# Full Join Pattern

**URL:** https://discuss.elastic.co/t/full-join-pattern/350101
**Category:** Kibana
**Tags:** dashboard
**Created:** [December 28, 2023, 6:59pm UTC](https://discuss.elastic.co/t/full-join-pattern/350101 "2023-12-28T18:59:48Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![AlanRocha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alanrocha/32/130395_2.png) [@AlanRocha](https://discuss.elastic.co/u/AlanRocha)
#### Post date: [December 28, 2023, 6:59pm UTC](https://discuss.elastic.co/t/full-join-pattern/350101/1 "2023-12-28T18:59:48Z")

</div>

Hello everyone, everything good?

I need to do a full join with four different patterns ex: datalake-1-_, tool-v1-_, za-ho-_, cmdb-grupos-_.

I'm filtering mine based on a dashboard I have in Power BI and I migrate all of them to Kibana.

By performing some filters I managed to reach a number of 17k, compared to the number on the dashboard of 13k, it is very close, but when I add a certain filter, the value resets to zero.

Analyzing the records, I noticed that the pattern "owner" of the field I am filtering does not have any field related to the others besides @timestemp.

Can I do a full join on the index?

---

<div class="post-metadata">

### Author: ![AlanRocha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alanrocha/32/130395_2.png) [@AlanRocha](https://discuss.elastic.co/u/AlanRocha)
#### Post date: [December 29, 2023, 12:59pm UTC](https://discuss.elastic.co/t/full-join-pattern/350101/2 "2023-12-29T12:59:58Z")

</div>

My version is 7.17.4

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [December 29, 2023, 2:10pm UTC](https://discuss.elastic.co/t/full-join-pattern/350101/4 "2023-12-29T14:10:03Z")

</div>

> [@AlanRocha](#):
>
> the filter works, but when adding the line, the numbering disappears.

Does this field exists in **all** indices in your data view?

Elasticsearch does not have joins, you can't do a join on elasticsearch.

What you can do is filter on the same field on multiple indices at the same time.

---

<div class="post-metadata">

### Author: ![AlanRocha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alanrocha/32/130395_2.png) [@AlanRocha](https://discuss.elastic.co/u/AlanRocha)
#### Post date: [December 29, 2023, 2:26pm UTC](https://discuss.elastic.co/t/full-join-pattern/350101/5 "2023-12-29T14:26:42Z")

</div>

This field is not common across all, the common field is @timestemp.

Is there any way to bypass this?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [December 29, 2023, 2:35pm UTC](https://discuss.elastic.co/t/full-join-pattern/350101/6 "2023-12-29T14:35:36Z")

</div>

> [@AlanRocha](#):
>
> Is there any way to bypass this?

No, as mentioned Elasticsearch does not support joins.

For example, if you have three index under the same data view, `indexA`, `indexB` and `indexC`, you can search on all those three at the same time, but if you apply a filter on a field, like `exampleField`, only the documents that have this field will be retuned.

Nomally when you need to _join_ something in Elasticsearch you need to do that beforer indexing the data, normalizing it and put everything on the same index.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 26, 2024, 2:35pm UTC](https://discuss.elastic.co/t/full-join-pattern/350101/7 "2024-01-26T14:35:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
