# Merge two index to create third index using logstash

**URL:** <https://discuss.elastic.co/t/merge-two-index-to-create-third-index-using-logstash/249767>\
**Category:** Logstash\
**Created:** [September 24, 2020, 8:23am UTC](https://discuss.elastic.co/t/merge-two-index-to-create-third-index-using-logstash/249767 "2020-09-24T08:23:17Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)\
**Post date:** [September 24, 2020, 2:56pm UTC](https://discuss.elastic.co/t/merge-two-index-to-create-third-index-using-logstash/249767/2 "2020-09-24T14:56:40Z")

</div>

I think logstash might not be the right tool, it's conceptually a mapper, what you need is a reducer. In practice you want to _group_ documents, in your case you want to group docs with the same code field. You need aggregations for that.

Long story short, please have a look at the very similar ask: [Merging documents based on matched fields values](https://discuss.elastic.co/t/merging-documents-based-on-matched-fields-values/249728/2)

As you explicitly say that you want an index as output, transform sounds like the right tool to me.

---

_[View the full topic](https://discuss.elastic.co/t/merge-two-index-to-create-third-index-using-logstash/249767)._
