# Log Enrichment with Logstash and the Elastic Filter Plugin - How to Handle Ordering / Relationships?

**URL:** <https://discuss.elastic.co/t/log-enrichment-with-logstash-and-the-elastic-filter-plugin-how-to-handle-ordering-relationships/36822>\
**Category:** Logstash\
**Created:** [December 10, 2015, 3:01am UTC](https://discuss.elastic.co/t/log-enrichment-with-logstash-and-the-elastic-filter-plugin-how-to-handle-ordering-relationships/36822 "2015-12-10T03:01:05Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Craig\_Roberts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craig_roberts/32/6511_2.png) [@Craig\_Roberts](https://discuss.elastic.co/u/Craig_Roberts)\
**Post date:** [December 11, 2015, 1:34am UTC](https://discuss.elastic.co/t/log-enrichment-with-logstash-and-the-elastic-filter-plugin-how-to-handle-ordering-relationships/36822/4 "2015-12-11T01:34:34Z")

</div>

Just to clarify that we were planning to use the [elasticsearch filter plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html) to retrieve previous data from Elastic for enrichment. This saves us the problem of retrieving extra data from the DB, but adds a problem of "how do I know site information has been saved and is available" when logging page views from within the same second.

This may sound like a contrived use-case, but it's just the simplest example - there are some other cases we need to do similar enrichment with a dependency on "created" events - sharing during creation is the first thing that comes to my head, and so on.

**Edit**

I have found a blog post - [Document Processing and Elasticsearch](https://www.elastic.co/blog/found-document-processing) which covers some of the options in more detail for us. There is also another discussion on this forum ([Post processing of aggregation data](https://discuss.elastic.co/t/post-processing-of-aggregation-data/24651)) where somebody is having a similar problem:

> We don't want to denormalize our event data to contain all of the other relevant info besides the ids [...] Anyone out there have a good solution for storing ids in elasticsearch but then being able to associate those ids with their labels (from another data store but can be made available via a rest endpoint or by syncing them into elasticsearch) for presentation purposes?

Obviously we will now be doing some reading around mappings and custom asynchronous plugins.

Ta,  
-- Craig

---

_[View the full topic](https://discuss.elastic.co/t/log-enrichment-with-logstash-and-the-elastic-filter-plugin-how-to-handle-ordering-relationships/36822)._
