# Ingest pipeline execute external command or call rest?

**URL:** <https://discuss.elastic.co/t/ingest-pipeline-execute-external-command-or-call-rest/98264>\
**Category:** Elasticsearch\
**Created:** [August 24, 2017, 4:49pm UTC](https://discuss.elastic.co/t/ingest-pipeline-execute-external-command-or-call-rest/98264 "2017-08-24T16:49:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zachary\_Buckholz](https://avatars.discourse-cdn.com/v4/letter/z/f1d935/32.png) [@Zachary\_Buckholz](https://discuss.elastic.co/u/Zachary_Buckholz)\
**Post date:** [August 24, 2017, 4:49pm UTC](https://discuss.elastic.co/t/ingest-pipeline-execute-external-command-or-call-rest/98264/1 "2017-08-24T16:49:38Z")

</div>

I'd like to know if it's possible to execute an external command from an ingest pipeline?

My usecase is to do a unix dig command on an IP and see who owns it. We have Akamai fronting a lot of our web traffic and I'd like to identify Akamai requests.

Manually I can take an IP and execute the following:

$ dig -x 88.221.222.138

; \<\<\>\> DiG 9.8.3-P1 \<\<\>\> -x 88.221.222.138  
;; global options: +cmd  
;; Got answer:  
;; -\>\>HEADER\<\<- opcode: QUERY, status: NOERROR, id: 12542  
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:  
;138.222.221.88.in-addr.arpa. IN PTR

;; ANSWER SECTION:  
138.222.221.88.in-addr.arpa. 86400 IN PTR [a88-221-222-138.deploy.akamaitechnologies.com](http://a88-221-222-138.deploy.akamaitechnologies.com).

;; Query time: 136 msec  
;; SERVER: 2001:578:3f::30#53(2001:578:3f::30)  
;; WHEN: Thu Aug 24 09:44:14 2017  
;; MSG SIZE rcvd: 104

I'd like to grep for that [akamaitechnologies.com](http://akamaitechnologies.com) like and flag the request as from Akamai and update a field.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 25, 2017, 8:08am UTC](https://discuss.elastic.co/t/ingest-pipeline-execute-external-command-or-call-rest/98264/2 "2017-08-25T08:08:05Z")

</div>

Hey,

this is not possible. We dont want to introduce blocking calls into the ingest infrastructure. You could do that with writing your own processor, but this also implies that your ingestion pipeline and thus your capability to index documents depends on the availibility of external services. Maybe indexing first and then having a second process that uses a scroll search is a better idea, or use the update API later in time.

--Alex

---

<div class="post-metadata">

**Author:** ![Zachary\_Buckholz](https://avatars.discourse-cdn.com/v4/letter/z/f1d935/32.png) [@Zachary\_Buckholz](https://discuss.elastic.co/u/Zachary_Buckholz)\
**Post date:** [August 26, 2017, 1:27pm UTC](https://discuss.elastic.co/t/ingest-pipeline-execute-external-command-or-call-rest/98264/3 "2017-08-26T13:27:09Z")

</div>

Totally makes sense. Thanks for the response. I will investigate what you mentioned.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2017, 1:27pm UTC](https://discuss.elastic.co/t/ingest-pipeline-execute-external-command-or-call-rest/98264/4 "2017-09-23T13:27:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
