# How to transform values of field?

**URL:** <https://discuss.elastic.co/t/how-to-transform-values-of-field/63483>\
**Category:** Kibana\
**Created:** [October 20, 2016, 8:25am UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483 "2016-10-20T08:25:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![gandhi](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@gandhi](https://discuss.elastic.co/u/gandhi)\
**Post date:** [October 20, 2016, 8:25am UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483/1 "2016-10-20T08:25:28Z")

</div>

Hello, guys!  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/3/3ed7dd0493965bc58434f8832d702e2ecb0227d9.jpg)

'doctype' field's type is String. I'd like to transform this field values like '0.0' to 'content', '1.0' to 'reply'. I checked 'Setting \> Indices' controls button.

![](https://us1.discourse-cdn.com/elastic/original/2X/e/e4953098f35c7d0a82311ba31033222b0acec55f.png)

There is no option to work for me.  
Somebody knows answer. plz reply me!  
Thanks!

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [October 20, 2016, 3:24pm UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483/2 "2016-10-20T15:24:24Z")

</div>

For something like that, you'll need to make a scripted field instead of using formatters. What version of Kibana/Elasticsearch are you using?

---

<div class="post-metadata">

**Author:** ![gandhi](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@gandhi](https://discuss.elastic.co/u/gandhi)\
**Post date:** [October 21, 2016, 12:08am UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483/3 "2016-10-21T00:08:15Z")

</div>

HI, lukas. thanks for your reply.  
I am using 4.5.1 Kibana.  
Would you show how to make a scripted field for this situation?  
I'm beginner. I don't know typing a right code about scripted field.

- I saw other issue related this. Kibana 4.5.1 isn't work for String type. so should I change the type of 'doctype' field to Number for solving this issue?

---

<div class="post-metadata">

**Author:** ![txisme](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@txisme](https://discuss.elastic.co/u/txisme)\
**Post date:** [October 21, 2016, 10:06am UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483/4 "2016-10-21T10:06:00Z")

</div>

How are you sending data to ElasticSearch?

---

<div class="post-metadata">

**Author:** ![gandhi](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@gandhi](https://discuss.elastic.co/u/gandhi)\
**Post date:** [October 24, 2016, 12:04am UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483/5 "2016-10-24T00:04:54Z")

</div>

I do sending data by Elasticsearch's Mapping rule. Mapping is okay.  
I'm not sure if I understand what you say.

---

<div class="post-metadata">

**Author:** ![txisme](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@txisme](https://discuss.elastic.co/u/txisme)\
**Post date:** [October 24, 2016, 9:02am UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483/6 "2016-10-24T09:02:10Z")

</div>

if you process your data with Logstash before sending to ElasticSearch, you can do a conditional statement for what you want.

---

<div class="post-metadata">

**Author:** ![gandhi](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@gandhi](https://discuss.elastic.co/u/gandhi)\
**Post date:** [October 24, 2016, 9:14am UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483/7 "2016-10-24T09:14:22Z")

</div>

txisme, Would you show me some demo? I wanna detail for that.

---

<div class="post-metadata">

**Author:** ![txisme](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@txisme](https://discuss.elastic.co/u/txisme)\
**Post date:** [October 24, 2016, 9:24am UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483/8 "2016-10-24T09:24:19Z")

</div>

Logstash is a pipeline that processes your files and sends them to elastic search.  
[https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html](https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html)

For example, if you have a CSV file with that you want to send, you can parse it and send it with the map you want.  
Here is some example of code you can use:

```
if([column1] == "0.0){
     column1 => "content"
}
if([column1] == "1.0){
        column1 => "reply"
  }

```

I'm not sure you can change the value like that. But if not, you can perfectly add a new filed to the data with the string you want.

Check the reference guide for better understanding.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:35pm UTC](https://discuss.elastic.co/t/how-to-transform-values-of-field/63483/9 "2017-07-06T13:35:56Z")

</div>


