# Event Correlation \\ populate one field with data from other field in elasticsearch

**URL:** <https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372>\
**Category:** Logstash\
**Created:** [July 13, 2016, 5:52am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372 "2016-07-13T05:52:00Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 13, 2016, 5:52am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/1 "2016-07-13T05:52:00Z")

</div>

Hi,  
i'm looking to do correlation searches in elastic (kibana 4.4 actually) is there a way to have a search like the following -  
1 - find all ip addresses from a certain type (lets say from critical stack intel, via filebeat to logstash and elastic)  
2 - find all outgoing connections with bro ids that feeds the elk (via filebeat to logstash and elastic)  
i want to bring only ips that hosts were outgoing to in bro ids, and are also found in the feeds of critical stack intel, is it possible?

OR - is there a way to do that directly in Logstash?  
like working with logstash plugin "elasticsearch" like in this link -  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html)

as follows -  
if [type] == "end" {  
elasticsearch {  
hosts =\> ["es-server"]  
query =\> "type:start AND operation:%{[opid]}"  
fields =\> ["@timestamp", "started"]  
}

Thanks

Shai

---

<div class="post-metadata">

**Author:** ![muhamadli302](https://avatars.discourse-cdn.com/v4/letter/m/b4bc9f/32.png) [@muhamadli302](https://discuss.elastic.co/u/muhamadli302)\
**Post date:** [July 13, 2016, 11:25am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/2 "2016-07-13T11:25:44Z")

</div>

I have a similar problem, would be happy to get some advice

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 13, 2016, 9:32pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/3 "2016-07-13T21:32:20Z")

</div>

You can't do this in KB, best to do it in LS during processing like you have done there.

Our Graph plugin will also be able to do some of this, it's part of our X-Pack.

---

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 13, 2016, 9:34pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/4 "2016-07-13T21:34:08Z")

</div>

How is it possible in logstash?  
can you give me an example or a link?

Thanks A lot

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 13, 2016, 9:34pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/5 "2016-07-13T21:34:50Z")

</div>

Like what you have in the OP, with the Elasticsearch filter.

---

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 13, 2016, 9:36pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/6 "2016-07-13T21:36:42Z")

</div>

> [@shaigb](#):
>
> as follows - if [type] == "end" { elasticsearch { hosts =\> ["es-server"] query =\> "type:start AND operation:%{[opid]}" fields =\> ["@timestamp", "started"]

yeah but when i insert the field part, it doesn't insert the data with the original event, only what i give to as static text and not the field as parameter.

---

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 14, 2016, 6:58am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/7 "2016-07-14T06:58:00Z")

</div>

Hi,

Here is my filter part where I query and try to do the match and insert to the original field:  
elasticsearch {  
hosts =\> ["localhost"]  
query =\> "type:maltrail AND dst\_ip:%{dst\_ip}"  
add\_field =\> ["reason" , "maltrail['reason']" ]  
}

---

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 17, 2016, 8:33am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/8 "2016-07-17T08:33:52Z")

</div>

Hi Mark,

Could you give me an example for that ?  
for some reason it's not working for me. I can only get the data as static (as in 'field name') to get into the field that I want, it does not pull the actual data into it.

Thanks

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [July 17, 2016, 2:29pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/9 "2016-07-17T14:29:15Z")

</div>

add\_field is not the right option.

Here's the good configuration to do what you want :

```
elasticsearch {
         hosts => ["localhost"]
        query => "type:maltrail AND dst_ip:%{dst_ip}"
        fields => ["reason"]
 }

```

it will copy 'reason' field from elasticsearch result to your current logstash event.

---

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 18, 2016, 6:27am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/10 "2016-07-18T06:27:09Z")

</div>

Hi

After changing the configuration this is the error i'm getting in logstash log. here's the config and the error:

input {  
beats {  
port =\> 5044  
ssl =\> false

ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
filter {  
if [type] == "conn" {  
grok {  
tag\_on\_failure =\> ["connlog\_long\_parse\_fail"]  
match =\> {"message" =\> [".?\s+.?\s+(?\d+.\d+.\d+.\d+)\s\S+\s(?\d+.\d+.\d+.\d+)"] }  
}  
elasticsearch {  
hosts =\> ["localhost"]  
query =\> "type:maltrail AND dst\_ip:%{dst\_ip}"  
fields =\> ["reason"]  
}  
geoip {  
source =\> "src\_ip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
geoip {  
source =\> "dst\_ip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

