# Linking of query/search

**URL:** <https://discuss.elastic.co/t/linking-of-query-search/19674>\
**Category:** Elasticsearch\
**Created:** [September 9, 2014, 5:59am UTC](https://discuss.elastic.co/t/linking-of-query-search/19674 "2014-09-09T05:59:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![matej\_zerovnik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matej_zerovnik/32/1280_2.png) [@matej\_zerovnik](https://discuss.elastic.co/u/matej_zerovnik)\
**Post date:** [September 9, 2014, 5:59am UTC](https://discuss.elastic.co/t/linking-of-query-search/19674/1 "2014-09-09T05:59:39Z")

</div>

I'm currently evaluating using ES and logstash as a central log management.  
Aside from storing logs in ES, I will need to do some querying and reports  
as well. This is where I get into troubles, because I'm not sure how to  
solve the following problem.

I have a service, where a certain user logs in via web page. That login is  
logged in apache log. Login is then further forwarded to Radius server(logs  
to his log file) and from there, to LDAP server, which also logs to his own  
file. I would like to extract information(last log line) for a certain user  
to figure out, where the login failed(http,radius or ldap). This would be a  
script for helpdesk, to quickly check where login stopped and investigate  
further.

In SQL database, I could just link(=) fields in database and get a match.  
Something like  
SELECT httpd.username, httpd.full\_log\_message, radius.full\_log\_message,  
ldap.full\_log\_message  
FROM httpd,radius,ldap  
WHERE httpd.login = radius.login AND radius.login = ldap.login  
LIMIT 1

Can I achieve that in elasticsearch?  
How is that called in elasticsearch?  
Can someone provide an example or link to it?

Thanks, Matej

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/c8a239e8-a1ac-43d9-bc2d-3ce58cc204c4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/c8a239e8-a1ac-43d9-bc2d-3ce58cc204c4%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![matej\_zerovnik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matej_zerovnik/32/1280_2.png) [@matej\_zerovnik](https://discuss.elastic.co/u/matej_zerovnik)\
**Post date:** [September 12, 2014, 7:45am UTC](https://discuss.elastic.co/t/linking-of-query-search/19674/2 "2014-09-12T07:45:45Z")

</div>

Hello!

Can anyone shine some light on my question?  
Is the query in question achievable in ES directly?

If not, I can probably do that in application later, but it would be nicer  
if ES could serve me the final results.

Matej

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [September 12, 2014, 2:55pm UTC](https://discuss.elastic.co/t/linking-of-query-search/19674/3 "2014-09-12T14:55:44Z")

</div>

You cannot join documents in Lucene/Elasticsearch (at least not like a  
RDBMS). You would need to either denormalize your data, join on the client  
side or execute 2+ queries.

--  
Ivan

On Fri, Sep 12, 2014 at 12:45 AM, [matej.zerovnik@gmail.com](mailto:matej.zerovnik@gmail.com) wrote:

> Hello!
> 
> Can anyone shine some light on my question?  
> Is the query in question achievable in ES directly?
> 
> If not, I can probably do that in application later, but it would be nicer  
> if ES could serve me the final results.
> 
> Matej
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQBgybZpCz1bKV%3DE7XF\_cHGDuFKS1wruKNAYZTbo8t0jvA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQBgybZpCz1bKV%3DE7XF_cHGDuFKS1wruKNAYZTbo8t0jvA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Alex\_Kamil](https://avatars.discourse-cdn.com/v4/letter/a/d9b06d/32.png) [@Alex\_Kamil](https://discuss.elastic.co/u/Alex_Kamil)\
**Post date:** [September 12, 2014, 3:32pm UTC](https://discuss.elastic.co/t/linking-of-query-search/19674/4 "2014-09-12T15:32:04Z")

</div>

you can combine ES with RDBMS, and run your SQL queries either directly  
against db, or pull data via JDBC River into ES, I wrote about it here:  
[http://lessc0de.github.io/connecting\_hbase\_to\_elasticsearch.html](http://lessc0de.github.io/connecting_hbase_to_elasticsearch.html)

On Fri, Sep 12, 2014 at 10:55 AM, Ivan Brusic [ivan@brusic.com](mailto:ivan@brusic.com) wrote:

> You cannot join documents in Lucene/Elasticsearch (at least not like a  
> RDBMS). You would need to either denormalize your data, join on the client  
> side or execute 2+ queries.
> 
> --  
> Ivan
> 
> On Fri, Sep 12, 2014 at 12:45 AM, [matej.zerovnik@gmail.com](mailto:matej.zerovnik@gmail.com) wrote:
> 
> > Hello!
> > 
> > Can anyone shine some light on my question?  
> > Is the query in question achievable in ES directly?
> > 
> > If not, I can probably do that in application later, but it would be  
> > nicer if ES could serve me the final results.
> > 
> > Matej
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/6f3345f2-4b25-4b06-b203-4ad0de201e8f%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> > 
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQBgybZpCz1bKV%3DE7XF\_cHGDuFKS1wruKNAYZTbo8t0jvA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQBgybZpCz1bKV%3DE7XF_cHGDuFKS1wruKNAYZTbo8t0jvA%40mail.gmail.com)  
> [https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQBgybZpCz1bKV%3DE7XF\_cHGDuFKS1wruKNAYZTbo8t0jvA%40mail.gmail.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQBgybZpCz1bKV%3DE7XF_cHGDuFKS1wruKNAYZTbo8t0jvA%40mail.gmail.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAOtKWX623repUH5k2XbkFBFNu-b3cSKyObuyf793AVhOt3Gb-Q%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAOtKWX623repUH5k2XbkFBFNu-b3cSKyObuyf793AVhOt3Gb-Q%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:02am UTC](https://discuss.elastic.co/t/linking-of-query-search/19674/5 "2017-07-06T01:02:44Z")

</div>


