# Log Correlation

**URL:** <https://discuss.elastic.co/t/log-correlation/57187>\
**Category:** Logstash\
**Created:** [August 4, 2016, 7:55am UTC](https://discuss.elastic.co/t/log-correlation/57187 "2016-08-04T07:55:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![NicoYUE](https://avatars.discourse-cdn.com/v4/letter/n/96bed5/32.png) [@NicoYUE](https://discuss.elastic.co/u/NicoYUE)\
**Post date:** [August 4, 2016, 7:55am UTC](https://discuss.elastic.co/t/log-correlation/57187/1 "2016-08-04T07:55:36Z")

</div>

Hello,

I'm currently trying to use Logstash filter to correlate logs before outputting the result into Elasticsearch.

I thought about using aggregate when the logs are in a good order like

a  
b  
c

into "abc".

But the problem is, in some cases, the logs are not in the right order

a  
a2  
b  
b2  
c  
c2

And I need both "abc" and "a2b2c2", I don't really know what kind of method I should use to treat those cases efficiently.

Thanks.

---

<div class="post-metadata">

**Author:** ![NicoYUE](https://avatars.discourse-cdn.com/v4/letter/n/96bed5/32.png) [@NicoYUE](https://discuss.elastic.co/u/NicoYUE)\
**Post date:** [August 4, 2016, 8:13am UTC](https://discuss.elastic.co/t/log-correlation/57187/2 "2016-08-04T08:13:31Z")

</div>

I guess using Aggregate's Taskid on a unique field to differentiate event should be good...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:44am UTC](https://discuss.elastic.co/t/log-correlation/57187/3 "2017-07-06T04:44:57Z")

</div>


