# How to select data from multiple indicess

**URL:** <https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772>\
**Category:** Elasticsearch\
**Created:** [August 20, 2020, 1:09pm UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772 "2020-08-20T13:09:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [August 20, 2020, 1:09pm UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772/1 "2020-08-20T13:09:10Z")

</div>

Hi Everyone,

I am new to ELK stack, and I am facing an issue with searching data from multiple indices in single query.

I am able to do this from Dev tool but not from Discover or visualization. Can anyone please help me on this.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 20, 2020, 1:20pm UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772/2 "2020-08-20T13:20:36Z")

</div>

Create an index pattern in Management -\> Index Patterns. Then you can use that in Discover and Visualizations. Use `index-xxx*` type format to cover multiple indexes.

---

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [August 20, 2020, 1:32pm UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772/3 "2020-08-20T13:32:03Z")

</div>

Thanks @aaron-nimocks , but I think that will create a single index pattern and all the data will be there in single index only and it might impact the performance as well, and also if I want to generate report from one of the index that will also not be possible.

is there something like join(as we have in sql) to select from multiple indexes

Please suggest.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 20, 2020, 1:34pm UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772/4 "2020-08-20T13:34:43Z")

</div>

Can you give an example of the dev tools query you are using to get the result you want?

---

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [August 20, 2020, 1:43pm UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772/5 "2020-08-20T13:43:51Z")

</div>

Hi @aaron-nimocks , below is the query which I got from inspect of visualization

{  
"aggs": {  
"2": {  
"terms": {  
"field": "SERVICE\_NAME.keyword",  
"order": {  
"\_count": "desc"  
},  
"size": 500  
},  
"aggs": {  
"3": {  
"terms": {  
"field": "CHANNEL\_NAME.keyword",  
"order": {  
"\_count": "desc"  
},  
"size": 50  
}  
}  
}  
}  
},  
"size": 0,  
"stored\_fields": [  
"\*"  
],  
"script\_fields": {},  
"docvalue\_fields": [  
{  
"field": "@timestamp",  
"format": "date\_time"  
}  
],  
"\_source": {  
"excludes":   
},  
"query": {  
"bool": {  
"must": ,  
"filter": [  
{  
"match\_all": {}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "2020-08-19T13:38:15.991Z",  
"lte": "2020-08-20T13:38:15.992Z",  
"format": "strict\_date\_optional\_time"  
}  
}  
}  
],  
"should": ,  
"must\_not":   
}  
}  
}

Below , is the query which I am using from Devtool  
GET \*/\_search" "size" :0, "aggs": { "2": { "terms": { "field": "SERVICE\_NAME.keyword", "order": { "1": "desc" }, "size": 500 }, "aggs": { "1": { "cardinality": { "field": "CORREL.keyword" } }, "3": { "terms": { "field": "CHANNEL\_NAME.keyword", "order": { "1": "desc" }, "size": 50 }, "aggs": { "1": { "cardinality": { "field": "CORREL.keyword" } } } } } } }, "query": { "bool": { "filter": [{ "range": { "@timestamp": { "gte": "2020-07-11T18:30:00.000Z", "lte": "2020-07-12T18:30:00.000Z", "format": "strict\_date\_optional\_time" } } }] } }}'

From Dev tool, I am able to get data from multiple Indexes, but from there we are not able to get data in excel format. From Visualization, I am able to get data in excel but there is no way to get it from multiple indexes

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 20, 2020, 1:56pm UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772/6 "2020-08-20T13:56:57Z")

</div>

Is the ultimate goal to run an aggregation across multiple indexes and then export the result to excel?

---

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [August 20, 2020, 2:09pm UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772/7 "2020-08-20T14:09:18Z")

</div>

@aaron-nimocks : Yes, sometimes , we need to fetch data from multiple indexes using some correlation id in Discover.

However when we are generating reports then we are focused on getting it from single index.

Thanks!!

---

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [August 27, 2020, 8:04am UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772/8 "2020-08-27T08:04:40Z")

</div>

I am using alias for this purpose .. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2020, 8:04am UTC](https://discuss.elastic.co/t/how-to-select-data-from-multiple-indicess/245772/9 "2020-09-24T08:04:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
