# How to aggregate data from 2 different lines of a LDAP log

**URL:** https://discuss.elastic.co/t/how-to-aggregate-data-from-2-different-lines-of-a-ldap-log/150344
**Category:** Kibana
**Created:** [September 28, 2018, 1:06pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-from-2-different-lines-of-a-ldap-log/150344 "2018-09-28T13:06:52Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Noureddine\_Brahmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/noureddine_brahmi/32/62092_2.png) [@Noureddine\_Brahmi](https://discuss.elastic.co/u/Noureddine_Brahmi)
#### Post date: [September 28, 2018, 1:06pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-from-2-different-lines-of-a-ldap-log/150344/1 "2018-09-28T13:06:52Z")

</div>

Hello, I'm fresh to the ELK but I'm really liking the work with it so far.

I'm current working on a solution that allows us to monitor LDAP logs. and I was wondering if I could display data from several documents in one line. Knowing that they have a field in common.

Here's an exemple to make things clear:

LDAP log lines :

\*[04/Aug/2018:22:34:15 +0200] conn=184214 op=-1 msgId=-1 - fd=52 slot=52 LDAP connection from **10.169.146.54** :3625 to 10.68.27.65  
\*[04/Aug/2018:22:34:15 +0200] conn=184214 op=0 msgId=1 - BIND  
**dn="cn=azerty,ou=manager,o=s"** method=128 version=3  
\*[04/Aug/2018:22:34:15 +0200] conn=184214 op=0 msgId=1 - RESULT err=0 tag=97 nentries=0 **etime=0.000450** dn="cn=poiuyr,ou=manager,o=s"

Knowing that every field in this log document is well filtered using the grok pattern. I want to display for example in one chart the IP address of connection(10.169.146.54), the BIND message(dn="cn=azerty,ou=manager,o=s) and the etime of the result (etime=0.000450). and the common field of everything is the conn number("conn=184214")

Currently in the chart that is provided in the discovery mode I only get the fields that are in the same document.

Thank you very much for the help !

---

<div class="post-metadata">

### Author: ![christophilus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christophilus/32/42991_2.png) [@christophilus](https://discuss.elastic.co/u/christophilus)
#### Post date: [September 28, 2018, 2:02pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-from-2-different-lines-of-a-ldap-log/150344/2 "2018-09-28T14:02:57Z")

</div>

I can't think of a good way to do that. It's similar to a SQL join, but for performance reasons, Elasticsearch doesn't do joins.

Generally, the strategy is to try to store your data in a format that is search-friendly for your intended usecases. So, for example, instead of storing your LDAP logs as a document per log-file line, you'd store them as a document per IP address, maybe with a new entry per day / week / whatever time interval makes sense, and update the appropriate document as new log info comes in.

That may not be the _best_ approach, but that's the general idea. Can you store your data in a way that makes search and retrieval easy and efficient?

---

<div class="post-metadata">

### Author: ![Noureddine\_Brahmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/noureddine_brahmi/32/62092_2.png) [@Noureddine\_Brahmi](https://discuss.elastic.co/u/Noureddine_Brahmi)
#### Post date: [October 1, 2018, 6:08am UTC](https://discuss.elastic.co/t/how-to-aggregate-data-from-2-different-lines-of-a-ldap-log/150344/3 "2018-10-01T06:08:53Z")

</div>

Hello Chris and thank you for your respond.

Unfortunately I can't store the data in another way at this moment. Because within my company another team is incharge of the logstash parse of the logs. And we require a budget to make any change ( we don't have a budget at this moment ). So I've been looking for another solution using Kibana 6.3 .

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 29, 2018, 6:09am UTC](https://discuss.elastic.co/t/how-to-aggregate-data-from-2-different-lines-of-a-ldap-log/150344/4 "2018-10-29T06:09:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
