# Correlating information from different indexes

**URL:** <https://discuss.elastic.co/t/correlating-information-from-different-indexes/134249>\
**Category:** Kibana\
**Created:** [June 1, 2018, 3:28pm UTC](https://discuss.elastic.co/t/correlating-information-from-different-indexes/134249 "2018-06-01T15:28:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 1, 2018, 3:28pm UTC](https://discuss.elastic.co/t/correlating-information-from-different-indexes/134249/1 "2018-06-01T15:28:55Z")

</div>

Hi, this is something I have already found in several discussions here and in other places, but I would like to ask for your advice because I'm still not sure about which is the best solution.

I have data coming from a CSV formatted as follows:

```
timestamp;id;value

```

And I would like to create Visualizations based on other parameters which are present in another CSV which correlates id with other parameters.  
For example, apparently on Kibana I can't configure a stacked-bar visualization based on timestamp and values from one index differentiating the stacks for another parameter which is cointained in another index.

I see from other questions that one solution could be to add this information when parsing the CSV with Logstash using the Elasticsearch plugin.  
I'm wondering if there are other (easier) options.

Thank you

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [June 1, 2018, 4:56pm UTC](https://discuss.elastic.co/t/correlating-information-from-different-indexes/134249/2 "2018-06-01T16:56:41Z")

</div>

Elasticsearch has no notion of joins or something similar. Your best bet is to merge the data at ingest time and put that merged data into an index.

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 2, 2018, 12:42pm UTC](https://discuss.elastic.co/t/correlating-information-from-different-indexes/134249/3 "2018-06-02T12:42:30Z")

</div>

I'm trying with Elasticsearch plugin for Logstash, but I'm receiving this error from Logstash:

```
[LogStash::Runner] ERROR logstash.plugins.registry - Problems loading a plugin with {:type=>"filter", :name=>"elasticsearch", :path=>"logstash/filters/elasticsearch", :error_message=>"NameError", :error_class=>NameError, :error_backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:226:in `namespace_lookup'", "/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:162:in `legacy_lookup'", "/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:138:in `lookup'", "/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:180:in `lookup_pipeline_plugin'", "/usr/share/logstash/logstash-core/lib/logstash/plugin.rb:140:in `lookup'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:103:in `plugin'", "(eval):93:in `initialize'", "org/jruby/RubyKernel.java:1079:in `eval'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:75:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:165:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:296:in `create_pipeline'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:95:in `register_pipeline'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:313:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:67:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:204:in `run'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:132:in `run'", "/usr/share/logstash/lib/bootstrap/environment.rb:71:in `(root)'"]}
[LogStash::Runner] ERROR logstash.agent - Cannot create pipeline {:reason=>"Couldn't find any filter plugin named 'elasticsearch'. Are you sure this is correct? Trying to load the elasticsearch filter plugin resulted in this error: Problems loading the requested plugin named elasticsearch of type filter. Error: NameError NameError"}

```

I'm running Logstash on a Docker container.  
Do you have any idea what's going on?

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 2, 2018, 4:30pm UTC](https://discuss.elastic.co/t/correlating-information-from-different-indexes/134249/4 "2018-06-02T16:30:30Z")

</div>

I think this is a useful link to start: [https://www.elastic.co/blog/elasticsearch-docker-plugin-management](https://www.elastic.co/blog/elasticsearch-docker-plugin-management)

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 4, 2018, 6:28am UTC](https://discuss.elastic.co/t/correlating-information-from-different-indexes/134249/5 "2018-06-04T06:28:50Z")

</div>

I found the solution creating a new container installing the filter plugin `logstash-filter-elasticsearch` [https://www.elastic.co/guide/en/logstash/current/filter-plugins.html](https://www.elastic.co/guide/en/logstash/current/filter-plugins.html)

The new Dockerfile can be simple as explained here: [https://hub.docker.com/\_/logstash/](https://hub.docker.com/_/logstash/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2018, 6:29am UTC](https://discuss.elastic.co/t/correlating-information-from-different-indexes/134249/6 "2018-07-02T06:29:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
