# Querying in Elasticsearch

**URL:** <https://discuss.elastic.co/t/querying-in-elasticsearch/128507>\
**Category:** Elasticsearch\
**Created:** [April 18, 2018, 10:06am UTC](https://discuss.elastic.co/t/querying-in-elasticsearch/128507 "2018-04-18T10:06:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![soumya\_sahoo](https://avatars.discourse-cdn.com/v4/letter/s/bc79bd/32.png) [@soumya\_sahoo](https://discuss.elastic.co/u/soumya_sahoo)\
**Post date:** [April 18, 2018, 10:06am UTC](https://discuss.elastic.co/t/querying-in-elasticsearch/128507/1 "2018-04-18T10:06:30Z")

</div>

Hi Team. Is it possible to issue a single query for 2 different indexes.

Lets say I have 2 index - A & B and I need to write a query where in I need the count of matches where A.xyz = B.abc , where xyz, abc = fields of respective index.

Can anyone help me with this by adding comments along these lines.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 18, 2018, 2:14pm UTC](https://discuss.elastic.co/t/querying-in-elasticsearch/128507/2 "2018-04-18T14:14:18Z")

</div>

No. You can't join 2 indices at query time.

---

<div class="post-metadata">

**Author:** ![soumya\_sahoo](https://avatars.discourse-cdn.com/v4/letter/s/bc79bd/32.png) [@soumya\_sahoo](https://discuss.elastic.co/u/soumya_sahoo)\
**Post date:** [April 18, 2018, 3:31pm UTC](https://discuss.elastic.co/t/querying-in-elasticsearch/128507/3 "2018-04-18T15:31:35Z")

</div>

Hi there,

How about this - Let's say I have 2 csv files - A and B  
I need to ingest the csv data to my elastic server for potential search  
As of now I use logstash to ingest data to my elastic server - and now I want to check the records which have a relationship like A.[fieldname]=B.[fieldname].

How can I accomplish this using ELK stack.

Urgent help!

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 25, 2018, 6:33am UTC](https://discuss.elastic.co/t/querying-in-elasticsearch/128507/4 "2018-04-25T06:33:13Z")

</div>

You can't do that.

But you can try to do join at index time.  
Like instead of indexing:

```auto
PUT a/_doc/1
{
  "fieldname": "foo",
  "foo_a": "bar"
}
PUT b/_doc/1
{
  "fieldname": "foo",
  "foo_b": "bar"
}

```

Index:

```auto
PUT ab/_doc/1
{
  "fieldname": "foo",
  "foo_a": "bar",
  "foo_b": "bar"
}

```

Logstash jdbc filter might help for that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 23, 2018, 6:33am UTC](https://discuss.elastic.co/t/querying-in-elasticsearch/128507/5 "2018-05-23T06:33:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
