# How to index user account data vs their indexed data?

**URL:** <https://discuss.elastic.co/t/how-to-index-user-account-data-vs-their-indexed-data/69060>\
**Category:** Elasticsearch\
**Created:** [December 14, 2016, 5:35pm UTC](https://discuss.elastic.co/t/how-to-index-user-account-data-vs-their-indexed-data/69060 "2016-12-14T17:35:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![baden0x1](https://avatars.discourse-cdn.com/v4/letter/b/4da419/32.png) [@baden0x1](https://discuss.elastic.co/u/baden0x1)\
**Post date:** [December 14, 2016, 5:35pm UTC](https://discuss.elastic.co/t/how-to-index-user-account-data-vs-their-indexed-data/69060/1 "2016-12-14T17:35:59Z")

</div>

In an existing v1.0, in a RDMS we have user-based tables that relate to user details, login credentials, access logs, account configuration, etc., and a data mart with all the users' data.

Now for v2.0 using ELK, what would the suggested architecture be? Can we use one index for user-related credentials, their details, account configurations, etc., then have a separate index for each user's data (rather than a data mart type scenario with all users' data)?

I would like some suggestions on how to structure the user-related credential/config data and their actual data. User a RDMS in combination with ES? I don't like this option but am open to suggestions.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 14, 2016, 10:03pm UTC](https://discuss.elastic.co/t/how-to-index-user-account-data-vs-their-indexed-data/69060/2 "2016-12-14T22:03:31Z")

</div>

The two main options are;

1. Have an index for the user info, then time based ones for their data. Then do a join in your code to enrich an event with the user data.
2. Have time based indices, and include all the user data with each record.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2017, 10:03pm UTC](https://discuss.elastic.co/t/how-to-index-user-account-data-vs-their-indexed-data/69060/3 "2017-01-11T22:03:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
