# Kibana - How to join the values of a field cross events based on userId and sessionIDinto 1 string by timestamp ascendly with script fields

**URL:** <https://discuss.elastic.co/t/kibana-how-to-join-the-values-of-a-field-cross-events-based-on-userid-and-sessionidinto-1-string-by-timestamp-ascendly-with-script-fields/177172>\
**Category:** Kibana\
**Created:** [April 17, 2019, 12:32am UTC](https://discuss.elastic.co/t/kibana-how-to-join-the-values-of-a-field-cross-events-based-on-userid-and-sessionidinto-1-string-by-timestamp-ascendly-with-script-fields/177172 "2019-04-17T00:32:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [April 17, 2019, 12:32am UTC](https://discuss.elastic.co/t/kibana-how-to-join-the-values-of-a-field-cross-events-based-on-userid-and-sessionidinto-1-string-by-timestamp-ascendly-with-script-fields/177172/1 "2019-04-17T00:32:47Z")

</div>

Hi Team,

I have below events in elasitcsearch.  
timestamp,module,page,userId,actionType,sessionId  
2019-02-13 02:56:05.356,succession,talentsearch,cgrant1,list\_saved\_search,sid1  
2019-02-13 02:56:05.358,succession,talentsearch,lokamoto1,list\_saved\_search,sid2  
2019-02-13 02:56:05.358,succession,talentsearch,cgrant1,start\_over,sid1  
2019-02-13 02:56:05.360,succession,talentsearch,cgrant1,delete\_saved\_search,sid1  
2019-02-13 02:56:05.361,succession,talentsearch,lokamoto1,search,sid2  
2019-02-13 02:56:05.365,succession,talentsearch,lokamoto1,nominate,sid2

with above sample log event, I come up with 2 user scenarios from actionType field

1. list\_saved\_search-\>start\_over-\>delete\_saved\_search (cgrant1's user scenario in sid1)
2. list\_saved\_search-\>search-\>nominate (lokamoto's user scenario in sid2)

how can I join the actionType fields with userId and httpsessionID cross events to get a string represting a user scenario with script fields???

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 17, 2019, 5:19am UTC](https://discuss.elastic.co/t/kibana-how-to-join-the-values-of-a-field-cross-events-based-on-userid-and-sessionidinto-1-string-by-timestamp-ascendly-with-script-fields/177172/2 "2019-04-17T05:19:11Z")

</div>

Scripted fields run in the context of a single document, not a collection of documents, so I do not think this can be done using scripted fields. For scenarios where ordering of multiple events is important [creating a separate entity-centric index](https://discuss.elastic.co/t/updating-a-field-in-a-doc-with-the-fields-been-obtained-from-another-dataset-basically-joins-like-feature/175080/4) might be the best approach.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2019, 5:19am UTC](https://discuss.elastic.co/t/kibana-how-to-join-the-values-of-a-field-cross-events-based-on-userid-and-sessionidinto-1-string-by-timestamp-ascendly-with-script-fields/177172/3 "2019-05-15T05:19:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
