# Match Field Contents

**URL:** <https://discuss.elastic.co/t/match-field-contents/2537>\
**Category:** Kibana\
**Created:** [June 12, 2015, 5:16am UTC](https://discuss.elastic.co/t/match-field-contents/2537 "2015-06-12T05:16:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![peasead](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peasead/32/56562_2.png) [@peasead](https://discuss.elastic.co/u/peasead)\
**Post date:** [June 12, 2015, 5:16am UTC](https://discuss.elastic.co/t/match-field-contents/2537/1 "2015-06-12T05:16:51Z")

</div>

I apologize if I don't use the proper terminology, I'm new to ELK. I've done a lot of searching on this, but haven't found the answer...it's so simple that I'm sure I'm just not using the right terminology or it's Kibana 101.

I have two inputs in Logstash, one with some firewall logs and one with some IP addresses. I want a list in Kibana of IPs that are only in both logs.

I've used grok filters to make the IP field names the same for both log files (src\_ip) and I've tried making them different per log file (src\_ip1 & src\_ip2), but I can't figure out how to say "give me a list of only the IP addresses that are in both of these log files".

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [June 12, 2015, 10:47am UTC](https://discuss.elastic.co/t/match-field-contents/2537/2 "2015-06-12T10:47:24Z")

</div>

I think you're going to need to have an external process that runs the queries necessary to produce this data and stores it into elasticsearch.

I can't imagine a way to write this as a search aggregation, let alone how it would be visualized in Kibana.

---

<div class="post-metadata">

**Author:** ![peasead](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peasead/32/56562_2.png) [@peasead](https://discuss.elastic.co/u/peasead)\
**Post date:** [June 12, 2015, 12:57pm UTC](https://discuss.elastic.co/t/match-field-contents/2537/3 "2015-06-12T12:57:16Z")

</div>

Thanks for the response.

I'm surprised that there isn't some "src\_ip1" == "src\_ip2" search for data IN Kibana. If I copy the src\_ip2 data and paste it into a search box in Kibana into the search box, that works...but there are thousands of src\_ip2 IP addresses.

Is there a way to search data that isn't in Kibana? Like search a lookup table or something?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:18pm UTC](https://discuss.elastic.co/t/match-field-contents/2537/4 "2017-07-06T14:18:13Z")

</div>


