# Linking separate log records

**URL:** <https://discuss.elastic.co/t/linking-separate-log-records/276680>\
**Category:** Kibana\
**Created:** [June 22, 2021, 4:39pm UTC](https://discuss.elastic.co/t/linking-separate-log-records/276680 "2021-06-22T16:39:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kibanaquery](https://avatars.discourse-cdn.com/v4/letter/k/9de0a6/32.png) [@kibanaquery](https://discuss.elastic.co/u/kibanaquery)\
**Post date:** [June 22, 2021, 4:39pm UTC](https://discuss.elastic.co/t/linking-separate-log-records/276680/1 "2021-06-22T16:39:56Z")

</div>

Hi,

I was wondering if is possible to perform a basic link function (either in Discover or Visualise)?

All my records have a common identifier, say "LinkID", but only some records have "Type" and only some have "Colour".

What I'd like to do is count how many records have "Type" of "Cheese" and "Colour" of "Yellow".  
Which is fine when its all in one record, but how do I count them when they are in different records (albeit tied by the LinkID value)?

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [July 5, 2021, 3:35pm UTC](https://discuss.elastic.co/t/linking-separate-log-records/276680/2 "2021-07-05T15:35:06Z")

</div>

I could set up a simple data table based in this testing index that follows your example

```auto
PUT test_links
{
  "mappings": {
    "properties": {
      "linkid": {
        "type": "integer"
      },
      "colour": {
        "type": "keyword"
      },
      "type": {
        "type": "keyword"
      }
    }
  }
}

POST test_links/_bulk
{ "index" : { "_id" : "1" } }
{ "linkid" : 1 }
{ "index" : { "_id" : "2" } }
{ "linkid" : 1, "colour": "blue" }
{ "index" : { "_id" : "3" } }
{ "linkid" : 1, "type": "cheese" }
{ "index" : { "_id" : "4" } }
{ "linkid" : 2, "colour": "red", "type": "cheese" }
{ "index" : { "_id" : "5" } }
{ "linkid" : 3, "colour": "orange", "type": "bread" }
{ "index" : { "_id" : "6" } }
{ "linkid" : 4, "colour": "orange" }
{ "index" : { "_id" : "7" } }
{ "linkid" : 4, "type": "cheese" }

```

Then the table needs to use a histogram with a `1` value range step and for the metrics use a `Top Hit` aggregation for each field

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10ce184409a9c8a9d730c436e72771983fe60ce2.png)

Hope it helps!

---

<div class="post-metadata">

**Author:** ![kibanaquery](https://avatars.discourse-cdn.com/v4/letter/k/9de0a6/32.png) [@kibanaquery](https://discuss.elastic.co/u/kibanaquery)\
**Post date:** [July 5, 2021, 6:16pm UTC](https://discuss.elastic.co/t/linking-separate-log-records/276680/3 "2021-07-05T18:16:21Z")

</div>

Thanks for your help, I'll check this out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2021, 6:16pm UTC](https://discuss.elastic.co/t/linking-separate-log-records/276680/4 "2021-08-02T18:16:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
