# How to Execute Query to fetch inprogess processes

**URL:** <https://discuss.elastic.co/t/how-to-execute-query-to-fetch-inprogess-processes/261774>\
**Category:** Kibana\
**Created:** [January 21, 2021, 11:54am UTC](https://discuss.elastic.co/t/how-to-execute-query-to-fetch-inprogess-processes/261774 "2021-01-21T11:54:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhi.coerian](https://avatars.discourse-cdn.com/v4/letter/a/ec9cab/32.png) [@abhi.coerian](https://discuss.elastic.co/u/abhi.coerian)\
**Post date:** [January 21, 2021, 11:54am UTC](https://discuss.elastic.co/t/how-to-execute-query-to-fetch-inprogess-processes/261774/1 "2021-01-21T11:54:19Z")

</div>

I have log 'analytics', which contains a list of events of process logs ( for eg: CRUD) that occured over a period of time. I am looking to find a set of records that were record added but not deleted from system.

document structure:

> id, process\_id, event, timestamp

where process\_id is primary key of record, process events are 'create', 'read', 'delete', 'update'.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [January 21, 2021, 12:26pm UTC](https://discuss.elastic.co/t/how-to-execute-query-to-fetch-inprogess-processes/261774/2 "2021-01-21T12:26:47Z")

</div>

This is not easily possible as it requires correlating multiple documents which is essentially a join, something which isn't possible in Elasticsearch.

A way around this I've seen is to ingest the documents twice, once for a "event index" (the way you do it right now) and once as a "state index", using the `process_id` as the document id so it will always contain the most recent event. Then you can use a regular filter to search for the current state.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 18, 2021, 12:26pm UTC](https://discuss.elastic.co/t/how-to-execute-query-to-fetch-inprogess-processes/261774/3 "2021-02-18T12:26:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