there's the log-

{:timestamp=\>"2016-07-18T09:10:18.083000+0300", :message=\>"Failed to query elasticsearch for previous event", :index=\>"", :query=\>"type:maltrail AND dst\_ip:172.16.1.10", :event=\>#@metadata\_accessors=#@store={"type"=\>"conn", "beat"=\>"filebeat"}, @lut={}\>, @cancelled=false, @data={"message"=\>"1468822199.963471\tC3gEHk1b9GOQXYX5Z3\t172.17.1.2\t45124\t172.16.1.10\t53\tudp\tdns\t0.026759\t0\t506\tSHR\tT\tT\t0\tCd\t0\t0\t1\t534\t(empty)\t-\t-\t#siftworkstation-eth0", "@version"=\>"1", "@timestamp"=\>"2016-07-18T06:10:17.432Z", "type"=\>"conn", "source"=\>"/nsm/bro/logs/current/conn.log", "count"=\>1, "fields"=\>nil, "beat"=\>{"hostname"=\>"siftworkstation", "name"=\>"siftworkstation"}, "offset"=\>504473, "input\_type"=\>"log", "host"=\>"siftworkstation", "tags"=\>["beats\_input\_codec\_plain\_applied"], "syslog\_severity\_code"=\>5, "syslog\_facility\_code"=\>1, "syslog\_facility"=\>"user-level", "syslog\_severity"=\>"notice", "src\_ip"=\>"172.17.1.2", "dst\_ip"=\>"172.16.1.10"}, @metadata={"type"=\>"conn", "beat"=\>"filebeat"}, @accessors=#@store={"message"=\>"1468822199.963471\tC3gEHk1b9GOQXYX5Z3\t172.17.1.2\t45124\t172.16.1.10\t53\tudp\tdns\t0.026759\t0\t506\tSHR\tT\tT\t0\tCd\t0\t0\t1\t534\t(empty)\t-\t-\t#siftworkstation-eth0", "@version"=\>"1", "@timestamp"=\>"2016-07-18T06:10:17.432Z", "type"=\>"conn", "source"=\>"/nsm/bro/logs/current/conn.log", "count"=\>1, "fields"=\>nil, "beat"=\>{"hostname"=\>"siftworkstation", "name"=\>"siftworkstation"}, "offset"=\>504473, "input\_type"=\>"log", "host"=\>"siftworkstation", "tags"=\>["beats\_input\_codec\_plain\_applied"], "syslog\_severity\_code"=\>5, "syslog\_facility\_code"=\>1, "syslog\_facility"=\>"user-level", "syslog\_severity"=\>"notice", [{"message"=\>"1468822199.963471\tC3gEHk1b9GOQXYX5Z3\t172.17.1.2\t45124\t172.16.1.10\t53\tudp\tdns\t0.026759\t0\t506\tSHR\tT\tT\t0\tCd\t0\t0\t1\t534\t(empty)\t-\t-\t#siftworkstation-eth0", "@version"=\>"1", "@timestamp"=\>"2016-07-18T06:10:17.432Z", "type"=\>"conn", "source"=\>"/nsm/bro/logs/current/conn.log", "count"=\>1, "fields"=\>nil, "beat"=\>{"hostname"=\>"siftworkstation", "name"=\>"siftworkstation"}, "offset"=\>504473, "input\_type"=\>"log", "host"=\>"siftworkstation", "tags"=\>["beats\_input\_codec\_plain\_applied"], "syslog\_severity\_code"=\>5, "syslog\_facility\_code"=\>1, "syslog\_facility"=\>"user-level", "syslog\_severity"=\>"notice", "src\_ip"=\>"172.17.1.2", "dst\_ip"=\>"172.16.1.10"}, "src\_ip"]}\>\>, :error=\>#, :level=\>:warn}

---

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 18, 2016, 6:27am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/11 "2016-07-18T06:27:28Z")

