# Join between two different sources using Kibana 4

**URL:** <https://discuss.elastic.co/t/join-between-two-different-sources-using-kibana-4/21591>\
**Category:** Elasticsearch\
**Created:** [January 12, 2015, 7:36pm UTC](https://discuss.elastic.co/t/join-between-two-different-sources-using-kibana-4/21591 "2015-01-12T19:36:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gregory\_Touretsky](https://avatars.discourse-cdn.com/v4/letter/g/e36b37/32.png) [@Gregory\_Touretsky](https://discuss.elastic.co/u/Gregory_Touretsky)\
**Post date:** [January 12, 2015, 7:36pm UTC](https://discuss.elastic.co/t/join-between-two-different-sources-using-kibana-4/21591/1 "2015-01-12T19:36:19Z")

</div>

Hi,

what would be the right way to join between two data sources using  
Kibana 4 interface?  
Assume 2 data sources:

1. source=jobs, fields = {jobid, user, host, exitstatus,  
starttime,finishtime}  
Sample record:  
type = jobs; jobid = 1234; user = john; host = myhost; exitstatus =  
-3002; starttime = 01/01/2015 01:01; finishtime = 01/01/2015 01:15
2. source=license, fields = {host, user, time, feature, result}  
Sample records:  
type = license; user = john; host = myhost; time = 01/01/2015 01:05;  
feature = AAA; result = DENIED  
type = license; user = john; host = myhost; time = 01/01/2015 01:07;  
feature = BBB; result = APPROVED

I’d like to create a dashboard in Kibana 4 which would show a joint table  
combining both sources.  
Using pseudo-SQL code, it should do something like:

select  
jobs.jobid,jobs.user,jobs.host,license.feature,license.result,count(license.time)  
from jobs  
LEFT JOIN license  
WHERE jobs.exitstatus=-3002 AND license.user=jobs.user AND  
license.host=jobs.host AND license.time\>=jobs.starttime AND  
license.time\<=jobs.finishtime  
GROUP BY jobs.jobid,jobs.user,jobs.host

Thanks in advance,  
Gregory

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Itamar\_Syn\_Hershko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itamar_syn_hershko/32/725_2.png) [@Itamar\_Syn\_Hershko](https://discuss.elastic.co/u/Itamar_Syn_Hershko)\
**Post date:** [January 12, 2015, 7:38pm UTC](https://discuss.elastic.co/t/join-between-two-different-sources-using-kibana-4/21591/2 "2015-01-12T19:38:43Z")

</div>

You either use parent / child

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Or index denormalized data in the first place

Elasticsearch isn't meant to be used using the same models as relational  
databases

--

Itamar Syn-Hershko  
[http://code972.com](http://code972.com) | @synhershko [https://twitter.com/synhershko](https://twitter.com/synhershko)  
Freelance Developer & Consultant  
Author of RavenDB in Action [http://manning.com/synhershko/](http://manning.com/synhershko/)

On Mon, Jan 12, 2015 at 9:36 PM, Gregory Touretsky \<  
[gregory.touretsky@intel.com](mailto:gregory.touretsky@intel.com)\> wrote:

> Hi,
> 
> what would be the right way to join between two data sources using  
> Kibana 4 interface?  
> Assume 2 data sources:
> 
> 1. source=jobs, fields = {jobid, user, host, exitstatus,  
> starttime,finishtime}  
> Sample record:  
> type = jobs; jobid = 1234; user = john; host = myhost; exitstatus =  
> -3002; starttime = 01/01/2015 01:01; finishtime = 01/01/2015 01:15
> 2. source=license, fields = {host, user, time, feature, result}  
> Sample records:  
> type = license; user = john; host = myhost; time = 01/01/2015 01:05;  
> feature = AAA; result = DENIED  
> type = license; user = john; host = myhost; time = 01/01/2015 01:07;  
> feature = BBB; result = APPROVED
> 
> I’d like to create a dashboard in Kibana 4 which would show a joint table  
> combining both sources.  
> Using pseudo-SQL code, it should do something like:
> 
> select  
> jobs.jobid,jobs.user,jobs.host,license.feature,license.result,count(license.time)  
> from jobs  
> LEFT JOIN license  
> WHERE jobs.exitstatus=-3002 AND license.user=jobs.user AND  
> license.host=jobs.host AND license.time\>=jobs.starttime AND  
> license.time\<=jobs.finishtime  
> GROUP BY jobs.jobid,jobs.user,jobs.host
> 
> Thanks in advance,  
> Gregory
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAHTr4ZuW4n8JLyAXsnM%3Dppv\_Wjg1SSm0OJrmyVYWKkAtrKTzUw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAHTr4ZuW4n8JLyAXsnM%3Dppv_Wjg1SSm0OJrmyVYWKkAtrKTzUw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Gregory\_Touretsky](https://avatars.discourse-cdn.com/v4/letter/g/e36b37/32.png) [@Gregory\_Touretsky](https://discuss.elastic.co/u/Gregory_Touretsky)\
**Post date:** [January 12, 2015, 10:10pm UTC](https://discuss.elastic.co/t/join-between-two-different-sources-using-kibana-4/21591/3 "2015-01-12T22:10:54Z")

</div>

Is there a way to manage it via Kibana interface just at the query time?  
Something like Splunk "transaction" statement, which allows to group events  
into transactions

On Monday, January 12, 2015 at 9:38:56 PM UTC+2, Itamar Syn-Hershko wrote:

