# Using join field

**URL:** <https://discuss.elastic.co/t/using-join-field/372753>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [January 3, 2025, 3:22pm UTC](https://discuss.elastic.co/t/using-join-field/372753 "2025-01-03T15:22:39Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![denisbik349](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denisbik349/32/140451_2.png) [@denisbik349](https://discuss.elastic.co/u/denisbik349)\
**Post date:** [January 3, 2025, 3:22pm UTC](https://discuss.elastic.co/t/using-join-field/372753/1 "2025-01-03T15:22:39Z")

</div>

Hello everyone!

I have problem joining 2 documents in one index by using join type field.  
I have input, filter and output files configured for Logstash. I have index and index pattern set up in Elasticsearch. I was able to successfully retrieve the messages with out using join field. So I am having trouble only when I am trying to use this field. (I want to create a monitor with a query that requires joining 2 documents)

I receive 2 messages and they can be joined using one field. I use amazon\_es plugin in the output file for Logstash configuration. I have 2 indexes (1 that is working with out join field and 2 that is supposed to have join field). I send document to 2 indexes (Tried to send them separately - it didn't help). In 1 index I receive the message but the problem that join field is actually text type (As I understood for join field to work I am supposed to create new index with join field for it to be join type). In 2 index I either receive only 1 out of 2 messages or no messages at all or my Logstash crashes in the infinite loop of retrying to send messages. I tried a lot of different approaches but nothing worked for me and I think I might be missing some basic information.

So what I did is:

1. I created a new index using dev tool in Kibana
2. I updated the filter with 2 lines for my documents. _event.set("join\_field", "s3event")_ for parent document and _event.set("join\_field", { "name" =\> "lambda", "parent" =\> parsed\_message["requestPayload"]["Records"][0]["Sns"]["MessageId"] })_. So there is a field for parent document and I use a field with the same information for the child document.
3. And then I configure output for the correct index that I just created and send the message.

I tried so many approaches and can't think of what can be the issue, but the last thing I see that in Kibana join field actually has unknown type or maybe I set up the index incorrectly?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/b/abcc243f6b40bf0286f8e3c15701079b45c2c76a.png)

Here is the gist with my filter configuration, output (with out data) and index configuration. [Filter and output of Logstash · GitHub](https://gist.github.com/DenisBik/4eb642e51b919d86661412c75a5d5998)

Maybe you have some suggestions or links where I can get some information, because it's a little bit hard for me to obtain information for this join field topic...

I will be thankful for any help and tips!
