# Add new documents to an enrich index

**URL:** <https://discuss.elastic.co/t/add-new-documents-to-an-enrich-index/318759>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [November 11, 2022, 7:28pm UTC](https://discuss.elastic.co/t/add-new-documents-to-an-enrich-index/318759 "2022-11-11T19:28:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [November 11, 2022, 7:28pm UTC](https://discuss.elastic.co/t/add-new-documents-to-an-enrich-index/318759/1 "2022-11-11T19:28:46Z")

</div>

Hi, I have filebeat sending data to elasticsearch, this data is enriched with an ingest pipeline, I have added a new document to the enrich index that already is in use, but the changes are not showing.

What do I have to do so that these new documents are considered by the enrich processor?

Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 11, 2022, 10:31pm UTC](https://discuss.elastic.co/t/add-new-documents-to-an-enrich-index/318759/2 "2022-11-11T22:31:49Z")

</div>

> **[Set up an enrich processor | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/enrich-setup.html#update-enrich-policies)**

> ### Update an enrich policy
> 
> Once created, you can’t update or change an enrich policy. Instead, you can:
> 
> 1. Create and [execute](https://www.elastic.co/guide/en/elasticsearch/reference/current/execute-enrich-policy-api.html) a new enrich policy.
> 2. Replace the previous enrich policy with the new enrich policy in any in-use enrich processors.
> 3. Use the [delete enrich policy](https://www.elastic.co/guide/en/elasticsearch/reference/current/delete-enrich-policy-api.html) API to delete the previous enrich policy.

This may seem cumbersome, but it is by design, in essence it allows you "to version" your enrich policy. You can tag a date on the end...

```auto
PUT /_enrich/policy/my-policy-2022.11.11
{
  "match": {
    "indices": "users",
    "match_field": "email",
    "enrich_fields": ["first_name", "last_name", "city", "zip", "state"]
  }
}

PUT /_enrich/policy/my-policy-2022.11.11/_execute

PUT /_ingest/pipeline/user_lookup
{
  "processors" : [
    {
      "enrich" : {
        "description": "Add 'user' data based on 'email'",
        "policy_name": "my-policy-2022.11.11",
        "field" : "email",
        "target_field": "user",
        "max_matches": "1"
      }
    }
  ]
}

```

You can run a nightly script if you want...etc..

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 12, 2022, 12:44am UTC](https://discuss.elastic.co/t/add-new-documents-to-an-enrich-index/318759/3 "2022-11-12T00:44:01Z")

</div>

> [@ElasticLiver](#):
>
> What do I have to do so that these new documents are considered by the enrich processor?

As @stephenb said, you need to run the `_execute` request in your policy every time you update the source index of your enrich policy.

If you need to update your source indice frequently, you will need to schedule something to run this request, I have the same issue and I'm currently using a shell script on a crontab.

There is an [open issue](https://github.com/elastic/elasticsearch/issues/50071) in github with a feature request to implement some way to schedule an execute on an enrich policy.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 12, 2022, 1:08am UTC](https://discuss.elastic.co/t/add-new-documents-to-an-enrich-index/318759/4 "2022-11-12T01:08:05Z")

</div>

Some reason I think that our the Threat Intel package does this (i could be wrong), it seems that if it does that functionality should be exposed for other enrich indices...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2022, 1:08am UTC](https://discuss.elastic.co/t/add-new-documents-to-an-enrich-index/318759/5 "2022-12-10T01:08:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