> You either use parent / child  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/parent-child.html)
> 
> Or index denormalized data in the first place
> 
> Elasticsearch isn't meant to be used using the same models as relational  
> databases
> 
> --
> 
> Itamar Syn-Hershko  
> [http://code972.com](http://code972.com) | @synhershko [https://twitter.com/synhershko](https://twitter.com/synhershko)  
> Freelance Developer & Consultant  
> Author of RavenDB in Action [http://manning.com/synhershko/](http://manning.com/synhershko/)
> 
> On Mon, Jan 12, 2015 at 9:36 PM, Gregory Touretsky \<[gregory....@intel.com](mailto:gregory....@intel.com)  
> \<javascript:\>\> wrote:
> 
> > Hi,
> > 
> > what would be the right way to join between two data sources using  
> > Kibana 4 interface?  
> > Assume 2 data sources:
> > 
> > 1. source=jobs, fields = {jobid, user, host, exitstatus,  
> > starttime,finishtime}  
> > Sample record:  
> > type = jobs; jobid = 1234; user = john; host = myhost; exitstatus =  
> > -3002; starttime = 01/01/2015 01:01; finishtime = 01/01/2015 01:15
> > 2. source=license, fields = {host, user, time, feature, result}  
> > Sample records:  
> > type = license; user = john; host = myhost; time = 01/01/2015  
> > 01:05; feature = AAA; result = DENIED  
> > type = license; user = john; host = myhost; time = 01/01/2015  
> > 01:07; feature = BBB; result = APPROVED
> > 
> > I’d like to create a dashboard in Kibana 4 which would show a joint table  
> > combining both sources.  
> > Using pseudo-SQL code, it should do something like:
> > 
> > select  
> > jobs.jobid,jobs.user,jobs.host,license.feature,license.result,count(license.time)  
> > from jobs  
> > LEFT JOIN license  
> > WHERE jobs.exitstatus=-3002 AND license.user=jobs.user AND  
> > license.host=jobs.host AND license.time\>=jobs.starttime AND  
> > license.time\<=jobs.finishtime  
> > GROUP BY jobs.jobid,jobs.user,jobs.host
> > 
> > Thanks in advance,  
> > Gregory
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4a4acea6-8397-4a40-94bf-9eddc269b70f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4a4acea6-8397-4a40-94bf-9eddc269b70f%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ed\_Kim](https://avatars.discourse-cdn.com/v4/letter/e/53a042/32.png) [@Ed\_Kim](https://discuss.elastic.co/u/Ed_Kim)\
**Post date:** [January 13, 2015, 8:02pm UTC](https://discuss.elastic.co/t/join-between-two-different-sources-using-kibana-4/21591/4 "2015-01-13T20:02:31Z")

</div>

Without parent/child, you'll need an extra layer to execute 2 queries and  
merge the results yourself.

On Monday, January 12, 2015 at 2:10:54 PM UTC-8, Gregory Touretsky wrote:

> Is there a way to manage it via Kibana interface just at the query time?  
> Something like Splunk "transaction" statement, which allows to group  
> events into transactions
> 
> On Monday, January 12, 2015 at 9:38:56 PM UTC+2, Itamar Syn-Hershko wrote:
> 
> > You either use parent / child  
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/parent-child.html)
> > 
> > Or index denormalized data in the first place
> > 
> > Elasticsearch isn't meant to be used using the same models as relational  
> > databases
> > 
> > --
> > 
> > Itamar Syn-Hershko  
> > [http://code972.com](http://code972.com) | @synhershko [https://twitter.com/synhershko](https://twitter.com/synhershko)  
> > Freelance Developer & Consultant  
> > Author of RavenDB in Action [http://manning.com/synhershko/](http://manning.com/synhershko/)
> > 
> > On Mon, Jan 12, 2015 at 9:36 PM, Gregory Touretsky \<[gregory....@intel.com](mailto:gregory....@intel.com)
> > 
> > > wrote:
> > 
> > > Hi,
> > > 
> > > what would be the right way to join between two data sources using  
> > > Kibana 4 interface?  
> > > Assume 2 data sources:
> > > 
> > > 1. source=jobs, fields = {jobid, user, host, exitstatus,  
> > > starttime,finishtime}  
> > > Sample record:  
> > > type = jobs; jobid = 1234; user = john; host = myhost; exitstatus  
> > > = -3002; starttime = 01/01/2015 01:01; finishtime = 01/01/2015 01:15
> > > 2. source=license, fields = {host, user, time, feature, result}  
> > > Sample records:  
> > > type = license; user = john; host = myhost; time = 01/01/2015  
> > > 01:05; feature = AAA; result = DENIED  
> > > type = license; user = john; host = myhost; time = 01/01/2015  
> > > 01:07; feature = BBB; result = APPROVED
> > > 
> > > I’d like to create a dashboard in Kibana 4 which would show a joint  
> > > table combining both sources.  
> > > Using pseudo-SQL code, it should do something like:
> > > 
> > > select  
> > > jobs.jobid,jobs.user,jobs.host,license.feature,license.result,count(license.time)  
> > > from jobs  
> > > LEFT JOIN license  
> > > WHERE jobs.exitstatus=-3002 AND license.user=jobs.user AND  
> > > license.host=jobs.host AND license.time\>=jobs.starttime AND  
> > > license.time\<=jobs.finishtime  
> > > GROUP BY jobs.jobid,jobs.user,jobs.host
> > > 
> > > Thanks in advance,  
> > > Gregory
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit  
> > > [https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/daf3dbf4-7b76-477e-8b10-5ca54cb53bf0%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ebedd993-e489-4ed5-885e-48be074df3f4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ebedd993-e489-4ed5-885e-48be074df3f4%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:39am UTC](https://discuss.elastic.co/t/join-between-two-different-sources-using-kibana-4/21591/5 "2017-07-06T00:39:17Z")

</div>


