# Accessing a Separate Index in a Scripted Field

**URL:** <https://discuss.elastic.co/t/accessing-a-separate-index-in-a-scripted-field/27506>\
**Category:** Elasticsearch\
**Created:** [August 17, 2015, 1:43pm UTC](https://discuss.elastic.co/t/accessing-a-separate-index-in-a-scripted-field/27506 "2015-08-17T13:43:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![stevenlocke](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@stevenlocke](https://discuss.elastic.co/u/stevenlocke)\
**Post date:** [August 17, 2015, 1:43pm UTC](https://discuss.elastic.co/t/accessing-a-separate-index-in-a-scripted-field/27506/1 "2015-08-17T13:43:31Z")

</div>

Is it possible to create a scripted field which reads a value from indexA, performs a search in indexB, then takes that value and stores it back in indexA?

For example, I have an index filled with IP addresses and the companies who own them. In a separate index, I have an IP address and I need to know the company where this traffic is coming from. So ideally, I would read the address, search the other index for the company, then store the company alongside the original address.

Can this be performed at all, so far I've only seen accessing fields in a self-contained index?

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 17, 2015, 10:49pm UTC](https://discuss.elastic.co/t/accessing-a-separate-index-in-a-scripted-field/27506/2 "2015-08-17T22:49:03Z")

</div>

This is basically a join and you cannot do it inside ES, you'd have to do it outside and then reindex the document.

If you are using the ELK stack then check out the [translate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html).

---

<div class="post-metadata">

**Author:** ![stevenlocke](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@stevenlocke](https://discuss.elastic.co/u/stevenlocke)\
**Post date:** [August 18, 2015, 5:13pm UTC](https://discuss.elastic.co/t/accessing-a-separate-index-in-a-scripted-field/27506/3 "2015-08-18T17:13:14Z")

</div>

Not using Logstash, unfortunately.

Any alternatives?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2015, 9:54pm UTC](https://discuss.elastic.co/t/accessing-a-separate-index-in-a-scripted-field/27506/4 "2015-08-18T21:54:15Z")

</div>

Then it's all DIY, externally to ES.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:55pm UTC](https://discuss.elastic.co/t/accessing-a-separate-index-in-a-scripted-field/27506/5 "2017-07-05T23:55:11Z")

</div>


