# Fetch the data from multiple indexes and create one report

**URL:** <https://discuss.elastic.co/t/fetch-the-data-from-multiple-indexes-and-create-one-report/263867>\
**Category:** Logstash\
**Created:** [February 10, 2021, 12:18pm UTC](https://discuss.elastic.co/t/fetch-the-data-from-multiple-indexes-and-create-one-report/263867 "2021-02-10T12:18:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrunalini](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@mrunalini](https://discuss.elastic.co/u/mrunalini)\
**Post date:** [February 10, 2021, 12:18pm UTC](https://discuss.elastic.co/t/fetch-the-data-from-multiple-indexes-and-create-one-report/263867/1 "2021-02-10T12:18:48Z")

</div>

Hi Team,

I have 3 different index with one transaction\_id as common in all, i am generation report with fields from all 3 indices at every midnight for transactions of last 3 days.

I have different fields in all indices , to make it in one shape i have inserted all the required fields in report in every index as NULL expect the real fields in index, Then i have created Alias of all three indices and then i have used Select query with MAX aggregation for Group-by by transaction id.

This was giving me expected result for 'D-1' where there will be only one transaction for same transaction id . but it was failing for condition of 'D-3' as there was multiple transaction for same transaction id and data was mismatched in report as MAX aggregation was applied.

Please let me know if anyone aware bout same situation and knows any kind of solution.

Thanks and regards ,  
Mrunalini Sinnarkar

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2021, 12:19pm UTC](https://discuss.elastic.co/t/fetch-the-data-from-multiple-indexes-and-create-one-report/263867/2 "2021-03-10T12:19:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
