# Reference Tables in Elastic

**URL:** <https://discuss.elastic.co/t/reference-tables-in-elastic/301369>\
**Category:** Elasticsearch\
**Created:** [April 1, 2022, 7:54pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369 "2022-04-01T19:54:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matthew\_Dominic\_Ramp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_dominic_ramp/32/103606_2.png) [@Matthew\_Dominic\_Ramp](https://discuss.elastic.co/u/Matthew_Dominic_Ramp)\
**Post date:** [April 1, 2022, 7:54pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369/1 "2022-04-01T19:54:52Z")

</div>

Scenario:

- I have a multi-field index which stores documents, 'index a', which has a field "id" whose value is a hexadecimal number
- i have another index 'b' which stores a list of id's and their corresponding string names
- i would like to use index b as a reference table for index a so that instead of displaying the hex digits i can display the matched string on kibana.

Is this possible using elastic? This sort of resembles how an inner join/where query would work in sql.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 1, 2022, 8:05pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369/2 "2022-04-01T20:05:49Z")

</div>

It is possible, but since Elasticsearch does not support JOINs, you would need to add the information from `index b` in the documents from `index a`.

This could be done when ingesting the data.

There are a couple of ways to do that, it will depend on how you are sending your data to Elasticsearch.

If you are sending it directly to Elasticsearch, you can use an ingest pipeline with an enrich processor to [enrich your data](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest-enriching-data.html).

If you are using Logstash, you can use a couple of filters to do that.

---

<div class="post-metadata">

**Author:** ![Matthew\_Dominic\_Ramp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_dominic_ramp/32/103606_2.png) [@Matthew\_Dominic\_Ramp](https://discuss.elastic.co/u/Matthew_Dominic_Ramp)\
**Post date:** [April 1, 2022, 8:07pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369/3 "2022-04-01T20:07:30Z")

</div>

would this work if we are ingesting the data using the bulk api?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 1, 2022, 8:14pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369/4 "2022-04-01T20:14:10Z")

</div>

Yes.

Using the bulk API means that you are sending your logs making requests directly to Elasticsearch, so you need create an [ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html) with the [enrich processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/enrich-setup.html).

Then you have two options, pass the ingest pipeline directly on the [request](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html#add-pipeline-to-indexing-request), or add the ingest pipeline to your [template](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules.html) as the `index.default_pipeline` or `index.final_pipeline`.

---

<div class="post-metadata">

**Author:** ![Matthew\_Dominic\_Ramp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_dominic_ramp/32/103606_2.png) [@Matthew\_Dominic\_Ramp](https://discuss.elastic.co/u/Matthew_Dominic_Ramp)\
**Post date:** [April 1, 2022, 8:15pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369/5 "2022-04-01T20:15:01Z")

</div>

okay thank you. I will look into this. I appreciate your help

---

<div class="post-metadata">

**Author:** ![Matthew\_Dominic\_Ramp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_dominic_ramp/32/103606_2.png) [@Matthew\_Dominic\_Ramp](https://discuss.elastic.co/u/Matthew_Dominic_Ramp)\
**Post date:** [April 4, 2022, 5:14pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369/6 "2022-04-04T17:14:23Z")

</div>

Hey @leandrojmp ! I got the pipeline working for one of my policies and i had a few followup questions:

- is it possible, and if so what is the syntax or example, to have more than one enrich policy included in a single pipeline?
- how/where can i include this pipeline into the template as you mentioned? I am unsure of the syntax

I have searched for examples on these but have not found anything useful. Any examples would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 4, 2022, 5:44pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369/7 "2022-04-04T17:44:29Z")

</div>

You can have as many `enrich` processors you want in your pipeline, the example in the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-match-enrich-policy-type.html#geo-match-enrich-policy-type) shows how to add a enrich processor in an ingest pipeline.

To add another enrich, you just add another processor to the pipeline, this can be done using a API Request or using the Kibana Interface, which is easier.

```auto
PUT /_ingest/pipeline/ingest-pipeline-name
{
    "processors": [
        {
            "enrich": {
             "description": "description one",
             "policy_name": "enrich_policy_1",
             "field": "source_field_1",
             "target_field": "target_field_1"
            },
            "enrich": {
                "description": "description two",
                "policy_name": "enrich_policy_2",
                "field": "source_field_2",
                "target_field": "target_field_2"
            }
        }
    ]
}

```

To specify a `default_pipeline` or a `final_pipeline` in the template, you put in the settings section, the same place where you have the `number_of_shards` or `number_of_replcas`.

For example, considering the settings part of a component template, to set the `default_pipeline` you will need something like this:

```auto
{
    "template": {
        "settings" : {
            "index" : {
              "refresh_interval" : "30s",
              "number_of_shards" : "1",
              "number_of_replicas" : "1",
              "default_pipeline": "pipeline-name"
            }
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![Matthew\_Dominic\_Ramp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_dominic_ramp/32/103606_2.png) [@Matthew\_Dominic\_Ramp](https://discuss.elastic.co/u/Matthew_Dominic_Ramp)\
**Post date:** [April 4, 2022, 6:24pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369/8 "2022-04-04T18:24:12Z")

</div>

@leandrojmp thank you so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2022, 6:24pm UTC](https://discuss.elastic.co/t/reference-tables-in-elastic/301369/9 "2022-05-02T18:24:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
