# Create Visualize "Data Table" with join data

**URL:** https://discuss.elastic.co/t/create-visualize-data-table-with-join-data/107588
**Category:** Kibana
**Created:** [November 14, 2017, 4:38pm UTC](https://discuss.elastic.co/t/create-visualize-data-table-with-join-data/107588 "2017-11-14T16:38:37Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![karmax](https://avatars.discourse-cdn.com/v4/letter/k/45deac/32.png) [@karmax](https://discuss.elastic.co/u/karmax)
#### Post date: [November 14, 2017, 4:38pm UTC](https://discuss.elastic.co/t/create-visualize-data-table-with-join-data/107588/1 "2017-11-14T16:38:37Z")

</div>

Hi all,  
I write log in elastic with logstash and I get some data from logfile and some data from mysql with jdbc query.  
Now I need to concat this data.  
logfile contain this fields: ipaddress, timestamp, url  
mysql contain this fields: ipaddress, name  
I wish to show in Data Table url, ipaddress and name where ipaddress is unique id.

This is possible? How I can create this visualization?  
Thanks a lot

---

<div class="post-metadata">

### Author: ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)
#### Post date: [November 14, 2017, 8:44pm UTC](https://discuss.elastic.co/t/create-visualize-data-table-with-join-data/107588/2 "2017-11-14T20:44:26Z")

</div>

It sounds like each document in elasticsearch has the ipaddress and name field? If you want to join them together into a single field I recommend doing that in logstash, but another option is scripted fields, which you can use to create a third field that concatenates the two fields together into a synthetic field. Scripted fields are evaluated at query time, so they aren't as performant as an actual field, but if you want to experiment around a bit before updating your logstash config they are a great option.

---

<div class="post-metadata">

### Author: ![karmax](https://avatars.discourse-cdn.com/v4/letter/k/45deac/32.png) [@karmax](https://discuss.elastic.co/u/karmax)
#### Post date: [November 15, 2017, 10:59am UTC](https://discuss.elastic.co/t/create-visualize-data-table-with-join-data/107588/3 "2017-11-15T10:59:09Z")

</div>

> [@spalger](#):
>
> It sounds like each document in elasticsearch has the ipaddress and name field?

No spalger.  
logfile contain this fields: _ipaddress_, timestamp, url  
mysql contain this fields: _ipaddress_, **name**

I need to concat the fields of two different rows.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 13, 2017, 10:59am UTC](https://discuss.elastic.co/t/create-visualize-data-table-with-join-data/107588/4 "2017-12-13T10:59:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
