# Make two indexes which different fields communicate

**URL:** <https://discuss.elastic.co/t/make-two-indexes-which-different-fields-communicate/271137>\
**Category:** Kibana\
**Created:** [April 24, 2021, 9:50am UTC](https://discuss.elastic.co/t/make-two-indexes-which-different-fields-communicate/271137 "2021-04-24T09:50:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dumpnetflow](https://avatars.discourse-cdn.com/v4/letter/d/eb9ed0/32.png) [@dumpnetflow](https://discuss.elastic.co/u/dumpnetflow)\
**Post date:** [April 24, 2021, 9:50am UTC](https://discuss.elastic.co/t/make-two-indexes-which-different-fields-communicate/271137/1 "2021-04-24T09:50:59Z")

</div>

Hi Everyone,

I have two indexes which are automatically generated by an application which I cannot modify.

Index one has two fields:  
{  
"mappings": {  
"properties": {  
"src.ip.address": {  
"type": "ip"  
},  
"dst.ip.address": {  
"type": "ip"  
}  
}  
}  
}

Index two has two fields:  
{  
"mappings": {  
"properties": {  
"SOURCE\_IP\_ADDRESS": {  
"type": "ip"  
},  
"DESTINATION\_IP\_ADDRESS": {  
"type": "ip"  
}  
}  
}  
}

I there a way I can modify on of the two kibana index pattern to be able to add an alias or something else to be able to filter for those values?

To be more speficic if I filter for src.ip.address in a dashboard made with both the index patterns, I also filter for SOURCE\_IP\_ADDRESS on th other index (since they have the same value).

Thanks!

A.

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 24, 2021, 12:23pm UTC](https://discuss.elastic.co/t/make-two-indexes-which-different-fields-communicate/271137/2 "2021-04-24T12:23:38Z")

</div>

Which version are you running on?

---

<div class="post-metadata">

**Author:** ![dumpnetflow](https://avatars.discourse-cdn.com/v4/letter/d/eb9ed0/32.png) [@dumpnetflow](https://discuss.elastic.co/u/dumpnetflow)\
**Post date:** [April 26, 2021, 8:41am UTC](https://discuss.elastic.co/t/make-two-indexes-which-different-fields-communicate/271137/3 "2021-04-26T08:41:50Z")

</div>

7.8.0

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 26, 2021, 9:07am UTC](https://discuss.elastic.co/t/make-two-indexes-which-different-fields-communicate/271137/4 "2021-04-26T09:07:23Z")

</div>

There are multiple ways to do this. It make sense to solve this as far upstream in your pipeline as possible.

- If you can control the data source, change it there (already ruled out)
- If you can control the mapping of the indices, use field aliases ([Alias field type | Elasticsearch Guide [master] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/master/alias.html)) or `copy_to` [copy\_to | Elasticsearch Guide [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/copy-to.html)
- If you can only control Kibana, use a scripted field to check both locations for the actual value ([Scripted fields | Kibana Guide [7.12] | Elastic](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html))

This last option is not recommended in this situation, as it will be much slower than the other options.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2021, 9:08am UTC](https://discuss.elastic.co/t/make-two-indexes-which-different-fields-communicate/271137/5 "2021-05-24T09:08:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
