# Dashboard / Canvas based on two indices

**URL:** https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729
**Category:** Kibana
**Tags:** canvas
**Created:** [December 15, 2020, 3:24pm UTC](https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729 "2020-12-15T15:24:41Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![Itay\_Bittan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itay_bittan/32/23527_2.png) [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)
#### Post date: [December 15, 2020, 3:24pm UTC](https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729/1 "2020-12-15T15:24:41Z")

</div>

I have two indices: users & activities.  
Users index data looks like:

```auto
{
    "email": "alice@gmail.com",
    "Name": "Alice A"
},
{
    "email": "bob@gmail.com",
    "name": "Bob B"
},
...

```

activity index data looks like this:

```auto
{
    "@timestamp": "...",
    "email": "bob@gmail.com",
    "activity": "bob's first activity"
},
{
    "@timestamp": "...",
    "email": "bob@gmail.com",
    "activity": "bob's second activity"
}

```

I want to create a graph that counts the activities per user.  
I did something like this: ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d2081e5aec91b182b8514f09716d636f1c4394e.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/f/1f351951696b4ad09dedd9e2ed0bc42ad640630d.png)  
But I want to change the `email` with `name` field (from users index). I need to present real names in the legend.  
Is there a way to do that? `JOIN`?  
I don't mind to use visualization in dashboard or canvas / any other solution (rather than SQL) that supports that.

---

<div class="post-metadata">

### Author: ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)
#### Post date: [December 16, 2020, 6:28pm UTC](https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729/2 "2020-12-16T18:28:07Z")

</div>

This is currently not possible to do at query time (as it would require to join documents). You need to move this kind of enriching your event index into the ingest phase.

This sounds like a good use case for the enrich processor as part of an ingest pipeline: [https://www.elastic.co/guide/en/elasticsearch/reference/current/enrich-setup.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/enrich-setup.html)

---

<div class="post-metadata">

### Author: ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)
#### Post date: [December 16, 2020, 7:23pm UTC](https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729/3 "2020-12-16T19:23:32Z")

</div>

If your index isn't HUGE you can do this in Vega.

```auto
{
  "$schema": "https://vega.github.io/schema/vega/v5.json",
  "data": [
    {
      "name": "users",
      "url": {"index": "users", "body": {"size": 10000}},
      "format": {"property": "hits.hits"},
    },
    {
      "name": "data",
      "url": {"index": "activities", "body": {"size": 10000}},
      "format": {"property": "hits.hits"},
      "transform": [
        {
          "type": "lookup",
          "from": "users",
          "key": "email",
          "fields": ["name"],
          "as": ["obj"]
        },
        {
          "type": "project",
          "fields": [
            "obj._source.email",
            "obj._source.name",
            "_source.activity"
          ],
          "as": ["email", "name", "activity"]
        }
      ]
    }
  ]
}

```

Given your example documents the above produces 2 results which I believe is what you need. Would need to do an aggregation or 2 still to get counts but the start is there.

```auto
{
 "activity:" "bob's first activity",
 "email:" "bob@gmail.com",
 "name": "Bob B"
},
{
 "activity" "bob's second activity",
 "email": "bob@gmail.com",
 "name": "Bob B"
}

```

Also I'd still recommend doing this during ingest. This is just an option if required.

---

<div class="post-metadata">

### Author: ![Itay\_Bittan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itay_bittan/32/23527_2.png) [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)
#### Post date: [December 17, 2020, 4:27pm UTC](https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729/4 "2020-12-17T16:27:54Z")

</div>

Thanks,  
I wasn't familiar with Vega - look nice.  
Tried your snippet with no lack ☹ - no errors in Kibana but I get blank visualisation.

---

<div class="post-metadata">

### Author: ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)
#### Post date: [December 17, 2020, 4:38pm UTC](https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729/5 "2020-12-17T16:38:50Z")

</div>

I didn't do the visualization part. Just the data portion.

There is a lot left to do in Vega still for this and would require learning it first unfortunately.

The way I learned is going through the examples at [https://vega.github.io/vega/examples/](https://vega.github.io/vega/examples/) and then loading those in the editor and seeing what everything does.

---

<div class="post-metadata">

### Author: ![Itay\_Bittan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itay_bittan/32/23527_2.png) [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)
#### Post date: [December 17, 2020, 5:00pm UTC](https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729/6 "2020-12-17T17:00:47Z")

</div>

Thanks! I'll try & update!  
BTW, back to the HUGE index, with Vega, is it (the lookup) done in the client-side or server-side?

---

<div class="post-metadata">

### Author: ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)
#### Post date: [December 17, 2020, 5:04pm UTC](https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729/7 "2020-12-17T17:04:35Z")

</div>

Client side.

Say you do a query in Vega that returns 9,000 results all that data goes to the client and then processed. The max return by default is 10,000 so if you need to query above that you need update settings.

Also if you put a Vega visualization in a dashboard the UI loads for the dashboard and then the data processes for Vega. Meaning if it's a lot of data that visualization could appear a few seconds after the rest of the dashboard does.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 14, 2021, 5:04pm UTC](https://discuss.elastic.co/t/dashboard-canvas-based-on-two-indices/258729/8 "2021-01-14T17:04:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
