# Index relationship

**URL:** <https://discuss.elastic.co/t/index-relationship/167267>\
**Category:** Elasticsearch\
**Created:** [February 6, 2019, 11:00am UTC](https://discuss.elastic.co/t/index-relationship/167267 "2019-02-06T11:00:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fedwe](https://avatars.discourse-cdn.com/v4/letter/f/a88e4f/32.png) [@fedwe](https://discuss.elastic.co/u/fedwe)\
**Post date:** [February 6, 2019, 11:00am UTC](https://discuss.elastic.co/t/index-relationship/167267/1 "2019-02-06T11:00:45Z")

</div>

i need help to work around problem. I have 2 files one with a number field and the other with country code and country name.

for example i have this number 12398564 and there is the country code 123 of country name x

My questions is should i index both files in the same index so i can use use them  
my final result is that i want to take the substring of the code which returns 123 and link it with country code field 123 and returns the country name x to display it in a table next to it.  
can i use scripted fields or something of a link?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 6, 2019, 11:07am UTC](https://discuss.elastic.co/t/index-relationship/167267/2 "2019-02-06T11:07:20Z")

</div>

Elasticsearch does not support joins, so the is not possible. I would instead recommend looking up the country code and country name before indexing the document and then store it together with the data. Denormalising data this way is very common when working with Elasticsearch.

---

<div class="post-metadata">

**Author:** ![fedwe](https://avatars.discourse-cdn.com/v4/letter/f/a88e4f/32.png) [@fedwe](https://discuss.elastic.co/u/fedwe)\
**Post date:** [February 6, 2019, 11:10am UTC](https://discuss.elastic.co/t/index-relationship/167267/3 "2019-02-06T11:10:08Z")

</div>

im am indexing using logstash is there a way to do this with logstash

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 6, 2019, 11:16am UTC](https://discuss.elastic.co/t/index-relationship/167267/4 "2019-02-06T11:16:41Z")

</div>

You should be able to use a translate filter plugin to perform this, as this supports pattern matching. For performance reasons you may however want to instead break it up into several filters as country codes can have different lengths.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2019, 11:16am UTC](https://discuss.elastic.co/t/index-relationship/167267/5 "2019-03-06T11:16:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
