# Compare two fields

**URL:** <https://discuss.elastic.co/t/compare-two-fields/273069>\
**Category:** Elasticsearch\
**Created:** [May 14, 2021, 10:25pm UTC](https://discuss.elastic.co/t/compare-two-fields/273069 "2021-05-14T22:25:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gal\_Segal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gal_segal/32/88797_2.png) [@Gal\_Segal](https://discuss.elastic.co/u/Gal_Segal)\
**Post date:** [May 14, 2021, 10:25pm UTC](https://discuss.elastic.co/t/compare-two-fields/273069/1 "2021-05-14T22:25:59Z")

</div>

Hi,

I am new to elastic and was hoping you can help me.  
I am using elastic to collect logs from both packetbeat to my 'packetbeat' index, and filebeat to my 'filebeat' index.  
I have an IP field in both of the indexes and I would like to trigger an alert if there's a match (if IP from packetbeat index log appears in IP field of filebeat index log)

for example:

"\_index": "packetbeat-7.12.1-2021.05.14-000001",  
"\_type": "\_doc",  
"fields": {  
"source.ip": [  
"192.168.0.100"  
],}

and

"\_index": "filebeat-7.12.1-2021.05.14-000001",  
"\_type": "\_doc",  
"fields": {  
"recipientIP": [  
"192.168.0.100"  
],}

since source.ip = recipientIP -\> trigger an alert.

What is the method of doing so?  
I am using managed version of elastic stack (cloud) and using the web console to perform the alerts (not python or anything like that)

Thank you in advance

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 15, 2021, 10:41am UTC](https://discuss.elastic.co/t/compare-two-fields/273069/2 "2021-05-15T10:41:32Z")

</div>

In a relational database this would be a join, which is something Elasticsearch does not support as it scales badly in distributed systems with large amounts of data. You might be able to create a separate index using a [transform](https://www.elastic.co/guide/en/elasticsearch/reference/7.12/transform-apis.html) where you have a document per IP address and record which stream it has been seen in. This would allow you to query this index directly which would be easier and faster.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2021, 10:42am UTC](https://discuss.elastic.co/t/compare-two-fields/273069/3 "2021-06-12T10:42:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
