# 2 events in 1 visualize data table

**URL:** <https://discuss.elastic.co/t/2-events-in-1-visualize-data-table/93013>\
**Category:** Kibana\
**Created:** [July 13, 2017, 12:57pm UTC](https://discuss.elastic.co/t/2-events-in-1-visualize-data-table/93013 "2017-07-13T12:57:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![oded17](https://avatars.discourse-cdn.com/v4/letter/o/d6d6ee/32.png) [@oded17](https://discuss.elastic.co/u/oded17)\
**Post date:** [July 13, 2017, 12:57pm UTC](https://discuss.elastic.co/t/2-events-in-1-visualize-data-table/93013/1 "2017-07-13T12:57:18Z")

</div>

Hן

I gather events from application performance management ( dynatrace ) to elasticsearch.  
I wanted to know if there is a possibility to combine 2 events, each with the same variable, and display them together under data table - visualize in KIBANA. So that the table contains columns from the two events, with one field shared by both

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [July 13, 2017, 5:14pm UTC](https://discuss.elastic.co/t/2-events-in-1-visualize-data-table/93013/2 "2017-07-13T17:14:04Z")

</div>

I'm not 100% if I understand the use case, let me try to restate it.

You have two events, each with a field that contains a matching value, say `id`. You want to combine the values of other fields in these two documents to create a single column in a data table? For example if you have two documents that look like:

```auto
{ id: 1, foo: "bar" }
{ id: 1, baz: "qux" }

```

You'd like a table that looks something like this:

```auto
id | foo-baz
-----------------
1 | "bar", "qux"

```

Is that correct?

---

<div class="post-metadata">

**Author:** ![oded17](https://avatars.discourse-cdn.com/v4/letter/o/d6d6ee/32.png) [@oded17](https://discuss.elastic.co/u/oded17)\
**Post date:** [July 16, 2017, 7:06am UTC](https://discuss.elastic.co/t/2-events-in-1-visualize-data-table/93013/3 "2017-07-16T07:06:09Z")

</div>

no 🙂

the id:1 is in all events.  
I want to show in 1 data table, others fields from both events  
in event 1 fields  
id 1  
name oded  
city nyc

event 2 fields  
id 1  
gender male

so in the data table I will see  
id name city gender

1 oded nyc male

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [July 17, 2017, 2:36pm UTC](https://discuss.elastic.co/t/2-events-in-1-visualize-data-table/93013/4 "2017-07-17T14:36:05Z")

</div>

Ah I see. That'll prove to be difficult, Elasticsearch doesn't support joins. ES does have a parent/child feature, but Kibana doesn't support it yet. The usual way to get the view you want is to denormalize your data.

Depending on your data, you might be able to abuse the top\_hits agg to accomplish your goal though. Create a new data table vis. For the bucket, do a terms agg on your `ID` field. For each field you want to display as a column add a "Top Hit" metric. Configure the `size` parameter of the Top Hit metric to equal the number of documents you expect to match each ID (I'll assume two, since that's the example you gave). For the `Aggregate With` parameter, choose `Concatenate` . You should end up with something like this:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a378194f803e3425870c9bf45cc8db54af708cb9.png)

If this workaround doesn't work for you, I think denormalization may be your only option at the moment.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2017, 2:36pm UTC](https://discuss.elastic.co/t/2-events-in-1-visualize-data-table/93013/5 "2017-08-14T14:36:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
