# Join 2 indexes with 1 primary key logstash filter elasticsearch

**URL:** <https://discuss.elastic.co/t/join-2-indexes-with-1-primary-key-logstash-filter-elasticsearch/251279>\
**Category:** Logstash\
**Created:** [October 7, 2020, 1:43pm UTC](https://discuss.elastic.co/t/join-2-indexes-with-1-primary-key-logstash-filter-elasticsearch/251279 "2020-10-07T13:43:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![charles97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charles97/32/79243_2.png) [@charles97](https://discuss.elastic.co/u/charles97)\
**Post date:** [October 7, 2020, 1:43pm UTC](https://discuss.elastic.co/t/join-2-indexes-with-1-primary-key-logstash-filter-elasticsearch/251279/1 "2020-10-07T13:43:09Z")

</div>

So tried to join a transfrom index to index table. I saw this as reference : [How to join fields from multi events into single event?](https://discuss.elastic.co/t/how-to-join-fields-from-multi-events-into-single-event/106364) and it seems like it should work by using elasticsearch filter plugin.  
transform index name : transform\_ndex  
transform index contains these fields : `extract.keyword, service.keyword.cardinality, timestamp_tries.max,userID.keyword`  
here is my new index configuration:

```auto
input
{
    beats
    {
        port =>5053
    }
}

filter
{
         csv
         {
            skip_header => true
            columns => ["Name","Email","date"]
            separator => ","
        }
        grok {
        match => {"[log][file][path]" => "%{POSINT:extract}"}

        elasticsearch {
        hosts => ["127.0.0.1"]
        index => "transform_authentication"
        query => "extract:%{extract.keyword} AND email:%{userID.keyword}"
        fields => {
            "timestamp_tries.max" => "timestamp_tries.max"
            "service.keyword.cardinality" => "service.keyword.cardinality"
        }
    }

}
output {
        stdout{codec=>rubydebug}
}

```

field in new index (extract) should be the same as transform\_ndex(extract.keyword) and new index (email) should be the same as transform\_ndex(userID.keyword).  
after it passed the query I want to add fields from transform\_ndex to new\_index (timestamp\_tries.max, service.keyword.cardinality)

it keeps on returning error

I don't know if I missed the concept or missed the conf file. Please tell me how to do this. Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2020, 1:43pm UTC](https://discuss.elastic.co/t/join-2-indexes-with-1-primary-key-logstash-filter-elasticsearch/251279/2 "2020-11-04T13:43:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
