# Combining Events Based on Common session\_id Field

**URL:** <https://discuss.elastic.co/t/combining-events-based-on-common-session-id-field/180627>\
**Category:** Kibana\
**Created:** [May 11, 2019, 12:26am UTC](https://discuss.elastic.co/t/combining-events-based-on-common-session-id-field/180627 "2019-05-11T00:26:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MakoWish](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Post date:** [May 11, 2019, 12:27am UTC](https://discuss.elastic.co/t/combining-events-based-on-common-session-id-field/180627/1 "2019-05-11T00:27:00Z")

</div>

Good afternoon, all! I first have to say I am very new to ElasticSearch, so I would appreciate some assistance here.

I have a firewall that sends a few different types of logs for the same event, but in a different category. For instance, if someone connects to a site of ours on port 443, I will see something similar to the following (truncated):

event\_type: session\_event  
src\_ip: x.x.x.x  
src\_port: 16864  
src\_interface: external  
dst\_ip: x.x.x.x  
dst\_port: 443  
dst\_interface: internal  
session\_id: 101906080442957

That is fine and dandy, but this does not show what the actual firewall did with the event. The firewall event is a separate log message resembling something like:

event\_type: firewall\_event  
action: blocked  
reason: ACL  
session\_id: 101906080442957

I would like to be able to search for (and display) the combined event details so I can not only see the source and destination details, but whether or not the connection was allowed or blocked by the firewall. All related events share a common "session\_id" that I would think we could pivot on, but I am not sure how to do this. Any ideas?

Thank you all in advance for the assistance!

EDIT: To note... this is all in the same index.

Eric

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [May 13, 2019, 5:39pm UTC](https://discuss.elastic.co/t/combining-events-based-on-common-session-id-field/180627/2 "2019-05-13T17:39:26Z")

</div>

@MakoWish

Are all your events, of both types (firewall and session) in the same index?

What you could do is make a data-table as a Kibana Visualization.

- use a terms-aggregation on `session_id` to split rows
- add a top-hit metrics for all other fields you would like to see
  - src\_ip
  - dst\_ip
  - action
  - ...

If you have a single ``session\_event corresponding to a single `firewall_event`, it should produce a table where each row is a session-id with a column for each of those fields.

fwiw, this is a tough one using Elasticsearch, in the way that data is modeled.

Generally, how users approach this is that they denormalize the data at ingest-time by ensuring each individual document combines the events from both sources.

---

<div class="post-metadata">

**Author:** ![MakoWish](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Post date:** [May 14, 2019, 10:13pm UTC](https://discuss.elastic.co/t/combining-events-based-on-common-session-id-field/180627/3 "2019-05-14T22:13:28Z")

</div>

Hi Thomas,

Thank you for the reply! These different events are actually from the same "Untangle" firewall, and yes they are all in the same index.

I will try the terms-aggregation on `session_id` to split rows.

I am not sure it would be possible to join the messages at ingest. They are coming from the same source, and there are three or more messages per session. Here is a very rudimentary example of what comes through:

session\_id: 1, type: "session\_start", message: "Connection established from..."  
session\_id: 2, type: "session\_start", message: "Connection established to..."  
session\_id: 1, type: "session\_stats", bytes\_received: 640, time\_elapsed: 31  
session\_id: 1, type: "session\_close", message: "Connection terminated..."  
session\_id: 2, type: "session\_stats", bytes\_sent: 1024, time\_elapsed: 65  
session\_id: 2, type: "session\_stats", bytes\_sent: 512, time\_elapsed: 127  
session\_id: 2, type: "sessino\_close", message: "Connection terminated..."

Is it possible to combine these messages in Logstash? In this example, there are three total events for session\_id 1, and four total events for session\_id 2. I am thinking your terms-aggregation idea would be easiest to just combine them during search, but that would be fantastic to combine them to a single event at ingest.

Thank you,  
Eric

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2019, 10:13pm UTC](https://discuss.elastic.co/t/combining-events-based-on-common-session-id-field/180627/4 "2019-06-11T22:13:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
