# Editing an enrich policy

**URL:** <https://discuss.elastic.co/t/editing-an-enrich-policy/305494>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [May 24, 2022, 11:38am UTC](https://discuss.elastic.co/t/editing-an-enrich-policy/305494 "2022-05-24T11:38:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![chapmantrain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chapmantrain/32/22646_2.png) [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Post date:** [May 24, 2022, 11:38am UTC](https://discuss.elastic.co/t/editing-an-enrich-policy/305494/1 "2022-05-24T11:38:00Z")

</div>

It appears that if I need to edit an enrichment policy that an ingest pipeline uses, I have to delete the pipe, then delete the policy, then create the new edited policy, then create the ingest pipeline. That is the process I used in my POC cluster, but if I need to edit the policy in a PROD cluster, that multiple step process could present a problem with a lot of events coming in.

Do I have the process of editing a policy correct or is there a better way?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 25, 2022, 2:12am UTC](https://discuss.elastic.co/t/editing-an-enrich-policy/305494/2 "2022-05-25T02:12:24Z")

</div>

Unfortunately that is the only way to do it - [Set up an enrich processor | Elasticsearch Guide [8.2] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.2/enrich-setup.html#update-enrich-policies)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 25, 2022, 6:13am UTC](https://discuss.elastic.co/t/editing-an-enrich-policy/305494/3 "2022-05-25T06:13:10Z")

</div>

Actually @chapmantrain @warkolm linked to the proper process.

You can do this with no downtime.

Say your updating your source index for the enrich index daily.

You create the policy with a date suffix...

That policy is referenced inside your ingest pipeline.

So you just create a new enrich policy with today's date from today's new source index.

Then update The pipeline that uses that enrich policy with today's date.

Then you delete the old enrich policy.

> Once created, you can’t update or change an enrich policy. Instead, you can:
> 
> 1. Create and [execute](https://www.elastic.co/guide/en/elasticsearch/reference/current/execute-enrich-policy-api.html) a new enrich policy.
> 2. Replace the previous enrich policy with the new enrich policy in any in-use enrich processors.
> 3. Use the [delete enrich policy](https://www.elastic.co/guide/en/elasticsearch/reference/current/delete-enrich-policy-api.html) API to delete the previous enrich policy.

---

<div class="post-metadata">

**Author:** ![chapmantrain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chapmantrain/32/22646_2.png) [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Post date:** [June 2, 2022, 12:17pm UTC](https://discuss.elastic.co/t/editing-an-enrich-policy/305494/4 "2022-06-02T12:17:04Z")

</div>

Thanks Stephen and Mark. Looks like I can rig a way around down time. There is always a way.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2022, 12:17pm UTC](https://discuss.elastic.co/t/editing-an-enrich-policy/305494/5 "2022-06-30T12:17:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
