# Correlate field

**URL:** <https://discuss.elastic.co/t/correlate-field/82992>\
**Category:** Elasticsearch\
**Created:** [April 20, 2017, 7:01am UTC](https://discuss.elastic.co/t/correlate-field/82992 "2017-04-20T07:01:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Marcou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_marcou/32/17519_2.png) [@John\_Marcou](https://discuss.elastic.co/u/John_Marcou)\
**Post date:** [April 20, 2017, 7:01am UTC](https://discuss.elastic.co/t/correlate-field/82992/1 "2017-04-20T07:01:23Z")

</div>

Hello,

Sorry if my question is a bit easy, but I didn't find any way to do this request, and I am getting to wonder if it's really possible ...

# Init

PUT /test-index  
PUT /test-index/user/1  
{  
"name": "John",  
"connID": "44"  
}  
PUT /test-index/connection/1  
{  
"connID": "44",  
"ip\_source": "8.8.8.8"  
}

# Search

I would like to write a request to return:

- "John" : "8.8.8.8"

This little test is actually to correlate real data log from python app and firewalls logs.

Thank you for you help.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 20, 2017, 7:32am UTC](https://discuss.elastic.co/t/correlate-field/82992/2 "2017-04-20T07:32:23Z")

</div>

Joins are not supported in elasticsearch unless you are using parent/child feature.

A better approach is to create a flat document containing all that info.

---

<div class="post-metadata">

**Author:** ![John\_Marcou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_marcou/32/17519_2.png) [@John\_Marcou](https://discuss.elastic.co/u/John_Marcou)\
**Post date:** [April 20, 2017, 7:59am UTC](https://discuss.elastic.co/t/correlate-field/82992/3 "2017-04-20T07:59:41Z")

</div>

Thank you David for you reply.

Do you know if joins are not supported by conception/design, or if it is plan to implement this feature in future ?

Does this means there is no way to do logs correlation on the fly (I mean post-indexation) with ELK ?  
(I push logs from filebeat directly to ES)

Thank you.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 20, 2017, 8:42am UTC](https://discuss.elastic.co/t/correlate-field/82992/4 "2017-04-20T08:42:52Z")

</div>

By design. You can see a whole discussion here:

> <https://github.com/elastic/elasticsearch/pull/3278>

If you want to do something like this without pre-processing your data or without paren/child feature, you can have a look at the Graph feature available in X-Pack (commercial licence).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 8:52am UTC](https://discuss.elastic.co/t/correlate-field/82992/5 "2017-05-18T08:52:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
