/imad)
#### Post date: [March 23, 2016, 3:13pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/18 "2016-03-23T15:13:28Z")

</div>

if you don't mind can you also suggest a solution for another problem I am stuck with. You can find it here: [New java.exe process starts everytime I stop and run logstash](https://discuss.elastic.co/t/new-java-exe-process-starts-everytime-i-stop-and-run-logstash/45045)

Thanks alot!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 11:05pm UTC](https://discuss.elastic.co/t/where-is-my--rev-field/44860/19 "2017-07-05T23:05:49Z")

</div>


