# Combining logs based on timestamp

**URL:** <https://discuss.elastic.co/t/combining-logs-based-on-timestamp/90849>\
**Category:** Logstash\
**Created:** [June 26, 2017, 4:04pm UTC](https://discuss.elastic.co/t/combining-logs-based-on-timestamp/90849 "2017-06-26T16:04:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![infamous](https://avatars.discourse-cdn.com/v4/letter/i/df705f/32.png) [@infamous](https://discuss.elastic.co/u/infamous)\
**Post date:** [June 26, 2017, 4:04pm UTC](https://discuss.elastic.co/t/combining-logs-based-on-timestamp/90849/1 "2017-06-26T16:04:54Z")

</div>

Hi all,

Im looking at ways to combine 2 distinct event logs only if their respective timestamps are the same. The 2 logs will be from different sources (2 different files). I am hoping to do this aggregation at time of ingestion, but I am also willing to do it after both files are already in Elasticsearch.

I've looked into both the elasticsearch filter and the aggregate filter, but they do not seem to be what I need. Any suggestions on where to start?

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2017, 4:05pm UTC](https://discuss.elastic.co/t/combining-logs-based-on-timestamp/90849/2 "2017-07-24T16:05:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
