# Ingest node 登録データと複数項目の突合せについて

**URL:** <https://discuss.elastic.co/t/ingest-node/223859>\
**Category:** 日本語による質問・議論はこちら\
**Created:** [March 17, 2020, 7:21am UTC](https://discuss.elastic.co/t/ingest-node/223859 "2020-03-17T07:21:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![harue](https://avatars.discourse-cdn.com/v4/letter/h/82dd89/32.png) [@harue](https://discuss.elastic.co/u/harue)\
**Post date:** [March 17, 2020, 7:21am UTC](https://discuss.elastic.co/t/ingest-node/223859/1 "2020-03-17T07:21:48Z")

</div>

お世話になります。

下記質問の投稿が説明不足であったため、再度投稿させて頂きます。

> [@Ingest node 複数項目の突合せについて](https://discuss.elastic.co/t/ingest-node/223435):
>
> お世話になります。 ▼実現したいこと 取り込むログと予め用意したリスト(下記参照)とを突き合わせて、突合せ結果をindexに登録 例) ID,IP 100,10.169.1.1 ,10.169.1.2 ▼取り込むログとの突合せ条件 1行目…IDが"100"かつIPが"10.169.1.1"であれば真 2行目…ソースIPが"10.169.1.2"であれば真 2行目の条件(1項目の突合せ)はenrich processorにて可能ですが、 1行目の条件(複数項目の突合せ)はenrich processorでは実現できないようです。 …enrich poricyの"match\_field"に複数項目を指定すると下記エラーになりました。 match\_field doesn't support values of type: START\_ARRAY" ingest nodeにて、1行目の条件を実現する方法はありますでしょうか？ お手数ですが、教えて頂けますと幸いです。

▼実現したいこと  
ingest nodeにて、インプットデータとindexA(下記参照)のデータを突き合わせて、突合せ結果をindexBに登録

indexAの例  
ID,IP  
100,10.169.1.1

インプットデータとindexAとの突合せ条件  
・IDが"100"かつIPが"10.169.1.1"の場合、indexBに"true"を登録  
・IDが"100"かつIPが"10.169.1.1"でない場合、indexBに"false"を登録

▼ご質問  
ingest nodeにて、上記を実現する方法はありますでしょうか？

script processorで実現できるか調べたところ、  
script processorではindexの参照が実施できないのではと思われます。

> [@Access data from different index using ingest pipeline](https://discuss.elastic.co/t/access-data-from-different-index-using-ingest-pipeline/197312):
>
> hi all, when a pipeline catches an index operation is there a way to query another index to get a specific field's value? I mean, if the current document will be indexed into index1 but I want to create also another field getting value from index2 is it possible to use ingest pipeline? Maybe using script processor? I know that I could use Logstash, but currently I cannot do it. regards

お手数ですが、教えて頂けますと幸いです。

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2020, 7:21am UTC](https://discuss.elastic.co/t/ingest-node/223859/2 "2020-04-14T07:21:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
