Home / Companies / Elastic / Blog / Post Details
Content Deep Dive

ES|QL Joins are here! Yes, Joins!

Blog post from Elastic

Post Details
Company
Date Published
Author
Tyler Perkins
Word Count
1,737
Company Posts That Month
41
Language
English
Hacker News Points
-
Post removed?
No
Summary

Elasticsearch 8.18 introduces a new feature, the ES|QL’s LOOKUP JOIN command, marking the first SQL-style JOIN capability within the platform, available in a tech preview. This feature allows for data correlation and enrichment by using easily updatable lookup datasets, enabling users to integrate additional information such as host and asset details into events without significant data preparation. Unlike previous attempts like nested and _parent join field types, LOOKUP JOIN utilizes a new index mode called 'lookup', which is limited to a single shard with a maximum of 2 billion documents to enhance performance and scalability. This new capability simplifies the process of managing relational data without the need for denormalization and allows for more comprehensive analytical functions, such as grouping and aggregating data. Elastic plans to further develop this feature, enabling more join types and improving the user experience.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.