# Can we join multiple index in Logstash after reading for elasticsearch and then create a new index

**URL:** <https://discuss.elastic.co/t/can-we-join-multiple-index-in-logstash-after-reading-for-elasticsearch-and-then-create-a-new-index/220086>\
**Category:** Logstash\
**Created:** [February 20, 2020, 5:13am UTC](https://discuss.elastic.co/t/can-we-join-multiple-index-in-logstash-after-reading-for-elasticsearch-and-then-create-a-new-index/220086 "2020-02-20T05:13:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stephy\_Jacob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephy_jacob/32/45032_2.png) [@Stephy\_Jacob](https://discuss.elastic.co/u/Stephy_Jacob)\
**Post date:** [February 20, 2020, 5:13am UTC](https://discuss.elastic.co/t/can-we-join-multiple-index-in-logstash-after-reading-for-elasticsearch-and-then-create-a-new-index/220086/1 "2020-02-20T05:13:15Z")

</div>

Hi Team,  
I have my data of three different views ingested in Elasticsearch as three different indices. Now I have a requirement to create a Dashboard in Kibana with the combination of data from three views. So now I need to ingest the data again after joining and then create a new index in elasticsearch as elasticsearch does not support join in 6.6.  
Can we use Logstash in this case? As in can we read all three elasticsearch indices to Logstash, do the join transformation in logstash and ingest it back to elasticsearch as a new index and then build visualizations on that index.

---

<div class="post-metadata">

**Author:** ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)\
**Post date:** [February 21, 2020, 7:25am UTC](https://discuss.elastic.co/t/can-we-join-multiple-index-in-logstash-after-reading-for-elasticsearch-and-then-create-a-new-index/220086/2 "2020-02-21T07:25:20Z")

</div>

Hi,

combining indices can be done with [Transform](https://www.elastic.co/guide/en/elasticsearch/reference/current/transforms.html), however you need at least 7.3.

Can you provide more information, best with some data examples (If you do not want to leak information, rename the fields and put in some generic values in the example)?

With an index pattern that has all 3 indices in it, you might not even need to re-ingest but can directly query the 3 indices with 1 search request. But again, that's highly data dependent and depends on whether joining data has to be done on document level before visualization.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2020, 7:25am UTC](https://discuss.elastic.co/t/can-we-join-multiple-index-in-logstash-after-reading-for-elasticsearch-and-then-create-a-new-index/220086/3 "2020-03-20T07:25:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
