# Data tranformation

**URL:** <https://discuss.elastic.co/t/data-tranformation/28405>\
**Category:** Kibana\
**Created:** [September 1, 2015, 6:11am UTC](https://discuss.elastic.co/t/data-tranformation/28405 "2015-09-01T06:11:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mathiasa](https://avatars.discourse-cdn.com/v4/letter/m/74df32/32.png) [@mathiasa](https://discuss.elastic.co/u/mathiasa)\
**Post date:** [September 1, 2015, 6:11am UTC](https://discuss.elastic.co/t/data-tranformation/28405/1 "2015-09-01T06:11:11Z")

</div>

Hi,  
What is the best way of doing data transformations in the ELK flow.  
I want for example transform seconds into minutes. Is there a way of doing that kind of calculations in Kibana? Don't think logstash is the right place. Or should I run updated in ES directly?

What's your take on this?

Br  
Mathias

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 1, 2015, 6:15am UTC](https://discuss.elastic.co/t/data-tranformation/28405/2 "2015-09-01T06:15:18Z")

</div>

You could do that in LS, or you could do a scripted field in KB, it depends on your pipeline.

---

<div class="post-metadata">

**Author:** ![mathiasa](https://avatars.discourse-cdn.com/v4/letter/m/74df32/32.png) [@mathiasa](https://discuss.elastic.co/u/mathiasa)\
**Post date:** [September 1, 2015, 6:33am UTC](https://discuss.elastic.co/t/data-tranformation/28405/3 "2015-09-01T06:33:21Z")

</div>

Thanks for your input,  
I think doing tranformations in LS will make the config to to complex in the long run and also have to much of an performance hit. We have an index rate of 10.000 ind/s so i'm trying to keep LS as streamlined as possible.  
How does scripted fields in KB work?

Br  
Mathias

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [September 1, 2015, 6:46am UTC](https://discuss.elastic.co/t/data-tranformation/28405/4 "2015-09-01T06:46:27Z")

</div>

For transformation from seconds into minutes, scripted fields are indeed a good option. By default scripted fields use [Lucene expressions](http://lucene.apache.org/core/4_9_0/expressions/index.html?org/apache/lucene/expressions/js/package-summary.html) syntax, but that works really well for numerical transformations.

You can find more info on scripted fields in the Kibana interface itself:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/d0cba9cdf0060566c73c8bd12c0b6a5ea7177b44.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 1, 2015, 6:47am UTC](https://discuss.elastic.co/t/data-tranformation/28405/5 "2015-09-01T06:47:41Z")

</div>

There's also [https://www.elastic.co/guide/en/kibana/current/managing-fields.html#create-scripted-field](https://www.elastic.co/guide/en/kibana/current/managing-fields.html#create-scripted-field)

---

<div class="post-metadata">

**Author:** ![mathiasa](https://avatars.discourse-cdn.com/v4/letter/m/74df32/32.png) [@mathiasa](https://discuss.elastic.co/u/mathiasa)\
**Post date:** [September 1, 2015, 12:36pm UTC](https://discuss.elastic.co/t/data-tranformation/28405/6 "2015-09-01T12:36:33Z")

</div>

Thanks, works like a charm... 😄

Thanks  
Mathias

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:13pm UTC](https://discuss.elastic.co/t/data-tranformation/28405/7 "2017-07-06T14:13:55Z")

</div>


