# Combining documents in two indices correlated by their ID, but the fieldname is different

**URL:** <https://discuss.elastic.co/t/combining-documents-in-two-indices-correlated-by-their-id-but-the-fieldname-is-different/294933>\
**Category:** Kibana\
**Tags:** transforms\
**Created:** [January 20, 2022, 10:47am UTC](https://discuss.elastic.co/t/combining-documents-in-two-indices-correlated-by-their-id-but-the-fieldname-is-different/294933 "2022-01-20T10:47:56Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 21, 2022, 10:41am UTC](https://discuss.elastic.co/t/combining-documents-in-two-indices-correlated-by-their-id-but-the-fieldname-is-different/294933/8 "2022-01-21T10:41:52Z")

</div>

> [@Is is possible to partially update a dest doc with transforms?](https://discuss.elastic.co/t/is-is-possible-to-partially-update-a-dest-doc-with-transforms/209808/4):
>
> Hi, a transform can have multiple sources and they do not need a common schema as long as the field name of the group\_by is compatible. So if you have for example a field "customer\_id" in both indices "past\_purchases" and "predicted\_purchases" you can create a transform that joins over both indices: PUT \_transform/prediction\_accuracy { "source": { "index": ["past\_purchases", "predicted\_purchases"] }, "pivot": { "group\_by": { "id": {"terms": { "field": "customer\_id" …

> [@How to aggregate data on elastic sent by logstash](https://discuss.elastic.co/t/how-to-aggregate-data-on-elastic-sent-by-logstash/205140/2):
>
> Hi, you should be able to do this using transform (see [https://www.elastic.co/guide/en/elasticsearch/reference/7.4/put-transform.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/put-transform.html)). The workflow would look like this: you index the data into elasticsearch as single docs, this is the "source" index you create a transform that pulls data from the "source" and aggregates it according to your needs into a "dest" index. In your case you would group by entity Id, firm id, etc. and define aggregations, e.g. lastUpdated would be a max aggregatio…

> [@How to join two index](https://discuss.elastic.co/t/how-to-join-two-index/274572/3):
>
> I like to add another option: [transform](https://www.elastic.co/guide/en/elasticsearch/reference/current/transforms.html). A transform in a nutshell is a task that runs aggregation queries and persists the result in an index. In order to join 2 indices you need compatible mappings for grouping, e.g. a key that is named the same way and has the same type. Note, this can be achieved with scripts or runtime fields, however if you want to run in it continuously at scale, it is advised to use proper ordinary mappings. For the group\_by use terms on the common key. For the aggreg…

To use transform to join multiple indices is not straight forward, but these posts will help you to use transform.

---

_[View the full topic](https://discuss.elastic.co/t/combining-documents-in-two-indices-correlated-by-their-id-but-the-fieldname-is-different/294933)._
