# How to query 2 logs and show where session.id is missing in one of the logs?

**URL:** <https://discuss.elastic.co/t/how-to-query-2-logs-and-show-where-session-id-is-missing-in-one-of-the-logs/197126>\
**Category:** Elasticsearch\
**Created:** [August 28, 2019, 1:37pm UTC](https://discuss.elastic.co/t/how-to-query-2-logs-and-show-where-session-id-is-missing-in-one-of-the-logs/197126 "2019-08-28T13:37:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [August 28, 2019, 1:37pm UTC](https://discuss.elastic.co/t/how-to-query-2-logs-and-show-where-session-id-is-missing-in-one-of-the-logs/197126/1 "2019-08-28T13:37:57Z")

</div>

Hi,

I have 2 logs (httpd\_access and session log).  
Both logs have the field session.id.  
One httpd call can result in multiple sessionlog entries.

I want to find out the following:

- which session ids have entries in session log but not in httpd log
- which session ids have entries in httpd log, but not in session log.

There are thousands of requests, so I cannot do the comparison manually.

How can kibana / elasticsearch help here?

Thanks, Andreas

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [August 28, 2019, 1:50pm UTC](https://discuss.elastic.co/t/how-to-query-2-logs-and-show-where-session-id-is-missing-in-one-of-the-logs/197126/2 "2019-08-28T13:50:43Z")

</div>

Hi Andreas,  
For this sort of analysis it's probably best to combine these two event-centric index contents into a third "entity-centric" index keyed on session ID.  
The new [dataframes](https://www.elastic.co/guide/en/elastic-stack-overview/current/ml-transform-overview.html) functionality is designed to do the work of fusing the data. You may need to set up an alias that combines the two indices and use that as the source data to perform the transform, using the common `session.id` field as the join key.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2019, 1:50pm UTC](https://discuss.elastic.co/t/how-to-query-2-logs-and-show-where-session-id-is-missing-in-one-of-the-logs/197126/3 "2019-09-25T13:50:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
