# Merging fields of two index pattern

**URL:** <https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564>\
**Category:** Kibana\
**Created:** [September 30, 2022, 1:43pm UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564 "2022-09-30T13:43:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![random\_dash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/random_dash/32/100548_2.png) [@random\_dash](https://discuss.elastic.co/u/random_dash)\
**Post date:** [September 30, 2022, 1:43pm UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564/1 "2022-09-30T13:43:57Z")

</div>

Hi,

I have two data streams in Kibana with similar information. I am trying to aggregate them by creating a new index pattern. Each of them has a field "state". For one of them, the state can be [passed, failed], and for the other one is [Succeeded, Failed]. I want to aggerate passed with Succeeded and failed with Failed. This is my new index pattern:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a312724aa59c5b3cc0b6813be2113c6442b8f887.png)

when I try to simply visualize the state for the merged index pattern, I get the below chart, which is expected:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/3/33aba06a6f1bb7ec89885926fdf30f1583bc3a4e.jpeg)

To merge states, I defined a lookup for merged index pattern as below:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9390485133064220deebf257df4460b52d12dfb.png)

that I expected to merge the states. But I get this in visualization:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/8/589e0f5ca4a7193a9c777b5b164a931260479016.jpeg)

So my question is, how can I merge the data from both streams?

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [October 24, 2022, 2:19pm UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564/2 "2022-10-24T14:19:49Z")

</div>

Sorry for the late reply, have you solved this? Which version of the stack are you running?

You should use [runtime fields](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/runtime.html) to do this type of data manipulation at query time. For a simple dataset following your data:

```auto
PUT discuss-315564-one
{
  "mappings": {
    "properties": {
      "state": {"type": "keyword"}
    }
  }
}

PUT discuss-315564-one/_bulk
{ "index": {}}
{ "state": "Succeeded" }
{ "index": {}}
{ "state": "Succeeded" }
{ "index": {}}
{ "state": "Failed" }
{ "index": {}}
{ "state": "Succeeded" }

PUT discuss-315564-two
{
  "mappings": {
    "properties": {
      "state": {"type": "keyword"}
    }
  }
}

PUT discuss-315564-two/_bulk
{ "index": {}}
{ "state": "success" }
{ "index": {}}
{ "state": "success" }
{ "index": {}}
{ "state": "fail" }
{ "index": {}}
{ "state": "success" }

# Check 8 docs are returned
GET discuss-315564-*/_search

# Cleanup
DELETE discuss-315564-index-*

```

A data view with this new runtime field:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/a/3aed848e5f57599d81fdce970f3da3d239f04f85.png)

```auto
String state = doc['state'].value;

if (state == 'Succeeded' || state == 'success') emit('yes');
else if (state == 'Failed' || state == 'fail') emit('no');
else emit ('n/a');

```

Will render on Lens without issues

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/1/914f18061dbb0eb0b699f8d573e519f50ebf34d4.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2022, 6:02am UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564/3 "2022-11-20T06:02:30Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2022, 2:55am UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564/4 "2022-12-18T02:55:53Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2023, 11:10pm UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564/5 "2023-01-14T23:10:08Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2023, 11:10pm UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564/6 "2023-02-11T23:10:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
