# Can Logstash enrich data before send to elasticsearch?

**URL:** <https://discuss.elastic.co/t/can-logstash-enrich-data-before-send-to-elasticsearch/76437>\
**Category:** Logstash\
**Created:** [February 24, 2017, 6:37pm UTC](https://discuss.elastic.co/t/can-logstash-enrich-data-before-send-to-elasticsearch/76437 "2017-02-24T18:37:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ranieri\_Mazili\_de\_Ol](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranieri_mazili_de_ol/32/15815_2.png) [@Ranieri\_Mazili\_de\_Ol](https://discuss.elastic.co/u/Ranieri_Mazili_de_Ol)\
**Post date:** [February 24, 2017, 6:37pm UTC](https://discuss.elastic.co/t/can-logstash-enrich-data-before-send-to-elasticsearch/76437/1 "2017-02-24T18:37:03Z")

</div>

Hello,

I'm completely new and I'm evaluating some tool to implement my solution.

I'll use Beats as agent and when a new event come I'll send it to Logstash.

Can Logstash, based in the information receveid by Beats, enrich this data (querying a database to get more data for example) and then send it to Elasticsearch?

I really appreciate any help.  
Thanks

---

<div class="post-metadata">

**Author:** ![Mat\_J](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mat_j/32/15849_2.png) [@Mat\_J](https://discuss.elastic.co/u/Mat_J)\
**Post date:** [February 24, 2017, 10:26pm UTC](https://discuss.elastic.co/t/can-logstash-enrich-data-before-send-to-elasticsearch/76437/2 "2017-02-24T22:26:53Z")

</div>

Hi Ranieri,

Yes you can do lookup within a logstash pipeline using the Elasticsearch filter to query Elasticsearch and pull back values from documents that match the query and then enrich the original event with them. We do this to add customer specific data to syslog messages at indexing time.

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html)

If you have a smaller set of lookup data you could use a translate filter with a dictionary lookup.

Regards  
Mat

---

<div class="post-metadata">

**Author:** ![Ranieri\_Mazili\_de\_Ol](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranieri_mazili_de_ol/32/15815_2.png) [@Ranieri\_Mazili\_de\_Ol](https://discuss.elastic.co/u/Ranieri_Mazili_de_Ol)\
**Post date:** [February 25, 2017, 2:49pm UTC](https://discuss.elastic.co/t/can-logstash-enrich-data-before-send-to-elasticsearch/76437/3 "2017-02-25T14:49:31Z")

</div>

But can data be enrich with results from a database query or only be data already inside elastic search?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 27, 2017, 3:52am UTC](https://discuss.elastic.co/t/can-logstash-enrich-data-before-send-to-elasticsearch/76437/4 "2017-02-27T03:52:03Z")

</div>

You will be able to do this with LS 5.3 and a new JDBC filter, which will be out soon.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2017, 3:52am UTC](https://discuss.elastic.co/t/can-logstash-enrich-data-before-send-to-elasticsearch/76437/5 "2017-03-27T03:52:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
