In Splunk we can do the lookup during the query time
lookup sn_instances ip AS ip, node AS port OUTPUTNEW name AS nodename
Is it possible to something similar in elastic?
I know Logstash filters [csv, jdbc, .. etc] using which we can transform the data in logstash. But once data is indexed if we want to any additional transformations, can we do it?
My use case is : I am ingesting the data with simple schema which contains only timestamp and message fields. In message fields I have a IP and port, using Painless script i can extract these two fields, using these two extracted fields I want to do lookup [csv or DB ... ] which should give some readable name for this combination. Please let me know how to achieve this functionality?