# Lookup during query time

**URL:** <https://discuss.elastic.co/t/lookup-during-query-time/176190>\
**Category:** Elasticsearch\
**Created:** [April 10, 2019, 9:50am UTC](https://discuss.elastic.co/t/lookup-during-query-time/176190 "2019-04-10T09:50:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ravitandur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravitandur/32/4568_2.png) [@ravitandur](https://discuss.elastic.co/u/ravitandur)\
**Post date:** [April 10, 2019, 9:50am UTC](https://discuss.elastic.co/t/lookup-during-query-time/176190/1 "2019-04-10T09:50:12Z")

</div>

In Splunk we can do the lookup during the query time  
Example:  
lookup sn\_instances ip AS ip, node AS port OUTPUTNEW name AS nodename

Is it possible to something similar in elastic?

I know Logstash filters [csv, jdbc, .. etc] using which we can transform the data in logstash. But once data is indexed if we want to any additional transformations, can we do it?

My use case is : I am ingesting the data with simple schema which contains only timestamp and message fields. In message fields I have a IP and port, using Painless script i can extract these two fields, using these two extracted fields I want to do lookup [csv or DB ...] which should give some readable name for this combination. Please let me know how to achieve this functionality?

Thanks,  
Ravi

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 10, 2019, 10:03am UTC](https://discuss.elastic.co/t/lookup-during-query-time/176190/2 "2019-04-10T10:03:44Z")

</div>

No, this is something you typically do at index time when working with Elasticsearch. Please see [this blog post](https://www.elastic.co/blog/schema-on-write-vs-schema-on-read) for further details.

---

<div class="post-metadata">

**Author:** ![ravitandur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravitandur/32/4568_2.png) [@ravitandur](https://discuss.elastic.co/u/ravitandur)\
**Post date:** [April 10, 2019, 11:11am UTC](https://discuss.elastic.co/t/lookup-during-query-time/176190/3 "2019-04-10T11:11:18Z")

</div>

Thank you Christian.  
But below is my use case.  
Application is generating the log entries into specific log file.  
i.e. in single log file we have many formats and it depends on developer and we don't have any control over the format of the log.  
As log is having many formats, so we can't apply any grok filter during the index time.

In this case, the only option is to extract the required fields at query time and do the lookup.  
Can we do the lookup in painless script? or some other place?

Thanks,  
Ravi

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 10, 2019, 3:25pm UTC](https://discuss.elastic.co/t/lookup-during-query-time/176190/4 "2019-04-10T15:25:01Z")

</div>

Not that I know of. Doing all this work at query time will be very slow and is generally not the best way to work with Elasticsearch in my opinion. If you want to continue doing analysis this way, which is what Splunk was designed for, why not stick with Splunk?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2019, 3:25pm UTC](https://discuss.elastic.co/t/lookup-during-query-time/176190/5 "2019-05-08T15:25:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
