# How to use ingest pipelines and processors

**URL:** <https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576>\
**Category:** Kibana\
**Tags:** ingest-pipeline\
**Created:** [July 25, 2021, 8:16pm UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576 "2021-07-25T20:16:19Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ailengcon](https://avatars.discourse-cdn.com/v4/letter/a/85f322/32.png) [@ailengcon](https://discuss.elastic.co/u/ailengcon)\
**Post date:** [July 25, 2021, 8:16pm UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/1 "2021-07-25T20:16:19Z")

</div>

So thankful if someone could help me out.

I have synced data from a mongodb to elastic with Monstache. Some of the data is mapped so when I make searches, the presentation of the data is rather messy and unstructured, not in the way it is suppose to be in database. Aggregations and such works fine, it's just that I want the user to be able to have the data presented so they can find the values they are looking for quicker.

I have attached images of how I want it to look like (1st image from from Robo3T), and how it looks in Kibana (Second image). It sort of groups the fields separately. I wonder if I can use an ingest pipeline to alter the mapping somehow? But not sure which processor to use? I can't find any good tutorials or instructions for this?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73a16e59e7be152acdb31454484d0fadb7b01475.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/2/82492865b40df042bbff22303ac178b7cd56689d.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 25, 2021, 11:45pm UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/2 "2021-07-25T23:45:32Z")

</div>

Welcome to our community! 😃

Can you share a little more of what you see in Kibana, as it's lacking some context.

---

<div class="post-metadata">

**Author:** ![ailengcon](https://avatars.discourse-cdn.com/v4/letter/a/85f322/32.png) [@ailengcon](https://discuss.elastic.co/u/ailengcon)\
**Post date:** [July 26, 2021, 4:30am UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/3 "2021-07-26T04:30:28Z")

</div>

Sure, so Parameters is an array and should be grouped for each index, as image one above. But instead this is what I get.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/e/fed809673c3a17825beec16495b8aaa55b6af9cd.png)

So if I want to look at this document's parameter index 67 to see what the value of that index is, it would be really annoying because I have to count manually to find it in this mess. Sure I can search for it so that it is highlighted, but my employer (who I am evaluating elastic for) want to be able to examine the different parameters in a document to get a good overview, therefore it needs the original structure (image one in the original post).

Hope this helps, and that there is a way for me to alter it. Thank you.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 26, 2021, 6:14am UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/4 "2021-07-26T06:14:39Z")

</div>

What does that look like as a json doc rather than that view?

---

<div class="post-metadata">

**Author:** ![ailengcon](https://avatars.discourse-cdn.com/v4/letter/a/85f322/32.png) [@ailengcon](https://discuss.elastic.co/u/ailengcon)\
**Post date:** [July 26, 2021, 6:38am UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/5 "2021-07-26T06:38:38Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d3e3137f9ded19c4268012d771897898acd175a4.png)

Like this. Does it help?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 26, 2021, 6:40am UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/6 "2021-07-26T06:40:52Z")

</div>

Yeah, it looks like you only have one single document, which seems odd.  
Does mongo only have a single document in it with all these values?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 26, 2021, 10:45pm UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/8 "2021-07-26T22:45:15Z")

</div>

Ah ok, thanks for clearing that up.

If you want to have something like the `n elements` or `n fields` values, you could probably add that `n` count with a [script processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/script-processor.html) that will iterate through and create it.

---

<div class="post-metadata">

**Author:** ![ailengcon](https://avatars.discourse-cdn.com/v4/letter/a/85f322/32.png) [@ailengcon](https://discuss.elastic.co/u/ailengcon)\
**Post date:** [July 27, 2021, 6:21am UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/9 "2021-07-27T06:21:00Z")

</div>

I'm sorry, I'm not sure I understand. I can see that the instruction is a console example also, isn't there any tutorial that is on another level?

Also not sure if I understand "n elements"... Thank you for all you help, sorry if I'm not getting it.

I need to sync the data all over again, right? to use the pipeline?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8d363e4da60ebae4fd8861bf64e8cef86e6dc172.png)  
This example is super clear, but I am not sure how to insert the fields I want to change so that I do it right.

---

<div class="post-metadata">

**Author:** ![ailengcon](https://avatars.discourse-cdn.com/v4/letter/a/85f322/32.png) [@ailengcon](https://discuss.elastic.co/u/ailengcon)\
**Post date:** [July 28, 2021, 11:46am UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/10 "2021-07-28T11:46:13Z")

</div>

Maybe index template is what I'm looking for to make it work?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 4, 2021, 12:18am UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/11 "2021-08-04T00:18:24Z")

</div>

You basically want to have a document that has a field showing the total count of value in another field. eg;

```auto
parameters: [list of parameters here]
parameters_count: [a count of the above parameters]

```

At least that is what I am understanding based on the above posts.

---

<div class="post-metadata">

**Author:** ![ailengcon](https://avatars.discourse-cdn.com/v4/letter/a/85f322/32.png) [@ailengcon](https://discuss.elastic.co/u/ailengcon)\
**Post date:** [August 4, 2021, 5:48am UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/12 "2021-08-04T05:48:07Z")

</div>

No not exaclty, or maybe - I started a new topic on it ( [[Index templates](https://discuss.elastic.co/t/index-templates/279952)] ) where maybe it's easier to understan. I at least want it structured the same way as in the database. I tried using index template but that resulted in elastic apparently making (millions) more documents than there is. (I read about it having something to do with the nested datatype)?

I started a new thread and got the advice to bring the topic to Elasticsearch instead of KIbana. I can do so, I also got a tip trying to use mongoconnector of some sort instead of monstache to synd the data. But I can't find any good instructions or tutorial on that. Can this help fix this issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2021, 5:48am UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-and-processors/279576/13 "2021-09-01T05:48:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
