# Combine two index in one using Kibana

**URL:** https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673
**Category:** Kibana
**Tags:** reindex
**Created:** [November 18, 2024, 6:45am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673 "2024-11-18T06:45:40Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![amity.nidhi](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@amity.nidhi](https://discuss.elastic.co/u/amity.nidhi)
#### Post date: [November 18, 2024, 6:45am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/1 "2024-11-18T06:45:40Z")

</div>

Hello,

I have a requirement to combine two index in Elasticsearch on basis of below criteria -  
index1:  
Record1: {"service": "abc", "opened\_at":"2024-11-04T16:48:04.000Z","closed\_at":"2024-11-05T18:00:10.000Z")  
Record2: {"service": "abc", "opened\_at":"2024-11-06T16:48:04.000Z","closed\_at":"2024-11-07T18:00:10.000Z")

index2:  
Record1: {"service": "abc", "opened\_at":"2024-11-06T16:48:04.000Z","closed\_at":"2024-11-17T18:00:10.000Z")  
Record2: {"service": "abc", "opened\_at":"2024-11-10T16:48:04.000Z","closed\_at":"2024-11-17T18:00:10.000Z")

So I want to correalet both of them on basis of service for example service and closed time on index 1 correlate to index2 service same and open time should be more than the closed time in index1 and less then the closed time of next record .  
In that case index1 record1 will correlate to index2 record 1 .

Please suggest.

---

<div class="post-metadata">

### Author: ![ashishtiwari1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashishtiwari1993/32/135241_2.png) [@ashishtiwari1993](https://discuss.elastic.co/u/ashishtiwari1993)
#### Post date: [November 18, 2024, 1:46pm UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/2 "2024-11-18T13:46:23Z")

</div>

Hi @amity.nidhi Welcome to the Elastic community. Do you want to fetch all records which satisfying above conditions? or do you want to perform some calculation ? You can simply perform query on both the index `index1,index2`.

---

<div class="post-metadata">

### Author: ![amity.nidhi](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@amity.nidhi](https://discuss.elastic.co/u/amity.nidhi)
#### Post date: [November 19, 2024, 9:01am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/3 "2024-11-19T09:01:01Z")

</div>

I want to fetch all records satisfying this condition and present it in dashboard

---

<div class="post-metadata">

### Author: ![ashishtiwari1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashishtiwari1993/32/135241_2.png) [@ashishtiwari1993](https://discuss.elastic.co/u/ashishtiwari1993)
#### Post date: [November 20, 2024, 6:19am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/4 "2024-11-20T06:19:17Z")

</div>

You can achieve this using [script query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-script-query.html). Could you help us with your index mapping and sample document index query. I will try to build query accordingly. thanks

---

<div class="post-metadata">

### Author: ![amity.nidhi](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@amity.nidhi](https://discuss.elastic.co/u/amity.nidhi)
#### Post date: [November 22, 2024, 3:05am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/5 "2024-11-22T03:05:21Z")

</div>

Hello @ashishtiwari1993 , Sorry I dont have much experience with elasticsearch . Can you please help to elaborate.

---

<div class="post-metadata">

### Author: ![amity.nidhi](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@amity.nidhi](https://discuss.elastic.co/u/amity.nidhi)
#### Post date: [November 22, 2024, 3:19am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/6 "2024-11-22T03:19:45Z")

</div>

Can I use python for this purpose ?  
But i am not sure where should i schedule

---

<div class="post-metadata">

### Author: ![amity.nidhi](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@amity.nidhi](https://discuss.elastic.co/u/amity.nidhi)
#### Post date: [November 27, 2024, 10:04am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/7 "2024-11-27T10:04:25Z")

</div>

Hello @ashishtiwari1993 , can you please help to share some example . the data i shared in my post is a sample data itself.

