# \[MAPS\]\[scripted field\]Heading and lat/lon not in same doc, any way to merge them?

**URL:** <https://discuss.elastic.co/t/maps-scripted-field-heading-and-lat-lon-not-in-same-doc-any-way-to-merge-them/202783>\
**Category:** Kibana\
**Created:** [October 9, 2019, 7:55am UTC](https://discuss.elastic.co/t/maps-scripted-field-heading-and-lat-lon-not-in-same-doc-any-way-to-merge-them/202783 "2019-10-09T07:55:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [October 9, 2019, 7:55am UTC](https://discuss.elastic.co/t/maps-scripted-field-heading-and-lat-lon-not-in-same-doc-any-way-to-merge-them/202783/1 "2019-10-09T07:55:15Z")

</div>

Hi,

I am collecting lat/lon data for a moving object containing three fields.

> {  
> "object": "name",  
> "geo": "lat lon",  
> "@timestamp": 12:00:00  
> }

I am also receiving heading information from a different source.

> {  
> "object": "name",  
> "heading": "200",  
> "@timestamp": 11:23:00  
> }

The lat/lon is collected hourly, heading at random intervals.

I want to use the heading data to plot the direction of an icon on the MAPS app. But because the data is not in the same document this doesn't look like a straight forward job. I tried using term joins but I don't think they can do what I want.

Is there any way Kibana can somehow pull the closest heading data (based on @timestamp) into the document containing the lat/lon?

---

<div class="post-metadata">

**Author:** ![Aaron\_Caldwell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron_caldwell/32/45755_2.png) [@Aaron\_Caldwell](https://discuss.elastic.co/u/Aaron_Caldwell)\
**Post date:** [October 9, 2019, 8:57pm UTC](https://discuss.elastic.co/t/maps-scripted-field-heading-and-lat-lon-not-in-same-doc-any-way-to-merge-them/202783/2 "2019-10-09T20:57:15Z")

</div>

Hello Sjaak,

If you're using Logstash to ingest your data, [the filter plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html) may work for you. You would just pull the heading data from one index into the new docs being inserted into their index.

In the near future, this should be an option using Elasticsearch Ingest Enrichment which is in-progress now and described [here](https://github.com/elastic/elasticsearch/issues/32789). Effectively this would allow you to ingest data and "decorate" the data on ingest using data from a different index. Feel free to keep an eye on this issue!

Regards,  
Aaron

---

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [October 10, 2019, 6:39am UTC](https://discuss.elastic.co/t/maps-scripted-field-heading-and-lat-lon-not-in-same-doc-any-way-to-merge-them/202783/3 "2019-10-10T06:39:27Z")

</div>

That is a very good idea. I spent today making a demo and while it could work, the queries supported by that filter are very limited. As far as I can tell bool queries are not supported (not mentioned anywhere and Logstash reports no errors, just doesn't work) and neither is KQL.

This means there is no way to search for documents older than the Logstash document. My data is not real time and I cannot be sure Logstash will ingest everything oldest first so without some kind of range filter it might retrieve the wrong data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2019, 6:39am UTC](https://discuss.elastic.co/t/maps-scripted-field-heading-and-lat-lon-not-in-same-doc-any-way-to-merge-them/202783/4 "2019-11-07T06:39:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
