# Multiple sql table to one elastic index

**URL:** <https://discuss.elastic.co/t/multiple-sql-table-to-one-elastic-index/189188>\
**Category:** Logstash\
**Created:** [July 6, 2019, 6:19am UTC](https://discuss.elastic.co/t/multiple-sql-table-to-one-elastic-index/189188 "2019-07-06T06:19:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![manish\_kaushik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manish_kaushik/32/48169_2.png) [@manish\_kaushik](https://discuss.elastic.co/u/manish_kaushik)\
**Post date:** [July 6, 2019, 6:19am UTC](https://discuss.elastic.co/t/multiple-sql-table-to-one-elastic-index/189188/1 "2019-07-06T06:19:17Z")

</div>

I have been using logstash to index data in elastic from mysql via jdbc plugin. I was using join query to pull the data but my usecase increased to check for insert and updates. So, i used tracking columns and :sql\_last\_value but I have updation columns in both the tabels and want to check for updation or insertion in any one of them. However, i have only been able to made the updation check on one updation column of one table only. How, can i make a check on both updation table i.e. how to give two(multi) tracking columns to logstash.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 6, 2019, 7:12am UTC](https://discuss.elastic.co/t/multiple-sql-table-to-one-elastic-index/189188/2 "2019-07-06T07:12:18Z")

</div>

I do not think you can. You need to write queries that generate documents with a single tracking column. If you need to track changes across multiple tables that form part of a join you may need to select the maximum of a number of tracking columns into a single tracking column to compare with. This will naturally result in a more complex SQL query, but should be possible.

If you can not create a single query the easiest way may be to create a custom script and use that instead of Logstash.

---

<div class="post-metadata">

**Author:** ![manish\_kaushik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manish_kaushik/32/48169_2.png) [@manish\_kaushik](https://discuss.elastic.co/u/manish_kaushik)\
**Post date:** [July 6, 2019, 1:51pm UTC](https://discuss.elastic.co/t/multiple-sql-table-to-one-elastic-index/189188/3 "2019-07-06T13:51:48Z")

</div>

Thanks, can you hint me with something on how can i achieve combine multiple columns because when I concat i cannot use it in the same query and also how can i make :last\_sql\_value to map on that field because tracking column only takes [integer, timestamp].  
@Christian_Dahlqvist

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 6, 2019, 1:58pm UTC](https://discuss.elastic.co/t/multiple-sql-table-to-one-elastic-index/189188/4 "2019-07-06T13:58:54Z")

</div>

Maybe [something like this](https://stackoverflow.com/questions/71022/sql-max-of-multiple-columns) would work? That may not be the way to do it but it has been quite some time since I write more advanced SQL queries.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2019, 2:11pm UTC](https://discuss.elastic.co/t/multiple-sql-table-to-one-elastic-index/189188/5 "2019-08-03T14:11:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
