I have ElasticSearch index that stores more than 10 mln documents. I need to iterate over all index and add new field and value for each document. I know about two approaches: 1. Use scroll search to get all results and use BULK api to copy all documents into new index [adding new fields while copying]. After all documents are copied to new index - switch aliases. 2. Use scroll search and bulk API to update all documents in existed index (do not need to copy to new index and switching aliases).
I do not understand, why first approach is recommended? Can I just use 2 approach? Is there any possibility that while running program with 2 approach, something bad can happen to the index? Index that I need to update has live prod data and I worried that customers may be affected in some way