# Enrichment doesn't work sometimes

**URL:** <https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [June 19, 2023, 12:28pm UTC](https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366 "2023-06-19T12:28:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![matled](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@matled](https://discuss.elastic.co/u/matled)\
**Post date:** [June 19, 2023, 12:28pm UTC](https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366/1 "2023-06-19T12:28:31Z")

</div>

Currently we have a situation where the enrichment processor of the elasticsearch ingest pipeline  
doesn't always work.

Elastic-Stack: 8.8.1

- The syslog messages have the identical structure and are parsed correctly. I've manually verified this information with the elasticsearch ingest pipeline editor.

- The load of the systems ingesting are around 10% CPU and the nodes do have 128 GB Memory. There is no indicator of memory pressure or high Java Heap usage.

- The Ingest Nodes have the ingest role and data\_content roles assigned.

- The enrichment Pipeline and the enrichment index were not modified in any way while ingesting the data.

- The ingest pipeline does have about 80 Processors assigned

- The enrichment index contains 11 fields that are enriched to the documents

- The field I'm using for linking the enrichment is an ip address

- The field for the linking to the enrichment processor exists only once in the enrichment index

I'm glad for help to debug this further.

My wild guess is:

- Some kind of overload of the ingest pipeline/cache and missing enrichments due to some upper time limits for enrichment process itself

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 20, 2023, 4:18am UTC](https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366/2 "2023-06-20T04:18:25Z")

</div>

> [@matled](#):
>
> Currently we have a situation where the enrichment processor of the elasticsearch ingest pipeline  
> doesn't always work.

Can you elaborate more on what you are seeing to make this determination?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 20, 2023, 4:27am UTC](https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366/3 "2023-06-20T04:27:43Z")

</div>

Can you share an example of how your document looks like and a document that should've been enriched but wasn't?

Also, share your enrich policy and how the data looks like in your source index.

If possible share your entire ingest pipeline as well, so it is possible to try to replicate the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2023, 4:28am UTC](https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366/4 "2023-07-18T04:28:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
