Can we join two index fields in one index


(Vinay Garg) #1

Hi All,

Environment:
ELK 5.5

We are having two index of different logs (haproxy-index and fuselog-index).
Both index having different grok pattern.
but in haproxy grok pattern having three fields
'col1-ID':1
'col2-Name':'Testing'
'col3-Service':'Test'

FuseLog grok pattern
'col1-ID':1
'col2-Date':'2017-08-17'
'col3-IP':'0.0.0.0'

But grok pattern having same col1-ID field.
Is it possible to join fields of two index in one index? as mention in below example
'col1-ID':1
'col2-Name':'Testing'
'col3-IP':'0.0.0.0'


(Mark Walkom) #2

FYI we’ve renamed ELK to the Elastic Stack, otherwise Beats feels left out :wink:

No it is not, it's not possible to joins in Elasticsearch at all.


(Vinay Garg) #3

So can you give any other idea to solve it?


(Mark Walkom) #4

What is the problem you are trying to solve?


(Vinay Garg) #5

I have to monitor 200,500,502,504 response code from haproxy log. Based on i have to define fuse log pattern. So that i can easily rectify where the 200,500,502,504 response occur.
I hope it is clear.


(Mark Walkom) #6

That can be handled by grok.


(Vinay Garg) #7

Thanks for share you input.


(system) #8

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.