# Dashboard with kibana

**URL:** <https://discuss.elastic.co/t/dashboard-with-kibana/334016>\
**Category:** Kibana\
**Created:** [May 22, 2023, 1:25pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016 "2023-05-22T13:25:36Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [May 22, 2023, 1:25pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/1 "2023-05-22T13:25:36Z")

</div>

Hello, I have two CSV files. One file contains the names of applications, and the other file contains information about a specific application. Both files have the "Host" column in common. I have imported these two files into Elasticsearch, each in a separate index. I would like to be able to match these two files in such a way that I can filter my dashboard to display information about a specific application.  
How can I achieve that?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [May 22, 2023, 1:54pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/2 "2023-05-22T13:54:42Z")

</div>

Hi @Hanni,

Can you explain what you mean by match on the host column and what kind of view you're trying to build on top of these indices?

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [May 22, 2023, 2:01pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/3 "2023-05-22T14:01:27Z")

</div>

I want to be able to create a dashboard in which there will be visualizations for each application, but I don't want it to display all the visualizations. I would like to filter it by the name of each application. However, the application names are located in a different index.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [May 22, 2023, 2:25pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/4 "2023-05-22T14:25:55Z")

</div>

Thanks for confirming @Hanni. I would recommend using something like an [enrich policy](https://www.elastic.co/guide/en/elasticsearch/reference/current/match-enrich-policy-type.html) to add the application values from the other index to the one with your metrics.

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [May 22, 2023, 2:27pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/5 "2023-05-22T14:27:57Z")

</div>

Is it not possible to create an index pattern with both files?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [May 22, 2023, 2:30pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/6 "2023-05-22T14:30:37Z")

</div>

If you don't need to connect things together and both indices have the application attribute you can [create a data view](https://www.elastic.co/guide/en/kibana/master/data-views.html) across multiple indices using a pattern and then build your dashboard on top.

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [May 23, 2023, 8:40am UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/7 "2023-05-23T08:40:43Z")

</div>

I am not sure I understand what you are saying.  
Let me put it in context.  
On the one hand, I have csv files that give us information about various applications. In a csv file we have information about a given application and so on.  
On the other hand I have another csv file that serves as a repository in which there is the name of each application.  
What the files have in common is the ip address of the application. I would like to be able to visualize each application and to be able to filter in the dashboard so that when we want information on an application the dashboard is updated. So to do this I need the app's com. I was asking how to match the files containing the information of the application and the referential file.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [May 23, 2023, 9:57am UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/8 "2023-05-23T09:57:50Z")

</div>

Hi @Hanni,

Appreciate the additional details. Elasticsearch isn't like a DB in the way that you join two tables together on a particular field, in this case the ip adddress. So it's not a case of matching the field between two indices.

You can use an enrichment processor to match the ip address fields between the two indices, and then output them into an enriched index with the application name value added to the respective document. Then you can build your dashboard on top on this enriched index.

I would recommend taking look at the below resources on enrichment processing:

1. [Example: Enrich data based on exact values](https://www.elastic.co/guide/en/elasticsearch/reference/current/match-enrich-policy-type.html)
2. [Set up an enrich processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/enrich-setup.html)
3. [How the enrich processor works](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest-enriching-data.html#how-enrich-works)

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [May 24, 2023, 11:48am UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/9 "2023-05-24T11:48:22Z")

</div>

Can I have an exemple?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [May 24, 2023, 1:07pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/10 "2023-05-24T13:07:04Z")

</div>

There's an example in the 1st link I've given above that walks through creation and execution of the enrich policy that you need. Is there something that you're unsure of in the example?

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [May 24, 2023, 1:12pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/11 "2023-05-24T13:12:15Z")

</div>

I had tried this :  
But I don't see the "Nom\_Application" add in my index

```auto
PUT _enrich/policy/app-enri
{
  "match": {
    "indices": ["app","referentiel"],
    "match_field": "ip",
    "enrich_fields": ["Nom_Application"]
  }
}

POST /_enrich/policy/app-enri/_execute

```

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [May 24, 2023, 1:30pm UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/12 "2023-05-24T13:30:49Z")

</div>

> [@Hanni](#):
>
> `POST /_enrich/policy/app-enri/_execute`

Thanks for confirming @Hanni. The `_execute` command for the enrichment policy creates the enrich index rather than add the fields. So you have a couple of steps to do to enrich your data into a new index:

1. Create an ingest pipeline. The above example gives the API steps, but you can also use the UI as an alternative which may be easier. See below example:

 ![Screenshot 2023-05-24 at 10.35.47](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0de236cdb610d8d83879683e970a9d583ad8f317.png)

1. Reindex your data into a new index using the ingest pipeline, which will make use of the policy you have created. The [reindex documentation has an example](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html#reindex-with-an-ingest-pipeline).

Give those additional steps a try and see if that gives you what you need.

---

<div class="post-metadata">

**Author:** ![Hanni](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Post date:** [May 30, 2023, 11:22am UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/13 "2023-05-30T11:22:50Z")

</div>

is it possible to automate this task? so that it is done automatically as soon as a new document is added to the index or a new index is added?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [May 31, 2023, 8:52am UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/14 "2023-05-31T08:52:28Z")

</div>

For a new document being added to an existing index, the ingest pipeline will enrich for each new document once you have set things up.

By a new index, do you mean creating a new index with it's own separate enrichment policy and ingest pipeline, or reusing the existing one? You should be able to script the steps using the [Ingest API as per the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest-apis.html).

Hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2023, 8:53am UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016/15 "2023-06-28T08:53:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
