Event Correlation \ populate one field with data from other field in elasticsearch

I have a similar problem, would be happy to get some advice