---

<div class="post-metadata">

### Author: ![ashishtiwari1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashishtiwari1993/32/135241_2.png) [@ashishtiwari1993](https://discuss.elastic.co/u/ashishtiwari1993)
#### Post date: [November 27, 2024, 12:36pm UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/8 "2024-11-27T12:36:03Z")

</div>

HI @amity.nidhi, Could you sample data as you mentioned above but still it is unclear to perform poc. Let's assume you've below records -

```auto
POST index1/_doc
{
  "service": "abc",
  "opened_at": "2024-11-04T16:48:04.000Z",
  "closed_at": "2024-11-05T18:00:10.000Z"
}

POST index1/_doc
{
  "service": "abc",
  "opened_at": "2024-11-06T16:48:04.000Z",
  "closed_at": "2024-11-07T18:00:10.000Z"
}

POST index2/_doc
{
  "service": "abc",
  "opened_at": "2024-11-06T16:48:04.000Z",
  "closed_at": "2024-11-17T18:00:10.000Z"
}

POST index2/_doc
{
  "service": "abc",
  "opened_at": "2024-11-10T16:48:04.000Z",
  "closed_at": "2024-11-17T18:00:10.000Z"
}

```

Now on which condition you expecting which documents ? Correlation we can do basis on service name but could you give more explanation around your conditions?

---

<div class="post-metadata">

### Author: ![amity.nidhi](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@amity.nidhi](https://discuss.elastic.co/u/amity.nidhi)
#### Post date: [December 2, 2024, 2:29am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/9 "2024-12-02T02:29:32Z")

</div>

Hello Ashish ,  
I want to combine both records when closed\_at in index1 is less that in index2

For Example :-  
record in index1 doc1 have close\_at time 2024-11-05T18:00:10.000Z which is less than opened at time in index2 doc1 so to create index3 with additional field in index2  
POST index3/\_doc  
{  
"service": "abc",  
"opened\_at": "2024-11-06T16:48:04.000Z",  
"closed\_at": "2024-11-17T18:00:10.000Z"  
"dependentonindex1" : "yes-reference-record-from-index1"  
}

Similarly it should correlate others.

---

<div class="post-metadata">

### Author: ![amity.nidhi](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@amity.nidhi](https://discuss.elastic.co/u/amity.nidhi)
#### Post date: [December 2, 2024, 2:46am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673/10 "2024-12-02T02:46:15Z")

</div>

Here are some sample Data -

Index 1:

``index 1  
1.{  
"\_index": "change\_test",  
"\_type": "\_doc",  
"\_id": "adqddqw",  
"fields": {  
"opene\_at":  
[  
"2024-12-01T23:00:46.000Z"  
],  
"state": [  
"Closed"  
],  
"closed\_at": [  
"2024-12-02T02:00:46.000Z"  
],  
"business\_service":  
[  
"test1"  
],  
"change\_number":  
[  
"CH123"  
]  
}  
}

1. 

{  
"\_index": "change\_test",  
"\_type": "\_doc",  
"\_id": "adqddqw",  
"fields": {  
"opene\_at":  
[  
"2024-12-02T23:00:46.000Z"  
],  
"state": [  
"Closed"  
],  
"closed\_at": [  
"2024-12-03T23:00:46.000Z"  
],  
"business\_service":  
[  
"test1"  
],  
"change\_number":  
[  
"CH456"  
]  
}  
}`

Index 2

{  
"\_index": "incident\_test",  
"\_type": "\_doc",  
"\_id": "adqddqw",  
"fields": {  
"opene\_at":  
[  
"2024-12-02T03:00:46.000Z"  
],  
"state": [  
"Closed"  
],  
"closed\_at": [  
"2024-12-02T04:00:46.000Z"  
],  
"business\_service":  
[  
"test1"  
],  
"incident\_number":  
[  
"INC321"  
]  
}  
}

In this case create index3 with correlation as business service and closed\_at in index1 should be greater that doc1 but less than doc2.  
so that first record in index2 correlate to only first record in in index1 not not second record
