Wtacher or Ingest pipeline avoiding duplicates

Hello colleagues!

I have a question.

Is there a way to put in watcher or ingest pipelines an update based on a document_id ( field, fields, fingerprint... ) to avoid duplicates as in the logstash output ?

I have a watcher that is doing some aggregations by date ranges and we want to avoid that these duplicates can be produced.

Thanks in advance !
Best regards

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.