# Datatable from two different documents but one common field

**URL:** <https://discuss.elastic.co/t/datatable-from-two-different-documents-but-one-common-field/125628>\
**Category:** Elasticsearch\
**Created:** [March 26, 2018, 2:37pm UTC](https://discuss.elastic.co/t/datatable-from-two-different-documents-but-one-common-field/125628 "2018-03-26T14:37:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![naveen\_kumar\_Reddy](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@naveen\_kumar\_Reddy](https://discuss.elastic.co/u/naveen_kumar_Reddy)\
**Post date:** [March 26, 2018, 2:37pm UTC](https://discuss.elastic.co/t/datatable-from-two-different-documents-but-one-common-field/125628/1 "2018-03-26T14:37:37Z")

</div>

Hi,

I have two documents as shown below in same index/module but different fileset

**Document 1:**

| Col1 | Col2 | Col3 |
| --- | --- | --- |
| a1 | b1 | c1 |
| a2 | b2 | c2 |

**Document 2:**

| T1 | T2 | T3 |
| --- | --- | --- |
| 123 | 456 | c1 |
| 111 | 222 | c2 |

Now, I need to have the data table as follows

| MyCol1 | MyCol2 | MyCol3 | MyCol4 |
| --- | --- | --- | --- |
| a1 | b1 | c1 | 123 |
| a2 | b2 | c2 | 111 |

Is this feasible? I'm fine to have new index creation, or new ingesting pipeline or whatever. Please suggest.

If not possible, what would be the best way to achieve such kind of result by still using ELK and Kibana tools?I believe this is kind of normal functionality expected by lot of people.

---

<div class="post-metadata">

**Author:** ![naveen\_kumar\_Reddy](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@naveen\_kumar\_Reddy](https://discuss.elastic.co/u/naveen_kumar_Reddy)\
**Post date:** [March 31, 2018, 1:39pm UTC](https://discuss.elastic.co/t/datatable-from-two-different-documents-but-one-common-field/125628/2 "2018-03-31T13:39:55Z")

</div>

I don't think there is a way to this in ELK So, we did some data modelling with the input files.

In our case, we are having two input files and we merged them together before publishing to ELK. Thus, the output file contains all of these columns. We have to be careful while merging though!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 31, 2018, 2:08pm UTC](https://discuss.elastic.co/t/datatable-from-two-different-documents-but-one-common-field/125628/3 "2018-03-31T14:08:55Z")

</div>

That's IMO the way to go.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2018, 2:09pm UTC](https://discuss.elastic.co/t/datatable-from-two-different-documents-but-one-common-field/125628/4 "2018-04-28T14:09:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
