# Combine different logs in one data table

**URL:** https://discuss.elastic.co/t/combine-different-logs-in-one-data-table/130993
**Category:** Kibana
**Created:** [May 8, 2018, 11:50am UTC](https://discuss.elastic.co/t/combine-different-logs-in-one-data-table/130993 "2018-05-08T11:50:31Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![SunGirl](https://avatars.discourse-cdn.com/v4/letter/s/eb8c5e/32.png) [@SunGirl](https://discuss.elastic.co/u/SunGirl)
#### Post date: [May 8, 2018, 11:50am UTC](https://discuss.elastic.co/t/combine-different-logs-in-one-data-table/130993/1 "2018-05-08T11:50:31Z")

</div>

Hi! I have 2 different source logs with several common fields, e.g. field1 and field2, other fields are different.  
How can I join all fields from these different sources in one index by field1 and field2 in a data table? It returns "no results found" when selecting all these fields in data table. But there are equal values of field1 and field2 in both source logs.  
Thank you!

---

<div class="post-metadata">

### Author: ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)
#### Post date: [May 8, 2018, 1:50pm UTC](https://discuss.elastic.co/t/combine-different-logs-in-one-data-table/130993/2 "2018-05-08T13:50:41Z")

</div>

Hi @SunGirl,

Can you see the data in the Discover tab? Could it be an issue with the time filter at the top?

---

<div class="post-metadata">

### Author: ![SunGirl](https://avatars.discourse-cdn.com/v4/letter/s/eb8c5e/32.png) [@SunGirl](https://discuss.elastic.co/u/SunGirl)
#### Post date: [May 8, 2018, 2:12pm UTC](https://discuss.elastic.co/t/combine-different-logs-in-one-data-table/130993/3 "2018-05-08T14:12:22Z")

</div>

HI!)  
Yes, I see them in discover tab.  
Logs with the same field1 and field2 value have different timestamp, but I don`t select @timestamp field in the result data table.  
Just an example:  
Log1: ip, cmd, @timestamp  
Log2: ip, country, @timestamp

And I just want ip, cmd, country in one data table. And I have records with the same ip in both logs, though @timestamp differs at several minutes.

---

<div class="post-metadata">

### Author: ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)
#### Post date: [May 8, 2018, 3:14pm UTC](https://discuss.elastic.co/t/combine-different-logs-in-one-data-table/130993/4 "2018-05-08T15:14:34Z")

</div>

Hi @SunGirl,

I'm not exactly sure what you want to do, but this might help.

You can create a table like this with your sample data if you use a scripted field to create a synthetic field for the two fields that do not exist in both indices.

 ![07%20AM](https://us1.discourse-cdn.com/elastic/original/3X/6/7/6788dcb44911272399edb024cdffc6b287f5df04.png)

Scripted field:

```auto
def cmd = '';
try {
  cmd = doc['cmd.keyword'].value;
} catch (Exception e) { }

def country = '';
try {
  country = doc['country.keyword'].value;
} catch (Exception e) {}

return cmd + country;

```

---

<div class="post-metadata">

### Author: ![SunGirl](https://avatars.discourse-cdn.com/v4/letter/s/eb8c5e/32.png) [@SunGirl](https://discuss.elastic.co/u/SunGirl)
#### Post date: [May 14, 2018, 9:43am UTC](https://discuss.elastic.co/t/combine-different-logs-in-one-data-table/130993/5 "2018-05-14T09:43:07Z")

</div>

Thank you very much!!!)  
And maybe is there another way how to do it? Because in documentation it`s written "Computing data on the fly with scripted fields can be very resource intensive and can have a direct impact on Kibana’s performance".

So I want to join row2 and row3 by ip.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/2/c28214b120484af1ff021eaa5e4e26aaa73adbb8.png)

---

<div class="post-metadata">

### Author: ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)
#### Post date: [June 7, 2018, 8:37pm UTC](https://discuss.elastic.co/t/combine-different-logs-in-one-data-table/130993/6 "2018-06-07T20:37:50Z")

</div>

Unfortunately, that's the only way I know of. The other route is to update your mappings to include a field for this and reindex your data

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2018, 8:37pm UTC](https://discuss.elastic.co/t/combine-different-logs-in-one-data-table/130993/7 "2018-07-05T20:37:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
