# Tagging - Correlating Between Datasets

**URL:** <https://discuss.elastic.co/t/tagging-correlating-between-datasets/368873>\
**Category:** Kibana\
**Tags:** runtime\
**Created:** [October 15, 2024, 8:21pm UTC](https://discuss.elastic.co/t/tagging-correlating-between-datasets/368873 "2024-10-15T20:21:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [October 15, 2024, 8:21pm UTC](https://discuss.elastic.co/t/tagging-correlating-between-datasets/368873/1 "2024-10-15T20:21:38Z")

</div>

Hello,

I want to do something like add tags but to datasets.  
I know I can use an ingest pipeline and then apply it all ingest pipelines but this isn't practical as updates to tags can't be retroactive.

Is it possible to do something like this in between a runtime field and a ingest pipeline?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 15, 2024, 8:46pm UTC](https://discuss.elastic.co/t/tagging-correlating-between-datasets/368873/2 "2024-10-15T20:46:55Z")

</div>

Can you provide more context?

It is not clear what you mean by tagging datasets and how this would be used.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [October 15, 2024, 9:01pm UTC](https://discuss.elastic.co/t/tagging-correlating-between-datasets/368873/3 "2024-10-15T21:01:18Z")

</div>

Yes,  
So lets say I have multiple data sources, and I have `host.name` field in all of them. I would like to add like a runtime field like "`tags`" or add to "`tags`" to all data sources where there's an instance of `host.name: "Elastic01"` and so then in each data view it will have the runtime field `tags: "Elastic Nodes"`.

So then if I want to find all instance across all data sources, I just use `tags: "Elastic Nodes"`

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 15, 2024, 9:14pm UTC](https://discuss.elastic.co/t/tagging-correlating-between-datasets/368873/4 "2024-10-15T21:14:15Z")

</div>

Yeah, this would be like adding a tag into the `tags` field, which is used for cases like this.

The way to do that is what you described, using ingest pipelines.

Not sure if you can do that with runtime fields, but I do not use them because they can be extremely expensive on searchs.

Do you really need it to be applied to older data? Depend on what you want to do you may be able to do that using update\_by\_query to add the tag into the `tags` field.

If it is just a couple of hosts you want to tag it would not be that complicated.
