# Visualisation with \* index

**URL:** <https://discuss.elastic.co/t/visualisation-with-index/111042>\
**Category:** Kibana\
**Created:** [December 11, 2017, 9:07am UTC](https://discuss.elastic.co/t/visualisation-with-index/111042 "2017-12-11T09:07:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kumpelblase](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kumpelblase/32/35709_2.png) [@kumpelblase](https://discuss.elastic.co/u/kumpelblase)\
**Post date:** [December 11, 2017, 9:07am UTC](https://discuss.elastic.co/t/visualisation-with-index/111042/1 "2017-12-11T09:07:51Z")

</div>

I have 2 indices, one with customer numbers and the other with errortypes. I made an index with \* to get exerithing into one index, now is it possible to compare these two values, for example in a Vertical Bar chart or a Heatmap? I tried both, but it only said 'No results found'.

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [December 11, 2017, 6:23pm UTC](https://discuss.elastic.co/t/visualisation-with-index/111042/2 "2017-12-11T18:23:50Z")

</div>

You can compare fields from two different indexes like this, but you need some way to connect the two values. What is your desired x-axis and y-axis fields? time and count?

---

<div class="post-metadata">

**Author:** ![kumpelblase](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kumpelblase/32/35709_2.png) [@kumpelblase](https://discuss.elastic.co/u/kumpelblase)\
**Post date:** [December 12, 2017, 7:15am UTC](https://discuss.elastic.co/t/visualisation-with-index/111042/3 "2017-12-12T07:15:32Z")

</div>

Here are the mappings for the two indices I'd like to compare.

> {  
> "mappings" : {  
> "ticket" : {  
> "properties" : {  
> "TTS\_Nummer" : {  
> "type" : "integer"  
> },  
> "TTS\_Art" : {  
> "type" : "short"  
> },  
> "TTS\_Schweregrad" : {  
> "type" : "short"  
> },  
> "TTS\_Prioritaet" : {  
> "type" : "short"  
> },  
> "TTS\_Status" : {  
> "type" : "short"  
> },  
> .  
> .  
> .  
> }  
> }  
> }  
> }

Note: The mapping for the type "ticket" is much longer, in total it has 27 fields. One of them is also a timestamp.

> {  
> "mappings" : {  
> "ticket\_customer" : {  
> "properties" : {  
> "TKK\_KundenNr" : {  
> "type" : "integer"  
> },  
> "TKK\_TicketNr" : {  
> "type" : "integer"  
> },  
> "TKK\_Custom" : {  
> "type" : "text"  
> }  
> }  
> }  
> }  
> }

They are linked via the fields TTS\_Nummer and TKK\_TicketNr, it's like private and foreign key from a database. (That's where they're originaly from).

I created a bar chart which counts the ammount of tickets for a customer:

 ![Screenshot-2017-12-12 Kunden - Kibana](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c5794c3e6cf48a4b2a44bfb8b1cb0ec43433580.png)  
Now I want to separate the bars with the field ` TTS_Art`, so I can see which customer has how many Tickets of which kind.

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [December 12, 2017, 4:48pm UTC](https://discuss.elastic.co/t/visualisation-with-index/111042/4 "2017-12-12T16:48:24Z")

</div>

Actually, I apologize but I don't believe this is possible due to the lack of support of joins in kibana and elasticsearch. I thought it was possible originally, but further investigation and I can't get it to work.

Can you combine the two indexes so a single document contains both customer number and error type?

---

<div class="post-metadata">

**Author:** ![kumpelblase](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kumpelblase/32/35709_2.png) [@kumpelblase](https://discuss.elastic.co/u/kumpelblase)\
**Post date:** [December 13, 2017, 8:25am UTC](https://discuss.elastic.co/t/visualisation-with-index/111042/5 "2017-12-13T08:25:34Z")

</div>

No problem, I also thought that it isn't possible.

> Can you combine the two indexes so a single document contains both customer number and error type?

Do I need to fully reindex the data if I want to combine the indices or can I just combine them in the Kibana console?

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [December 13, 2017, 6:40pm UTC](https://discuss.elastic.co/t/visualisation-with-index/111042/6 "2017-12-13T18:40:50Z")

</div>

I think you'll need to reindex, but you should be able to initiate the command from the Kibana console. [https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html) . Some of those examples have `View in console` links.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2018, 6:41pm UTC](https://discuss.elastic.co/t/visualisation-with-index/111042/7 "2018-01-10T18:41:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
