# Enrich all Elasticsearch REST requests by adding filters from plugin

**URL:** <https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714>\
**Category:** Elasticsearch\
**Created:** [December 13, 2018, 10:33am UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714 "2018-12-13T10:33:54Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 13, 2018, 10:33am UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/1 "2018-12-13T10:33:54Z")

</div>

Hi,

would it be possible to catch all Elasticsearch requests, from a plugin, in order to enrich them by adding some filters without changing the query client-side?  
E.g. user calls `GET /_search` and I will add:

```json
{
  "query": { 
    "bool": { 
      "must": [
        { "match": { "title": "Search" }}, 
        { "match": { "content": "Elasticsearch" }}  
      ],
      "filter": [ 
        { "term": { "status": "published" }}, 
        { "range": { "publish_date": { "gte": "2015-01-01" }}} 
      ]
    }
  }
}

```

in the plugin. somewhere.  
Is it possible to do that? If so, what methods / classes do I need to extend / override to add my logic?

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 13, 2018, 12:20pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/2 "2018-12-13T12:20:48Z")

</div>

Why not using an alias? An alias can have filters. See [https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-aliases.html#filtered](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-aliases.html#filtered)

---

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 13, 2018, 1:29pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/3 "2018-12-13T13:29:26Z")

</div>

Thanks for the answer @dadoonet, unfortunately I cannot use aliases because I need to add those filters in a transparent way so that user still keeps doing the same requests in the same way.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 13, 2018, 2:07pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/4 "2018-12-13T14:07:58Z")

</div>

That does not change the request. Just the index name.

---

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 13, 2018, 2:17pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/5 "2018-12-13T14:17:34Z")

</div>

@dadoonet, ok but when user make a normal and usual call (in the example `GET /_search`) how can I catch that call in the plugin to block it and replace it with another call to the previously created alias?

---

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 13, 2018, 2:28pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/6 "2018-12-13T14:28:28Z")

</div>

also, this would required to first create aliases for each filter I want to use in my Elasticsearch and I would like to avoid it.  
The alias feature could be useful in my case, but just in case I will be able to replace the normal request a user is making with a custom one so that I could dynamically create an alias with a specific filter and then make the filtered request instead of the original one.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 13, 2018, 2:50pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/7 "2018-12-13T14:50:45Z")

</div>

> [@Uiidoi12](#):
>
> I will be able to replace the normal request a user is making with a custom one so that I could dynamically create an alias with a specific filter and then make the filtered request instead of the original one.

Dynamically based on what?

---

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 13, 2018, 3:00pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/8 "2018-12-13T15:00:15Z")

</div>

> Dynamically based on what?

Based on the filters I want to add for the specific request.  
Anyway, so there is no way to catch requests from an Elasticsearch plugin in order to replace them somehow?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 13, 2018, 3:02pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/9 "2018-12-13T15:02:42Z")

</div>

> Based on the filters I want to add for the specific request.

So I don't understand... Can't you just do that by yourself in your application?

I mean that yes you can probably do that within a plugin but this is looking over engineering to me. Unless I'm missing something. Writing and more than that, maintaining a plugin, is not something that trivial IMHO.

That's why I'm asking and trying to check if you really need that.

---

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 13, 2018, 3:07pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/10 "2018-12-13T15:07:50Z")

</div>

> I mean that yes you can probably do that within a plugin but this is looking over engineering to me. Unless I'm missing something. Writing and more than that, maintaining a plugin, is not something that trivial IMHO.  
> That's why I'm asking and trying to check if you really need that.

yes you are right and thank you for that.  
The problem is that I am really unable to touch the application making requests, besides the plugin will be used on generic Elasticsearch instances that are called by different and generic applications.

Do have any idea about where I can start to try something from the plugin in order to do what I need?  
Any specific class I need to extend or methods to override in order to catch the request?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 13, 2018, 3:30pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/11 "2018-12-13T15:30:11Z")

</div>

I don't understand.

If you can not change the application, how do you know what filter you need to apply when someone just call `GET /_search`? There's no parameter to decide... I think I'm lost.

Anyway, I wrote a long time ago [how to write a plugin which adds a REST endpoint](http://david.pilato.fr/blog/2016/10/19/adding-a-new-rest-endpoint-to-elasticsearch-updated-for-ga/). That does not intercept your requests and add some filters though.

May be this can be a source of inspiration though: [https://github.com/elastic/elasticsearch/blob/master/x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/rest/SecurityRestFilter.java](https://github.com/elastic/elasticsearch/blob/master/x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/rest/SecurityRestFilter.java) (this code is not under Apache2 License though but that could help).

---

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 13, 2018, 3:39pm UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/12 "2018-12-13T15:39:38Z")

</div>

> [@dadoonet](#):
>
> If you can not change the application, how do you know what filter you need to apply when someone just call `GET /_search` ? There's no parameter to decide... I think I'm lost.

I get those information about filters from an external service I call where the source application put specific filters I will use in the plugin.  
I know it sound strange but there is reason for logic.

> [@dadoonet](#):
>
> Anyway, I wrote a long time ago [how to write a plugin which adds a REST endpoint](http://david.pilato.fr/blog/2016/10/19/adding-a-new-rest-endpoint-to-elasticsearch-updated-for-ga/). That does not intercept your requests and add some filters though.

yes I know about it and also found an official example about how to create a custom REST endpoint, but unfortunately it's not helpful for my needs.

> [@dadoonet](#):
>
> May be this can be a source of inspiration though: [elasticsearch/x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/rest/SecurityRestFilter.java at main · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/blob/master/x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/rest/SecurityRestFilter.java) (this code is not under Apache2 License though but that could help).

thank you, I'll try to look at it and will report here in case of progress.

Regards

---

<div class="post-metadata">

**Author:** ![Uiidoi12](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@Uiidoi12](https://discuss.elastic.co/u/Uiidoi12)\
**Post date:** [December 14, 2018, 9:18am UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/13 "2018-12-14T09:18:42Z")

</div>

Hi,

what about `org.elasticsearch.action.support.ActionFilter` ([https://github.com/elastic/elasticsearch/blob/master/server/src/main/java/org/elasticsearch/action/support/ActionFilter.java](https://github.com/elastic/elasticsearch/blob/master/server/src/main/java/org/elasticsearch/action/support/ActionFilter.java))?  
Do you think it can be useful for my needs?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2019, 9:18am UTC](https://discuss.elastic.co/t/enrich-all-elasticsearch-rest-requests-by-adding-filters-from-plugin/160714/14 "2019-01-11T09:18:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
