# Trying to correlate data in kibana for reports

**URL:** <https://discuss.elastic.co/t/trying-to-correlate-data-in-kibana-for-reports/145750>\
**Category:** Kibana\
**Created:** [August 23, 2018, 2:16pm UTC](https://discuss.elastic.co/t/trying-to-correlate-data-in-kibana-for-reports/145750 "2018-08-23T14:16:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sagar19](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagar19/32/34761_2.png) [@sagar19](https://discuss.elastic.co/u/sagar19)\
**Post date:** [August 23, 2018, 2:16pm UTC](https://discuss.elastic.co/t/trying-to-correlate-data-in-kibana-for-reports/145750/1 "2018-08-23T14:16:47Z")

</div>

I am trying to correlate data so that i can generate a report. The start of the log has a message 'TRANSACTION\_STARTED' and there is GatewayTxCode associated with it. The last log has message 'TRANSACTION\_SUCCESS' (or failure). I need to generate a report where I need to show correlate these logs with the help of GatewayTxCode. Is there anyway we can do this in kibana and generate reports? I am pasting the json doc of the log message.

{  
"\_index": "abcd-local-2018.08.23",  
"\_type": "logevent",  
"\_id": "2\_b0bc7bb1-6402-49db-9e4a-3aa3982d828a",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"@timestamp": "2018-08-23T12:14:18.8640746+01:00",  
"level": "Information",  
"messageTemplate": "TRANSACTION\_SUCCESS",  
"message": "TRANSACTION\_SUCCESS",  
"fields": {  
"GatewayTxCode": "7845a46d-d834-4a00-9ae5-08ed5ed55350",  
"CorrelationId": "7ae5f117-f1e8-44a1-afec-5a433c2751b5",  
"SourceContext": "xyzr",  
"Service": "PWSP",  
"EnvironmentId": "cdef",  
"EnvironmentUserName": "abcd"  
}  
},  
"fields": {  
"@timestamp": [  
"2018-08-23T11:14:18.864Z"  
]  
},  
"sort": [  
1535022858864  
]  
}

Any help will be much appreciated.

Thanks,

Sagar

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [August 24, 2018, 10:39am UTC](https://discuss.elastic.co/t/trying-to-correlate-data-in-kibana-for-reports/145750/2 "2018-08-24T10:39:58Z")

</div>

Hello,

Elasticsearch is not a database, it's a document store. Generally speaking, the way to work with document stores is to denormalize your data as much as possible, usually by replicating data that you would normally group up into different tables in a relational database. So the short answer, you can't .  
The long answer: if you ingest the data in 2 different indices, you could do something similar by using this Logstash ingest plugin. [https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html)

But for what you're looking, an SQL database is what you need.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2018, 10:40am UTC](https://discuss.elastic.co/t/trying-to-correlate-data-in-kibana-for-reports/145750/3 "2018-09-21T10:40:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
