# Find and show values of a field, which is also in another field

**URL:** <https://discuss.elastic.co/t/find-and-show-values-of-a-field-which-is-also-in-another-field/201077>\
**Category:** Kibana\
**Created:** [September 25, 2019, 3:34pm UTC](https://discuss.elastic.co/t/find-and-show-values-of-a-field-which-is-also-in-another-field/201077 "2019-09-25T15:34:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [September 25, 2019, 3:34pm UTC](https://discuss.elastic.co/t/find-and-show-values-of-a-field-which-is-also-in-another-field/201077/1 "2019-09-25T15:34:20Z")

</div>

Hi all,  
I try to explain my problem as best as I can. Please ask if it is still not clear:  
So, I am sending me logfiles of two different systems via filebeat and parse them via logstash.  
The documents of "ServerA" contain an interessting field called "FieldA" with "ValueA"  
The documents of "ServerB" contain an interessting field called "FieldB" with "ValueB"  
All documents are in the same index (filebeat-yyyy.mm.dd) the kibana index pattern is filebeat-\*  
I now need a search, where first) all Documents are shown, where FieldA exists and second) based on the ValueA of FieldA every Document where ValueB of FIeldB is as same as ValueA

So basically a Kibana (pseudo) search like:  
FieldA: \* AND FieldB = FieldA

In MySQL it would be sth. like a join. How can I do this in Kibana?  
Thanks a lot in advance!  
Cheers,  
Marcus

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [September 25, 2019, 3:45pm UTC](https://discuss.elastic.co/t/find-and-show-values-of-a-field-which-is-also-in-another-field/201077/2 "2019-09-25T15:45:50Z")

</div>

Hi @MarcusCaepio, thanks for reaching out. You could do this with a [scripted field](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html) that becomes true if FieldA equals FieldB. Then you can filter in your dashboard by creating two filters `FieldA equals ValueA` and `ScriptedFieldAisB equals true` to get the documents you want to match.

---

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [September 25, 2019, 3:52pm UTC](https://discuss.elastic.co/t/find-and-show-values-of-a-field-which-is-also-in-another-field/201077/3 "2019-09-25T15:52:10Z")

</div>

Hey flash, thanks a lot. will have a look on it tomorrow 🙂

---

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [September 26, 2019, 8:09am UTC](https://discuss.elastic.co/t/find-and-show-values-of-a-field-which-is-also-in-another-field/201077/5 "2019-09-26T08:09:20Z")

</div>

So I think I need a little help here. I tried to create a scripted field like this:

- name: sc-test
- language painless
- type boolean
- script:  
if (doc['FieldA'].value == doc['FieldB'].value) {  
return true;  
} else {  
return false;  
}

also tried just  
doc['FieldA'].value == doc['FieldB'].value  
But after saving this, in Discovery I just only have the sc-test field available with no matches. All the other fields are gone until I delete sc-test again.

Maybe an important info. FieldA and FieldB are in different documents, not in the same.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [September 27, 2019, 3:03pm UTC](https://discuss.elastic.co/t/find-and-show-values-of-a-field-which-is-also-in-another-field/201077/6 "2019-09-27T15:03:31Z")

</div>

Hi @MarcusCaepio,

I'm sorry, I misread your original post - this will indeed only work if the fields are in the same document.

This kind of querying is very hard to do with Elasticsearch in general. A way that often works is to basically do the join at ingest time, meaning when ingesting the data you look up the values you are going to filter by and ingest them together with the rest of the document. Unfortunately that requires a bit more setup than just running filebeat, most likely you need a custom shipper that handles this. See also these resources: [https://www.elastic.co/blog/managing-relations-inside-elasticsearch](https://www.elastic.co/blog/managing-relations-inside-elasticsearch) [Does document database means denormalize](https://discuss.elastic.co/t/does-document-database-means-denormalize/18075)

I'm sorry I don't have a better answer for you here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2019, 3:03pm UTC](https://discuss.elastic.co/t/find-and-show-values-of-a-field-which-is-also-in-another-field/201077/7 "2019-10-25T15:03:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
