# Hashing in ElasticSearch

**URL:** <https://discuss.elastic.co/t/hashing-in-elasticsearch/336470>\
**Category:** Elasticsearch\
**Created:** [June 20, 2023, 11:14am UTC](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470 "2023-06-20T11:14:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [June 20, 2023, 11:14am UTC](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470/1 "2023-06-20T11:14:08Z")

</div>

Hello Team,

We have a requirement to store an array of 100,000 users in an Elasticsearch field. During search, we need to match if a user exists in that array and return the corresponding document.

Is it possible to achieve this using hashing or any other approach?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 20, 2023, 11:57am UTC](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470/2 "2023-06-20T11:57:55Z")

</div>

Why not using just the standard search on text?

But yes you can compute a fingerprint with: [Fingerprint processor | Elasticsearch Guide [8.8] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/fingerprint-processor.html)

---

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [June 22, 2023, 3:43am UTC](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470/3 "2023-06-22T03:43:17Z")

</div>

Hi @dadoonet,

Thanks, We are using elastic5.6. Is there a way in elastic 5.6 version.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 22, 2023, 3:47am UTC](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470/4 "2023-06-22T03:47:48Z")

</div>

You will have to do this with Logstash or custom code then.

Also note that 5.X is very much [EOL](https://www.elastic.co/support/eol) and no longer supported, you should be looking to upgrade as a matter of urgency.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 22, 2023, 5:05am UTC](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470/5 "2023-06-22T05:05:08Z")

</div>

It sounds like this is a user persmissions field that you filter on. If this is the case I also assume you will be adding and/or removing users on a regular basis.

If this is the case you should be aware that updating very large documents (which this could be) is expensive. One way to handle this that I have seen in the past is to use a parent-child relationship where the parent is the document and the child is the permitted users. This does complicate querying as you would need to add an [has child query](https://www.elastic.co/guide/en/elasticsearch/reference/8.8/query-dsl-has-child-query.html) to every query you run, which would have a performance impact. You would need to benchmark to see the impact, but note that having single very large documents also can have negative performance side effects. Having potentially 100000 child objects may not be optimal, so a workaround could be to create a set number of child objects and hash users into these. If you have 100 child objects per document each could hold an array of 1000 users. This would result in smaller documents that are more efficient to update and modify.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2023, 5:05am UTC](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470/6 "2023-07-20T05:05:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
