# Enrich policy access "\_id" field

**URL:** <https://discuss.elastic.co/t/enrich-policy-access-id-field/269868>\
**Category:** Elasticsearch\
**Created:** [April 12, 2021, 11:15am UTC](https://discuss.elastic.co/t/enrich-policy-access-id-field/269868 "2021-04-12T11:15:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sam3546](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sam3546/32/79281_2.png) [@sam3546](https://discuss.elastic.co/u/sam3546)\
**Post date:** [April 12, 2021, 11:15am UTC](https://discuss.elastic.co/t/enrich-policy-access-id-field/269868/1 "2021-04-12T11:15:08Z")

</div>

I am trying to use an enrich policy to match on a filename and return the \_id fields of that doc to add in as a field in my secondary index. I have two indexes the first has 1 entry with field 'filename'. The second index uses a pipeline and enrich policy shown below to match on the filename and return the \_id value of the first index entry as a field in the second index. This does not work the \_id value is not returned as expected.

Any clues as to why this is?

```auto
{
    "description": "x",
    "processors": [
      {
        "set": {
          "field": "test",
          "value": "null"
        }
      },
      {
        "enrich": {
          "policy_name": "enrich-policy",
          "field": "filename",
          "target_field": "tmp",
          "max_matches": "1",
          "ignore_failure": true
        }
      },
      {
        "set": {
          "if": "ctx.containsKey('tmp')",
          "field": "test",
          "value": "{{tmp._id}}",
          "on_failure":[{
            "set":{
              "field":"test",
              "value":"!Issue setting field value!"
            }
          }]
        }
      },
      {
        "remove": {
          "field": ["tmp"],
          "ignore_failure": true
        }
      }
    ],
    "version": 1
  }

```

enrich-policy.json

```auto
{
  "match": {
    "indices": ["index-1"],
    "match_field": "filename",
    "enrich_fields": ["_id"]
  }
}

```

---

<div class="post-metadata">

**Author:** ![sam3546](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sam3546/32/79281_2.png) [@sam3546](https://discuss.elastic.co/u/sam3546)\
**Post date:** [April 12, 2021, 2:15pm UTC](https://discuss.elastic.co/t/enrich-policy-access-id-field/269868/2 "2021-04-12T14:15:42Z")

</div>

It seems the \_ fields are restricted and cannot be accessed

' The `_id` field is restricted from use in aggregations, sorting, and scripting. In case sorting or aggregating on the `_id` field is required, it is advised to duplicate the content of the `_id` field into another field that has `doc_values` enabled.' ([\_id field | Elasticsearch Guide [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-id-field.html))

It talks about creating a copy into a new field that can be accessed but as described in the issue below \_id is not accessible on ingest in the pipeline and is only assigned after.

> <https://github.com/elastic/elasticsearch/issues/41163>
>
> I think this is merely a documentation issue for now. Found at https://discuss.elastic.co/t/accessing-id-in-ingest-pipeline/176503
> Indexing a document that will have its ID autogenerated,...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2021, 2:15pm UTC](https://discuss.elastic.co/t/enrich-policy-access-id-field/269868/3 "2021-05-10T14:15:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
