Splunk lookup file equivalent

When working with the Elastic Stack this is generally done at index time. Please see this blog post for a more detailed discussion.