# Display data from collection1 not in collection2

**URL:** <https://discuss.elastic.co/t/display-data-from-collection1-not-in-collection2/91771>\
**Category:** Kibana\
**Created:** [July 4, 2017, 12:31pm UTC](https://discuss.elastic.co/t/display-data-from-collection1-not-in-collection2/91771 "2017-07-04T12:31:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bterhorst](https://avatars.discourse-cdn.com/v4/letter/b/c57346/32.png) [@bterhorst](https://discuss.elastic.co/u/bterhorst)\
**Post date:** [July 4, 2017, 12:31pm UTC](https://discuss.elastic.co/t/display-data-from-collection1-not-in-collection2/91771/1 "2017-07-04T12:31:04Z")

</div>

Hello,

I have events of different types for example: registered|in\_transit|processed  
These events are correlated by an ID.

If an event is "registered" but the "in\_transit" event is not yet in elastic, I would like the ID's of these "in\_transit" events to be displayed.

Would it be possible to display the above situation in Kibana?  
If this is not possible in Kibana what other solutions are there?

Any help would be greatly appreciated!

Regards Benny

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 4, 2017, 4:05pm UTC](https://discuss.elastic.co/t/display-data-from-collection1-not-in-collection2/91771/2 "2017-07-04T16:05:24Z")

</div>

Hi @bterhorst,

I can't think of a way to do that kind of correlation across documents in Kibana right now, because it only supports a subset of the pipeline aggregations available in Elasticsearch.

If you create your own visualization tool you could use a [`terms` aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/search-aggregations-bucket-terms-aggregation.html) on the ids followed by a [`top_hits aggregation`](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/search-aggregations-metrics-top-hits-aggregation.html) that includes your type field. Then you could use that in a [`bucket_selector` pipeline aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/search-aggregations-pipeline-bucket-selector-aggregation.html) to filter out all id buckets that have both the "registered" and " in\_transit" types.

---

<div class="post-metadata">

**Author:** ![bterhorst](https://avatars.discourse-cdn.com/v4/letter/b/c57346/32.png) [@bterhorst](https://discuss.elastic.co/u/bterhorst)\
**Post date:** [July 5, 2017, 7:50am UTC](https://discuss.elastic.co/t/display-data-from-collection1-not-in-collection2/91771/3 "2017-07-05T07:50:03Z")

</div>

Hi Felix,

Thank you for your reply. I will certainly look in to that.

Would it be good practice to make a call to elastic and retrieve the corresponding "registered" event when the "in\_transit" event arrives. I could then add a field to it in order to identify it. This way if it does not have that field I know the "in\_transit" in not yet present.  
Or would you advise against this approach?

Regards benny

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 5, 2017, 7:53am UTC](https://discuss.elastic.co/t/display-data-from-collection1-not-in-collection2/91771/4 "2017-07-05T07:53:02Z")

</div>

Yes, doing this during ingestion is definitely a possibility and provides the best performance. If you are using Logstash to ingest your data the [Elasticsearch filter](https://www.elastic.co/guide/en/logstash/5.4/plugins-filters-elasticsearch.html) could help you with that.

---

<div class="post-metadata">

**Author:** ![bterhorst](https://avatars.discourse-cdn.com/v4/letter/b/c57346/32.png) [@bterhorst](https://discuss.elastic.co/u/bterhorst)\
**Post date:** [July 5, 2017, 7:55am UTC](https://discuss.elastic.co/t/display-data-from-collection1-not-in-collection2/91771/5 "2017-07-05T07:55:37Z")

</div>

Okay ....thanks for the quick feedback!

Regards benny

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2017, 7:55am UTC](https://discuss.elastic.co/t/display-data-from-collection1-not-in-collection2/91771/7 "2017-08-03T07:55:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
