Ingest node

Use an ingest node to pre-process documents before the actual document indexing happens. The ingest node intercepts bulk and index requests, it applies transformations, and it then passes the documents back to the index or bulk APIs.

All nodes enable ingest by default, so any node can handle ingest tasks. You can also create dedicated ingest nodes. To disable ingest for a node, configure the following setting in the elasticsearch.yml file:

node.ingest: false

To pre-process documents before indexing, define a pipeline that specifies a series of processors. Each processor transforms the document in some specific way. For example, a pipeline might have one processor that removes a field from the document, followed by another processor that renames a field. The cluster state then stores the configured pipelines.

To use a pipeline, simply specify the pipeline parameter on an index or bulk request. This way, the ingest node knows which pipeline to use. For example:

PUT my-index/_doc/my-id?pipeline=my_pipeline_id
{
  "foo": "bar"
}

An index may also declare a default pipeline that will be used in the absence of the pipeline parameter.

See Ingest APIs for more information about creating, adding, and deleting pipelines.