# Data getting SWAPPED in Elasticsearch with pipeline

**URL:** https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796
**Category:** Elasticsearch
**Created:** [August 28, 2023, 10:09am UTC](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796 "2023-08-28T10:09:09Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![tusharnemade](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)
#### Post date: [August 28, 2023, 10:09am UTC](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796/1 "2023-08-28T10:09:09Z")

</div>

Hello Team

We are using Elasticsearch version 7.8.0

We are having Index with Pipeline Defined ..

Our Problem is data is getting SWAPPED between two fields of Elasticsearch.

Data of "OBJ\_NAM\_FILDT" is getting posted in "USER\_TAGS\_AK" and vice-versa. That too only for FEW Records and not for all the data records being pushed to Elasticsearch.

Could you please help us if you are aware of such behaviour in Elasticsearch with Pipeline "PROCESSOR - SPLIT " define on a field.

Field Definition :

```auto
        "OBJ_NAM_FILDT" : {
          "type" : "text",
          "fields" : {
            "keyword" : {
              "type" : "keyword",
              "ignore_above" : 256
            }
          }
        },

```

```auto
        "USER_TAGS_AK" : {
          "type" : "text",
          "fields" : {
            "keyword" : {
              "type" : "keyword",
              "ignore_above" : 256
            }
          },
          "analyzer" : "autocomplete"
        },

```

Index Pipeline :

```auto
  "tf_usr_tags_smry_array_tags" : {
    "processors" : [
      {
        "split" : {
          "if" : "ctx.USER_TAGS_AK != null ",
          "field" : "USER_TAGS_AK",
          "separator" : ",",
          "ignore_failure" : true
        }
      }
    ]
  }

```

Also we have tokenizer define as below in our index settings ..

```auto
    "settings" : {
      "index" : {
        "default_pipeline" : "tf_usr_tags_smry_array_tags",
        "creation_date" : "1626846772008",
        "analysis" : {
          "analyzer" : {
            "autocomplete" : {
              "filter" : [
                "lowercase"
              ],
              "tokenizer" : "alz_tkn_tej_usr_tags_sum_9_a3"
            }
          },
          "tokenizer" : {
            "alz_tkn_tej_usr_tags_sum_9_a3" : {
              "punctuation" : {
                "pattern" : "[-]",
                "type" : "pattern"
              },
              "token_chars" : [],
              "min_gram" : "1",
              "side" : "front",
              "type" : "edge_ngram",
              "max_gram" : "10"
            }
          }
        }

```

---

<div class="post-metadata">

### Author: ![tusharnemade](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)
#### Post date: [August 29, 2023, 4:04am UTC](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796/2 "2023-08-29T04:04:06Z")

</div>

> [@tusharnemade](#):
>
> ```auto
> "tf_usr_tags_smry_array_tags" : {
> "processors" : [
> {
> "split" : {
> "if" : "ctx.USER_TAGS_AK != null ",
> "field" : "USER_TAGS_AK",
> "separator" : ",",
> "ignore_failure" : true
> }
> }
> ]
> }
> 
> ```

It has come to notice that , when USER\_TAGS\_AK is in actually NULL / empty , behaviour of SWAPPING data is seen.

Could you please someone confirm , this is BUG or something with condition of PROCESSOR which need to be changed.

---

<div class="post-metadata">

### Author: ![tusharnemade](https://avatars.discourse-cdn.com/v4/letter/t/67e7ee/32.png) [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)
#### Post date: [August 29, 2023, 5:33am UTC](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796/3 "2023-08-29T05:33:36Z")

</div>

I have now updated the SPLIT processor code with ON\_FAILURE Condition.

Will update in sometime , if this has worked for the data or not.

```auto
"processors" : [
    {
      "split" : {
        "if" : "ctx.USER_TAGS_AK != null ",
        "field": "USER_TAGS_AK",
        "separator" : ",",
        "on_failure" : [
          {
            "set" : {
              "field" : "USER_TAGS_AK",
              "value" : "'NULL'"
            }
          }
        ]
      }
    }
  ]

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 26, 2023, 5:34am UTC](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796/4 "2023-09-26T05:34:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
