# How to join/combine data from 2 indices using a common/join field in Elastic?

**URL:** <https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195>\
**Category:** Kibana\
**Created:** [October 21, 2022, 11:36am UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195 "2022-10-21T11:36:25Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![AshwiniPrabhu](https://avatars.discourse-cdn.com/v4/letter/a/439d5e/32.png) [@AshwiniPrabhu](https://discuss.elastic.co/u/AshwiniPrabhu)\
**Post date:** [October 21, 2022, 11:36am UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195/1 "2022-10-21T11:36:26Z")

</div>

Hi,  
Thank you for your time for reading the question. I have 2 indices:  
Index 1 (Activation) - Order Id, Activation Date  
Index 2 (Identity) - Order Id, Identity Date. The join field/common field is Order id.  
I have to calculate the duration from Identity Date to Activation Date in minutes and plot a bar graph showing all the orders that were activated in 10 minutes on Kibana ? Could you please explain how we can do that ? Is there some transformation that needs to be applied at the time of indexing the data or we can directly do this on Kibana ?. I have pasted some sample data for your reference.

**Activation:**

| Order Id | Mode of registration | Brand | Activation Date | Application name |
| --- | --- | --- | --- | --- |
| 101 | Cust Care | AVC | 3/1/2022 0:02 | ACT\_01 |
| 102 | Online website | AVC | 3/1/2022 0:02 | ACT\_01 |
| 103 | Online website | AVC | 3/1/2022 0:02 | ACT\_01 |
| 104 | Online website | AVC | 4/1/2022 0:30 | ACT\_01 |
| 105 | Online website | AVC | 3/1/2022 0:02 | ACT\_01 |

**Identity**

| Order Id | Mode of registration | Brand | Identity Date | Application name |
| --- | --- | --- | --- | --- |
| 101 | Cust Care | AVC | 3/1/2022 0:00 | IDV\_02 |
| 102 | Online website | AVC | 3/1/2022 0:00 | IDV\_02 |
| 103 | Online website | AVC | 3/1/2022 0:00 | IDV\_02 |
| 104 | Online website | AVC | 4/1/2022 0:00 | IDV\_02 |
| 105 | Online website | AVC | 3/1/2022 0:00 | IDV\_02 |

Thank you very much, again !! It would be really help us if we could get some guidance here !!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 23, 2022, 11:09pm UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195/2 "2022-10-23T23:09:18Z")

</div>

Welcome to our community! 😃

> [@AshwiniPrabhu](#):
>
> Is there some transformation that needs to be applied at the time of indexing the data

Yes, this is the best way to do it in the Elastic Stack.  
You can do that with an ingest pipeline that does an enrichment from one of the indices into the other.

---

<div class="post-metadata">

**Author:** ![AshwiniPrabhu](https://avatars.discourse-cdn.com/v4/letter/a/439d5e/32.png) [@AshwiniPrabhu](https://discuss.elastic.co/u/AshwiniPrabhu)\
**Post date:** [October 25, 2022, 2:07pm UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195/3 "2022-10-25T14:07:30Z")

</div>

Thank you @warkolm for the answer. I will definitely try that. I read on elastic documentation that for an enrich processor, one of the data sources (the one that contains enrich information) needs to be static. In my case both the source indices will be updated per second.  
Please help me with this!!

Thank you again 😊

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2022, 12:14am UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195/4 "2022-10-26T00:14:46Z")

</div>

What exactly do you need help with?

---

<div class="post-metadata">

**Author:** ![AshwiniPrabhu](https://avatars.discourse-cdn.com/v4/letter/a/439d5e/32.png) [@AshwiniPrabhu](https://discuss.elastic.co/u/AshwiniPrabhu)\
**Post date:** [October 26, 2022, 4:02am UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195/5 "2022-10-26T04:02:33Z")

</div>

@warkolm  
Apologies for not being clear with the question before. Below is a detailed explanation of the question:  
Please revisit my first post where I listed down 2 indices. I want to join the Activation and Identity indices based on the Order Id field and calculate the duration from Identity Date till Activation Date. The output or Kibana Data view should look as below:

| Order Id | Mode of registration | Brand | Identity Date | Application name | Activation Date | Duration (in minutes) |
| --- | --- | --- | --- | --- | --- | --- |
| 101 | Cust Care | AVC | 03-01-2022 00:00 | ACT\_01 | 03-01-2022 00:02 | 2 |
| 102 | Online website | AVC | 03-01-2022 00:00 | ACT\_01 | 03-01-2022 00:02 | 2 |
| 103 | Online website | AVC | 03-01-2022 00:00 | ACT\_01 | 03-01-2022 00:02 | 2 |
| 104 | Online website | AVC | 04-01-2022 00:00 | ACT\_01 | 04-01-2022 00:30 | 30 |
| 105 | Online website | AVC | 03-01-2022 00:00 | ACT\_01 | 03-01-2022 00:02 | 2 |

Please note that both the source indices are dynamic. We need to create this result data for all the incoming documents in real time.  
Then, we will use this resultant data set to create a dashboard in Kibana.  
I need help with this implementation. I came across 2 options in my research:

1. Writing transforms
2. Enrich processor  
Could you please suggest which of these is a better option. We would also be interested if there is another way to solve this challenge.

Thank you again !!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2022, 4:05am UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195/6 "2022-10-26T04:05:25Z")

</div>

You would be better off using an enrich processor here.

---

<div class="post-metadata">

**Author:** ![AshwiniPrabhu](https://avatars.discourse-cdn.com/v4/letter/a/439d5e/32.png) [@AshwiniPrabhu](https://discuss.elastic.co/u/AshwiniPrabhu)\
**Post date:** [October 26, 2022, 6:10am UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195/7 "2022-10-26T06:10:10Z")

</div>

Thank you Very much @warkolm .. I really appreciate your quick responses 🙂  
I will read more on Enrich Processors and will come back if there are more questions.  
Thank you very much!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2022, 12:47pm UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195/8 "2022-11-22T12:47:54Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2022, 12:48pm UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195/9 "2022-12-20T12:48:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
