A feature request - would really like the ability to enrich documents going through an ingest pipeline with fields from documents in another elasticsearch index.
I’m sure this has many use cases, but for SIEM use, enriching IP addresses against threat intel.
Absolutely. We are looking into it. Would you be ok for us to connect with you offline to share some of our approach and seek your feedback? Please DM and I’ll schedule a call with the team.