# Elasticsearch parent child mergin two tables together

**URL:** <https://discuss.elastic.co/t/elasticsearch-parent-child-mergin-two-tables-together/72456>\
**Category:** Elasticsearch\
**Created:** [January 23, 2017, 9:37am UTC](https://discuss.elastic.co/t/elasticsearch-parent-child-mergin-two-tables-together/72456 "2017-01-23T09:37:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [January 23, 2017, 9:37am UTC](https://discuss.elastic.co/t/elasticsearch-parent-child-mergin-two-tables-together/72456/1 "2017-01-23T09:37:37Z")

</div>

How do I do something like a JOIN in elasticsearch. I have 2 index

"\_index": "blacklist1", "\_type": "logs", "\_id": "KS8CI-XKSID8DKSLAKS"

"\_index": "raw\_firewall\_logs", "\_type": "logs", "\_id": "SADLFSJFOI3098WOIJFD",

Assuming in "raw\_firewall\_logs" I have a field "source\_ip" that contains "123.123.123.1"

Assuming in "blacklist1" I have a field "block\_ip" that contains "123.123.123.1" and a field "threat\_type" containing "worm"

How should I update my mapping and how should I query so that I can see the following

{"source\_ip": "123.123.123.1", "blacklist1": "Yes", "blacklist1": "worm"}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 24, 2017, 7:52am UTC](https://discuss.elastic.co/t/elasticsearch-parent-child-mergin-two-tables-together/72456/2 "2017-01-24T07:52:51Z")

</div>

You need to do this at index time, you cannot join like this.

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [February 8, 2017, 2:03am UTC](https://discuss.elastic.co/t/elasticsearch-parent-child-mergin-two-tables-together/72456/3 "2017-02-08T02:03:59Z")

</div>

Can I know what is index time?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 8, 2017, 9:07pm UTC](https://discuss.elastic.co/t/elasticsearch-parent-child-mergin-two-tables-together/72456/4 "2017-02-08T21:07:21Z")

</div>

When you send the data to ES to be stored.

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [February 9, 2017, 12:54am UTC](https://discuss.elastic.co/t/elasticsearch-parent-child-mergin-two-tables-together/72456/5 "2017-02-09T00:54:25Z")

</div>

Do you have any examples on one index joining with other indexes at index time?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 9, 2017, 7:22am UTC](https://discuss.elastic.co/t/elasticsearch-parent-child-mergin-two-tables-together/72456/6 "2017-02-09T07:22:03Z")

</div>

I would recommend reading [the section on data modelling from the Definitive Guide](https://www.elastic.co/guide/en/elasticsearch/guide/current/relations.html). For many use cases the best way is to simply denormalise the data prior to indexing it into Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2017, 7:22am UTC](https://discuss.elastic.co/t/elasticsearch-parent-child-mergin-two-tables-together/72456/7 "2017-03-09T07:22:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