</div>

[{"message"=\>"1468822626.133305\tCv3pcx65PJ07Jdv25\t172.17.1.2\t37239\t172.16.1.10\t53\tudp\tdns\t0.027748\t0\t506\tSHR\tT\tT\t0\tCd\t0\t0\t1\t534\t(empty)\t-\t-\t#siftworkstation-eth0", "@version"=\>"1", "@timestamp"=\>"2016-07-18T06:17:17.440Z", "source"=\>"/nsm/bro/logs/current/conn.log", "offset"=\>505790, "input\_type"=\>"log", "count"=\>1, "beat"=\>{"hostname"=\>"siftworkstation", "name"=\>"siftworkstation"}, "type"=\>"conn", "fields"=\>nil, "host"=\>"siftworkstation", "tags"=\>["beats\_input\_codec\_plain\_applied"], "syslog\_severity\_code"=\>5, "syslog\_facility\_code"=\>1, "syslog\_facility"=\>"user-level", "syslog\_severity"=\>"notice", "src\_ip"=\>"172.17.1.2", "dst\_ip"=\>"172.16.1.10"}, "src\_ip"]}\>\>, :error=\>#start\_with?' for nil:NilClass\>, :level=\>:warn}  
{:timestamp=\>"2016-07-18T09:17:20.595000+0300", :message=\>"Failed to query elasticsearch for previous event", :index=\>"", :query=\>"type:maltrail AND dst\_ip:172.16.1.10", :event=\>#\<LogStash::Event:0x4b653d18 @metadata\_accessors=#\<LogStash::Util::Accessors:0x614d158e @store={"type"=\>"conn", "beat"=\>"filebeat"}, @lut={}\>, @cancelled=false, @data={"message"=\>"1468822626.137517\tCJ06wGBTIOaRavwR2\t172.17.1.2\t50456\t172.16.1.10\t53\tudp\tdns\t0.035619\t0\t1008\tSHR\tT\tT\t0\tCd\t0\t0\t2\t1064\t(empty)\t-\t-\t#siftworkstation-eth0", "@version"=\>"1", "@timestamp"=\>"2016-07-18T06:17:17.440Z", "source"=\>"/nsm/bro/logs/current/conn.log", "type"=\>"conn", "input\_type"=\>"log", "count"=\>1, "fields"=\>nil, "beat"=\>{"hostname"=\>"siftworkstation", "name"=\>"siftworkstation"}, "offset"=\>505938, "host"=\>"siftworkstation", "tags"=\>["beats\_input\_codec\_plain\_applied"], "syslog\_severity\_code"=\>5, "syslog\_facility\_code"=\>1, "syslog\_facility"=\>"user-level", "syslog\_severity"=\>"notice", "src\_ip"=\>"172.17.1.2", "dst\_ip"=\>"172.16.1.10"}, @metadata={"type"=\>"conn", "beat"=\>"filebeat"}, @accessors=#\<LogStash::Util::Accessors:0x5f71b8e1 @store={"message"=\>"1468822626.137517\tCJ06wGBTIOaRavwR2\t172.17.1.2\t50456\t172.16.1.10\t53\tudp\tdns\t0.035619\t0\t1008\tSHR\tT\tT\t0\tCd\t0\t0\t2\t1064\t(empty)\t-\t-\t#siftworkstation-eth0", "@version"=\>"1", "@timestamp"=\>"2016-07-18T06:17:17.440Z", "source"=\>"/nsm/bro/logs/current/conn.log", "type"=\>"conn", "input\_type"=\>"log", "count"=\>1, "fields"=\>nil, "beat"=\>{"hostname"=\>"siftworkstation", "name"=\>"siftworkstation"}, "offset"=\>505938, "host"=\>"siftworkstation", "tags"=\>["beats\_input\_codec\_plain\_applied"], "syslog\_severity\_code"=\>5, "syslog\_facility\_code"=\>1, "syslog\_facility"=\>"user-level", "syslog\_severity"=\>"notice", "src\_ip"=\>"172.17.1.2", "dst\_ip"=\>"172.16.1.10"}, @lut={"@timestamp"=\>[{"message"=\>"1468822626.137517\tCJ06wGBTIOaRavwR2\t172.17.1.2\t50456\t172.16.1.10\t53\tudp\tdns\t0.035619\t0\t1008\tSHR\tT\tT\t0\tCd\t0\t0\t2\t1064\t(empty)\t-\t-\t#siftworkstation-eth0", "@version"=\>"1", "@timestamp"=\>"2016-07-18T06:17:17.440Z", "source"=\>"/nsm/bro/logs/current/conn.log", "type"=\>"conn", "input\_type"=\>"log", "count"=\>1, "fields"=\>nil, "beat"=\>{"hostname"=\>"siftworkstation", "name"=\>"siftworkstation"}, "offset"=\>505938, "host"=\>"siftworkstation", "tags"=\>["beats\_input\_codec\_plain\_applied"], "syslog\_severity\_code"=\>5, "syslog\_facility\_code"=\>1, "syslog\_facility"=\>"user-level", "syslog\_severity"=\>"notice", "src\_ip"=\>"172.17.1.2", "dst\_ip"=\>"172.16.1.10"}, "@timestamp"], "source"=\>[{"message"=\>"1468822626.137517\tCJ06wGBTIOaRavwR2\t172.17.1.2\t50456\t172.16.1.10\t53\tudp\tdns\t0.035619\t0\t1008\tSHR\tT\tT\t0\tCd\t0\t0\t2\t1064\t(empty)\t-\t-\t#siftworkstation-eth0", "@version"=\>"1", "@timestamp"=\>"2016-07-18T06:17:17.440Z", "source"=\>"/nsm/bro/logs/current/conn.log", "type"=\>"conn", "input\_type"=\>"log", "count"=\>1, "fields"=\>nil, "beat"=\>{"hostname"=\>"siftworkstation", "name"=\>"siftworkstation"}, "offset"=\>505938, "host"=\>"siftworkstation", "tags"=\>["beats\_input\_codec\_plain\_applied"], "syslog\_severity\_code"=\>5, "syslog\_facility\_code"=\>1, "syslog\_facility"=\>"user-level", "syslog\_severity"=\>"notice", "src\_ip"=\>"172.17.1.2", "dst\_ip"=\>"172.16.1.10"}, "source"], "type"=\>[{"message"=\>"1468822631.454374\tCfj4LIvtsNP39EI4\t172.17.1.2\t33237\t172.16.1.10\t53\tudp\tdns\t0.012831\t0\t1008\tSHR\tT\tT\t0\tCd\t0\t0\t2\t1064\t(empty)\t-\t-\t#siftworkstation-eth0", "@version"=\>"1", "@timestamp"=\>"2016-07-18T06:17:24.440Z", "fields"=\>nil, "beat"=\>{"hostname"=\>"siftworkstation", "name"=\>"siftworkstation"}, "offset"=\>506088, "type"=\>"conn", "input\_type"=\>"log", "source"=\>"/nsm/bro/logs/current/conn.log", "count"=\>1, "host"=\>"siftworkstation", "tags"=\>["beats\_input\_codec\_plain\_applied"], "syslog\_severity\_code"=\>5, "syslog\_facility\_code"=\>1, "syslog\_facility"=\>"user-level", "syslog\_severity"=\>"notice", "src\_ip"=\>"172.17.1.2", "dst\_ip"=\>"172.16.1.10"}, "src\_ip"]}\>\>, :error=\>#\<NoMethodError: undefined methodstart\_with?' for nil:NilClass\>, :level=\>:warn}

