Looking around on this, is there a guide somewhere (noob guide) that shows how to periodically aggregate data from two sources in my default time index (logs from filebeat to logstash to elasticsearch) to a new index based on my search criteria?
eg. want to bundle up matching data from default index (2 sources) to new index that combines the 2 sources on a matching field and then feed that into Kib
but how do i do this search and create index?
thanks 1000 times