# Compare 2 tables and add matching field in second table to first table

**URL:** <https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781>\
**Category:** Elasticsearch\
**Created:** [January 9, 2016, 9:39am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781 "2016-01-09T09:39:47Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [January 9, 2016, 9:39am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/1 "2016-01-09T09:39:47Z")

</div>

How can I Compare 2 tables and add matching field in second table to first table. Not sure what query syntax should I use

Table 1

Field1  
1020  
1021  
1022  
1023  
1025

Table2  
Field1 FieldX  
1021 "Good"  
1023 "Bad"

Result  
Table3  
Field 1 FieldX  
1020  
1021 "Good"  
1022  
1023 "Bad"  
1025

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 10, 2016, 12:38am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/2 "2016-01-10T00:38:28Z")

</div>

Are you taking data from a database here?

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [January 10, 2016, 6:20am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/3 "2016-01-10T06:20:19Z")

</div>

The data is stored in elastic search. I am just using the term "tables" to illustrate my problem as I am still not very familiar with elasticsearch terms.

Assuming I have loaded the two "Tables" into elasticsearch. How should I write the query to accomplish the previously mentioned scenario?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 10, 2016, 9:03am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/4 "2016-01-10T09:03:22Z")

</div>

You probably mean an index then.

But no, you cannot do this within ES, you would need to do it in your application code.

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [January 11, 2016, 1:15am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/5 "2016-01-11T01:15:08Z")

</div>

I am looking at accomplishing this in the query as I am not sure if doing at the application code level will allow me to pass the result into Kibana.

Can I do this?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 11, 2016, 1:16am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/6 "2016-01-11T01:16:52Z")

</div>

Nope.

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [January 13, 2016, 5:20am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/7 "2016-01-13T05:20:10Z")

</div>

🙂 Thanks

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [April 6, 2016, 6:57am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/8 "2016-04-06T06:57:55Z")

</div>

Can I use logstash to input 2 index at one go and can try to match the contents of one index with the content of the other

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 6, 2016, 7:47am UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/9 "2016-04-06T07:47:57Z")

</div>

Maybe with a ruby script, or the fingerprint filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:02pm UTC](https://discuss.elastic.co/t/compare-2-tables-and-add-matching-field-in-second-table-to-first-table/38781/10 "2017-07-05T23:02:00Z")

</div>


