# Regroupe LDAP log lines with same id on the same DataTable raw

**URL:** https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable-raw/157670
**Category:** Kibana
**Created:** [November 21, 2018, 9:53am UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable-raw/157670 "2018-11-21T09:53:49Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Noureddine\_Brahmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/noureddine_brahmi/32/62092_2.png) [@Noureddine\_Brahmi](https://discuss.elastic.co/u/Noureddine_Brahmi)
#### Post date: [November 21, 2018, 9:53am UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable-raw/157670/1 "2018-11-21T09:53:49Z")

</div>

Hello,

I'm currently working on an ElasticSearch project that monitors LDAP logs.

In the LDAP logs, related events shares the same id (connection\_number). I was wondering is there is a solution to regroupe the various fieds in different documents that shares the same id.

Ex:

[04/Aug/2018:22:34:15 +0200] conn=184214 op=0 msgId=1 - BIND dn="cn=XOPOY,ou=programs,o=psa" method=128 version=3

[04/Aug/2018:22:34:15 +0200] conn=184214 op=0 msgId=1 - RESULT err=0 tag=97 nentries=0 etime=0.000450 dn="cn=mwplim02,ou=programs,o=psa"

[04/Aug/2018:22:34:15 +0200] conn=184214 op=2 msgId=3 - UNBIND

The goal is to have a datatable with:

**TIMESTAMP | conn | dn (from the BIND) | err | etime**

PS: I already have a grok filter in place that sperates the various fields

Thank you !

---

<div class="post-metadata">

### Author: ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)
#### Post date: [November 22, 2018, 11:50am UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable-raw/157670/2 "2018-11-22T11:50:56Z")

</div>

Something like this has to be done most likely at ingest time. I think the Logstash team will able to help you more with this. You can ask in their part of the forums.

---

<div class="post-metadata">

### Author: ![Noureddine\_Brahmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/noureddine_brahmi/32/62092_2.png) [@Noureddine\_Brahmi](https://discuss.elastic.co/u/Noureddine_Brahmi)
#### Post date: [November 22, 2018, 12:07pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable-raw/157670/3 "2018-11-22T12:07:28Z")

</div>

Thanks for the reply, I will do that.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 20, 2018, 12:07pm UTC](https://discuss.elastic.co/t/regroupe-ldap-log-lines-with-same-id-on-the-same-datatable-raw/157670/4 "2018-12-20T12:07:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
