# Kibana Static Lookup

**URL:** <https://discuss.elastic.co/t/kibana-static-lookup/236309>\
**Category:** Kibana\
**Created:** [June 9, 2020, 10:05am UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309 "2020-06-09T10:05:58Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anton91](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Anton91](https://discuss.elastic.co/u/Anton91)\
**Post date:** [June 9, 2020, 10:05am UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/1 "2020-06-09T10:05:58Z")

</div>

Hello,

I am faced with the following problem:

I'm getting two fields A and B. For example, field A contains a 6 and field B should now contain Ethernet. Both fields are already stored in the index pattern and I have also created a static lookup in field B. Unfortunately I don't see anything in field B.

Can I create a connection between the two fields? Or is it only possible with a new scripted field?

Example:  
Field A Field B  
0 \> Other  
6 \> Ethernet  
23 \> VPN

I have also tried to create the lookup in field A only then I can't visualize the data.

I am grateful for any help.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 9, 2020, 10:53am UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/2 "2020-06-09T10:53:12Z")

</div>

Do you need both the number and the label in your visualization? If yes, a scripted field is indeed the way to go. If you always want to display the label and hide the number for the Kibana user, you should be able to apply the static lookup formatting to field A (no need for a field B at all in this case).

---

<div class="post-metadata">

**Author:** ![Anton91](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Anton91](https://discuss.elastic.co/u/Anton91)\
**Post date:** [June 9, 2020, 2:23pm UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/3 "2020-06-09T14:23:14Z")

</div>

Thank you very much for the answer.

I have now created it with the Scriptedfield, as I will probably need both values in the future.

I have created the following script:

```auto
if(doc['NetworkConfigInterfaceType'].size()== 0) return null;

if (doc['NetworkConfigInterfaceType'].value == 0)
    return "Other";
if (doc['NetworkConfigInterfaceType'].value == 6)
    return "Ethernet";
if (doc['NetworkConfigInterfaceType'].value == 23)
    return "VPN";
if (doc['NetworkConfigInterfaceType'].value == 63)
    return "ISDN";
if (doc['NetworkConfigInterfaceType'].value == 71)
    return "WiFi";
if (doc['NetworkConfigInterfaceType'].value == 243)
    return "WWAN";
return null;

```

Now I want to visualize it in Kibana and I get a message that no data is available.

 ![2020-06-09 16_15_18-](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8eaf4e3dcd32d4a99becc5a244fc21d4af3c6aa0.png)

If I select Show missing values below, I get exactly the values I need.  
How does this happen?

 ![2020-06-09 16_16_32-](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d76083d702e106e9d5e3b52e99202f5ab6ebe494.png)

Also in Discover the Scriptefield is displayed correctly.

 ![2020-06-09 16_19_55-Discover - Kibana](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0a340c441b351db9cc91e0189013b14f8f98337e.png)

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 12, 2020, 8:32am UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/4 "2020-06-12T08:32:30Z")

</div>

Could you try using `NetworkConfigInterfaceType.keyword` instead?

---

<div class="post-metadata">

**Author:** ![Anton91](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Anton91](https://discuss.elastic.co/u/Anton91)\
**Post date:** [June 12, 2020, 12:00pm UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/5 "2020-06-12T12:00:58Z")

</div>

> [@flash1293](#):
>
> .keyword

When I add the .keyword I get the following error message:

```auto
{
 "root_cause": [
  {
   "type": "script_exception",
   "reason": "runtime error",
   "script_stack": [
    "org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:94)",
    "org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:41)",
    "if(doc['NetworkConfigInterfaceType.keyword'].size()== 0) ",
    " ^---- HERE"
   ],
   "script": "if(doc['NetworkConfigInterfaceType.keyword'].size()== 0) return null;\r\n\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 0)\r\n return \"Other\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 6)\r\n return \"Ethernet\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 23)\r\n return \"VPN\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 63)\r\n return \"ISDN\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 71)\r\n return \"WiFi\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 243)\r\n return \"WWAN\";\r\n \r\nreturn null;\r\n",
   "lang": "painless"
  }
 ],
 "type": "search_phase_execution_exception",
 "reason": "all shards failed",
 "phase": "query",
 "grouped": true,
 "failed_shards": [
  {
   "shard": 0,
   "index": "test",
   "node": "52tn91DERquwvDXrqkww_w",
   "reason": {
    "type": "script_exception",
    "reason": "runtime error",
    "script_stack": [
     "org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:94)",
     "org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:41)",
     "if(doc['NetworkConfigInterfaceType.keyword'].size()== 0) ",
     " ^---- HERE"
    ],
    "script": "if(doc['NetworkConfigInterfaceType.keyword'].size()== 0) return null;\r\n\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 0)\r\n return \"Other\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 6)\r\n return \"Ethernet\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 23)\r\n return \"VPN\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 63)\r\n return \"ISDN\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 71)\r\n return \"WiFi\";\r\nif (doc['NetworkConfigInterfaceType.keyword'].value == 243)\r\n return \"WWAN\";\r\n \r\nreturn null;\r\n",
    "lang": "painless",
    "caused_by": {
     "type": "illegal_argument_exception",
     "reason": "No field found for [NetworkConfigInterfaceType.keyword] in mapping with types []"
    }
   }
  }
 ]
}

```

---

<div class="post-metadata">

**Author:** ![Anton91](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Anton91](https://discuss.elastic.co/u/Anton91)\
**Post date:** [June 15, 2020, 1:29pm UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/6 "2020-06-15T13:29:19Z")

</div>

Is there a way to add it to the Json input without a scripted field?

Does anyone else have any ideas?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [June 15, 2020, 1:33pm UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/7 "2020-06-15T13:33:23Z")

</div>

You can do this in Vega if you swap over your visualization to there. There you can use conditionals, lookup tables, etc.

But you would need to re-create your visualization there.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 16, 2020, 3:28pm UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/8 "2020-06-16T15:28:56Z")

</div>

I just tested this by creating a test index with a few documents and your scripted fields and doing a terms aggreagation works fine for me:

 ![Screenshot 2020-06-16 at 17.28.03](https://us1.discourse-cdn.com/elastic/original/3X/7/4/7453b08f602a9e52909554d4074f95f550881cf9.png) ![Screenshot 2020-06-16 at 17.28.12](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9edcb55180ff5c7940848c6264aac44c10dd4860.png)

Could you export and upload your index pattern saved object so I can replicate this issue?

---

<div class="post-metadata">

**Author:** ![Anton91](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Anton91](https://discuss.elastic.co/u/Anton91)\
**Post date:** [June 22, 2020, 11:57am UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/9 "2020-06-22T11:57:57Z")

</div>

I was able to fix the error and it was referenced to the wrong index pattern. Thanks for your support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2020, 11:58am UTC](https://discuss.elastic.co/t/kibana-static-lookup/236309/10 "2020-07-20T11:58:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
