Intersect statement in elasticsearch?


Is it possible to have an output from an intersection of data that are in
two different index or field?
We have a list of botIP in elasticsearch and in another index where we
capture data from firewall.

We want the list that match a predetermined field (example DST.IP) taken
from the firewall (real time log) and botIP list (mostly static).

It is like a "real time" intersect in SQL.

INSERT INTO table_a VALUES (1, 'A'), (2, 'B'), (3, 'B');INSERT INTO table_b VALUES (1, 'B');
SELECT value FROM table_aINTERSECTSELECT value FROM table_b



