Query to access distinct fields from different documents

I think I can solve this problem using the logstash elapsed plugin but I'm not able to install the plugin. I'll start a new topic in the logstash category.