I need to do a full join with four different patterns ex: datalake-1-, tool-v1-, za-ho-, cmdb-grupos-.
I'm filtering mine based on a dashboard I have in Power BI and I migrate all of them to Kibana.
By performing some filters I managed to reach a number of 17k, compared to the number on the dashboard of 13k, it is very close, but when I add a certain filter, the value resets to zero.
Analyzing the records, I noticed that the pattern "owner" of the field I am filtering does not have any field related to the others besides @timestemp.
No, as mentioned Elasticsearch does not support joins.
For example, if you have three index under the same data view, indexA, indexB and indexC, you can search on all those three at the same time, but if you apply a filter on a field, like exampleField, only the documents that have this field will be retuned.
Nomally when you need to join something in Elasticsearch you need to do that beforer indexing the data, normalizing it and put everything on the same index.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.