hi
I couldn't find a proper example of enriching outcome of a search query using external lookup/DB-table
I'm looking for something like..
<my search>
| lookup ip within {external lookup file or DB table}
| if ip is present, find its corresponding hostname ; else default it to "uknown_host"
| print ip, hostname
how to achieve this in elasticsearch?
PS: I don't want to index the external lookup-file nor DB table to Elastic
Why not doing that at index time instead?
If you want to search/display a hostname instead of an IP address, just index that information at index time within the same document and you're done.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.