# Field with name for each document

**URL:** <https://discuss.elastic.co/t/field-with-name-for-each-document/290815>\
**Category:** Kibana\
**Created:** [December 2, 2021, 7:07pm UTC](https://discuss.elastic.co/t/field-with-name-for-each-document/290815 "2021-12-02T19:07:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [December 2, 2021, 7:07pm UTC](https://discuss.elastic.co/t/field-with-name-for-each-document/290815/1 "2021-12-02T19:07:15Z")

</div>

In each entry I have IP address and I would have also name for it. I have pairs IP and name.

How can I deal with it? To have name in each document where is IP adress?

I use static lookup but this is hard to use, I don't know how update it etc.

What will be less problematic/CPU consuming etc, update static field or scripted fields?

How can I update static lookup? how should look script? can I do it some easy way with PHP API?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [December 2, 2021, 8:15pm UTC](https://discuss.elastic.co/t/field-with-name-for-each-document/290815/2 "2021-12-02T20:15:28Z")

</div>

best way would be to enrich the data from ingest, just add the field and name from the start. If that is not an option, a static lookup would be less intensive, depending on how many pairs you have.  
I assume this would be a list of hostnames, and for a size of 10-15 any options is fine. Once you get past the 100 the static lookup will be hard to manage and the scripted fields are going to get really big, so I would still suggest enriching the data from the start.

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [December 2, 2021, 10:04pm UTC](https://discuss.elastic.co/t/field-with-name-for-each-document/290815/3 "2021-12-02T22:04:20Z")

</div>

I will have more than 100, I guess like 200 or more.

You mean this? [Enrich processor | Elasticsearch Guide [7.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/enrich-processor.html)

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [December 2, 2021, 10:10pm UTC](https://discuss.elastic.co/t/field-with-name-for-each-document/290815/4 "2021-12-02T22:10:33Z")

</div>

That will work if you have a lot of fields, yes.

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [December 2, 2021, 10:11pm UTC](https://discuss.elastic.co/t/field-with-name-for-each-document/290815/5 "2021-12-02T22:11:28Z")

</div>

Hmm, ok... that looks litle complicated 🙂

It will work for daily indexes? I have like 3 indexes per day (3 sources for daily indexes).

And how can I automate it? It looks like a lot manual job, not like static lookup.

Is it possible to enrich by SQL query?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2021, 10:12pm UTC](https://discuss.elastic.co/t/field-with-name-for-each-document/290815/6 "2021-12-30T22:12:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
