# How to create a kibana dashboard which could search through index relations?

**URL:** <https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276>\
**Category:** Kibana\
**Created:** [September 27, 2022, 2:43pm UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276 "2022-09-27T14:43:27Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ibrahim\_Z\_HIDIR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibrahim_z_hidir/32/106875_2.png) [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Post date:** [September 27, 2022, 2:43pm UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/1 "2022-09-27T14:43:27Z")

</div>

Hi everybody

I have 3 different indices, A, B and C

A and B both sharing a field suppose F1  
B and C also sharing another field suppose F2

I've added 3 different saved search to a dash board. So when I want to search something from F1 A and B saved search displaying results but not C. How can I connect also the C shows the results depending on F1 and connecting using F2.

Thanks

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [September 27, 2022, 4:35pm UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/2 "2022-09-27T16:35:33Z")

</div>

Does your data view/index pattern match all three indices?

> How can I connect also the C shows the results depending on F1 and connecting using F2.

How do F1 and F2 relate? Could you please explain this in more detail?

---

<div class="post-metadata">

**Author:** ![Ibrahim\_Z\_HIDIR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibrahim_z_hidir/32/106875_2.png) [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Post date:** [September 28, 2022, 6:48am UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/3 "2022-09-28T06:48:49Z")

</div>

![kibanaedit](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d4c2786dffbbad0fdda27dcc9f314314ab3ee0b3.png)

I think it is better with drawing. All 3 saved searches using different data viewes.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [September 28, 2022, 4:36pm UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/4 "2022-09-28T16:36:05Z")

</div>

This sort of thing isn't really possible currently, especially if the documents are in separate indices. If they were in a shared index, you might be able to accomplish it using [join fields](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/parent-join.html).

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [September 28, 2022, 6:32pm UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/5 "2022-09-28T18:32:38Z")

</div>

Every index needs to have all fields you want to filter on. This can get achieved by using enrichment

---

<div class="post-metadata">

**Author:** ![Ibrahim\_Z\_HIDIR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibrahim_z_hidir/32/106875_2.png) [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Post date:** [September 29, 2022, 6:27am UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/6 "2022-09-29T06:27:41Z")

</div>

I've tried enrichment already but the enrichment index is static, and the all the indeces are datasteams and continously having new documents...

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [September 29, 2022, 7:40am UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/7 "2022-09-29T07:40:55Z")

</div>

Having new documents all the time is not an issue. The important question is how often you have new IDs.. In your case index B seems to know all the relationships. This one can be used. You only need to re-execute the enrichment policy every now and then. This works best with watcher. I've made this already using apm indices and enriching documents with information about the user that is coming in later in the user session. Works fine. Only trade off is that it adds a bit of load to your cluster.

Another option is to use lookup runtime fields. You could lookup from C in B to get F1. And lookup from A in B to get F2. The trade off for this approach is impact on search-performance and I believe not all aggregations are allowed on the fields that you looked up.

---

<div class="post-metadata">

**Author:** ![Ibrahim\_Z\_HIDIR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibrahim_z_hidir/32/106875_2.png) [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Post date:** [September 29, 2022, 8:10am UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/8 "2022-09-29T08:10:50Z")

</div>

Well, I've think about renew the enrichment but the new documnet frequency is high, every second all the indices having about 20-50 documnets, this way loads the cluster too much.

I could't find any way how to search different index using runtime fields. I think it is not possible!

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [September 29, 2022, 8:25am UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/9 "2022-09-29T08:25:16Z")

</div>

20 - 50 EPS does not sound very much.

This is the documentation for lookup runtime fields

> **[Retrieve a runtime field | Elasticsearch Guide \[8.4\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime-retrieving-fields.html#lookup-runtime-fields)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2022, 8:25am UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276/10 "2022-10-27T08:25:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