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [July 18, 2016, 10:25am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/12 "2016-07-18T10:25:43Z")

</div>

Sorry, the configuration I suggested was wrong.  
Here's the right configuration that copy 'reason' ES field to 'reason' logstash field.

```
elasticsearch {
         hosts => ["localhost"]
        query => "type:maltrail AND dst_ip:%{dst_ip}"
        fields => { "reason" => "reason" }
 }
```

---

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 18, 2016, 12:12pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/13 "2016-07-18T12:12:59Z")

</div>

> [@fbaligand](#):
>
> elasticsearch {  
> hosts =\> ["localhost"]  
> query =\> "type:maltrail AND dst\_ip:%{dst\_ip}"  
> fields =\> { "reason" =\> "reason" }  
> }

Hi fbaligand,

Thanks alot for your reply.  
Actually, It's a an official documentation mistake. in the logstash filter link above ([Elasticsearch filter plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html) )  
it's written in a Wrong syntax.  
I'll post it up on github as well as here as wrong syntax.  
I've been on this for more than a week with different syntaxes.

Your works great !

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [July 18, 2016, 12:59pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/14 "2016-07-18T12:59:01Z")

</div>

Actually, sample present in elasticsearch filter documentation is not wrong :

`["@timestamp", "started"]` and `{"@timestamp" => "started"}` are equivalent.

But I agree that `["@timestamp", "started"]` is more a trick and is not obvious for understanding.

---

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 18, 2016, 8:03pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/15 "2016-07-18T20:03:33Z")

</div>

Well, for some reason ["@timestamp", "started"] doesn't work for me at all, and brings only a static field name (reason, in my case). But this {"@timestamp" =\> "started"} works great.

I think You should definitely add this as the main syntax in the elasticsearch filter documentation.

Shai

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [July 18, 2016, 9:46pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/16 "2016-07-18T21:46:38Z")

</div>

Ok.  
I don't commit on this plugin. But feel free to open an issue on GitHub.

---

<div class="post-metadata">

**Author:** ![shaigb](https://avatars.discourse-cdn.com/v4/letter/s/e56c9b/32.png) [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Post date:** [July 18, 2016, 9:47pm UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/17 "2016-07-18T21:47:34Z")

</div>

Anyway, Thanks a lot for your reply.

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [July 19, 2016, 8:11am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/18 "2016-07-19T08:11:02Z")

</div>

You're welcome 🙂

Happy to see I help you !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:47am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372/19 "2017-07-06T04:47:30Z")

</div>


