# Mapping ids to labels with a scripted field

**URL:** <https://discuss.elastic.co/t/mapping-ids-to-labels-with-a-scripted-field/221841>\
**Category:** Kibana\
**Created:** [March 3, 2020, 9:16am UTC](https://discuss.elastic.co/t/mapping-ids-to-labels-with-a-scripted-field/221841 "2020-03-03T09:16:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![IvanHerreros](https://avatars.discourse-cdn.com/v4/letter/i/35a633/32.png) [@IvanHerreros](https://discuss.elastic.co/u/IvanHerreros)\
**Post date:** [March 3, 2020, 9:16am UTC](https://discuss.elastic.co/t/mapping-ids-to-labels-with-a-scripted-field/221841/1 "2020-03-03T09:16:08Z")

</div>

Hi, I am using ES to archive data originally stored in a relational DB, and then provide a Kibana Dashboard. I store "denormalized" data (that is, performing joins at upload time), which of course comes with some caveats.

One of them: for visualization and filtering purposes, data should be aggregated based on ids, but displayed based on labels. This mapping from ids to labels may change with time, and I would always want to use the current map.

In order to avoid having to update previously stored denormalized data (which in my opinion is an awful scenario), I am thinking of controlling the mapping with a scripted field like the one below:

```
def l = new ArrayList();
Map map = [
'id1':'label1', 
'id2':'label2'
];

def k = doc['myfield.keyword'].value;

if (!map.containsKey(k)) {
    return 'no_label';
} else {
    return map[k];
}

```

I can produced and update the scripted dynamically with the saved\_objects Kibana API.

However, this solution looks like a weak or problematic workaround to me. I suppose that, if at all, I could use an approach like this, with some safety, given that the map is small and very stable: on the order of hundred(s) entries and maybe changed one or twice a month)

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [March 3, 2020, 12:16pm UTC](https://discuss.elastic.co/t/mapping-ids-to-labels-with-a-scripted-field/221841/2 "2020-03-03T12:16:47Z")

</div>

You can do the same thing with the static field formatters as part of the index pattern in Kibana.

Just use the "Static Lookup" formatter and you can enter your mapping there:

 ![Screenshot 2020-03-03 at 13.15.37](https://us1.discourse-cdn.com/elastic/original/3X/8/3/83724cc140d4f86423d1cd61414cf46418c52ca8.png)

As a bonus, those won't be sent to Elasticsearch, but applied directly at the visualization level which improves performance.

---

<div class="post-metadata">

**Author:** ![IvanHerreros](https://avatars.discourse-cdn.com/v4/letter/i/35a633/32.png) [@IvanHerreros](https://discuss.elastic.co/u/IvanHerreros)\
**Post date:** [March 3, 2020, 4:10pm UTC](https://discuss.elastic.co/t/mapping-ids-to-labels-with-a-scripted-field/221841/3 "2020-03-03T16:10:05Z")

</div>

Thanks Joe, this is interesting.

I saw that the "static\_lookup" is easy to update programatically.

Would it be a problem to (ab)use this look-up functionality by adding, say, 4574 key-value pairs?

And where is the mapping actually taking place? In the Kibana server?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [March 4, 2020, 9:52am UTC](https://discuss.elastic.co/t/mapping-ids-to-labels-with-a-scripted-field/221841/4 "2020-03-04T09:52:20Z")

</div>

The mapping is taking place in the browser client and are saved in the index pattern. So when Kibana is showing a visualization, it will download the index pattern saved object containing the whole mapping and apply it before displaying.

Performance-wise I think ~5k pairs are still manageable, you probably have to increase the `server.maxPayloadBytes` setting in `kibana.yml` to be able to save the index pattern. If this number grows to 100k, we should think about a solution within Elasticsearch

---

<div class="post-metadata">

**Author:** ![IvanHerreros](https://avatars.discourse-cdn.com/v4/letter/i/35a633/32.png) [@IvanHerreros](https://discuss.elastic.co/u/IvanHerreros)\
**Post date:** [March 4, 2020, 1:14pm UTC](https://discuss.elastic.co/t/mapping-ids-to-labels-with-a-scripted-field/221841/5 "2020-03-04T13:14:21Z")

</div>

Thanks again for your clarifying answer.

Just for my understanding:

- the solution with the scripted field dynamically updated with, say, with a scheduler, will perform the mapping within the ES server, right? With this approach would you see still a problem working with 5k value pairs? or 50k value pairs? I feels a bit hacky to me: that will be a very long script...

- In your answer, when you refer to 100k, is it key-value pairs or `server.maxPayloadBytes`?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [March 4, 2020, 1:23pm UTC](https://discuss.elastic.co/t/mapping-ids-to-labels-with-a-scripted-field/221841/6 "2020-03-04T13:23:30Z")

</div>

> the solution with the scripted field dynamically updated with, say, with a scheduler, will perform the mapping within the ES server, right? With this approach would you see still a problem working with 5k value pairs? or 50k value pairs? I feels a bit hacky to me: that will be a very long script...

I wouldn't recommend the script approach because the script is not persisted within Elasticsearch, but sent to the server with each individual request made from Kibana. For a lot of key-value pairs this would impact performance a lot because it has to upload possibly megabytes of key-value pairs for each request each visualization is issuing. Field formatters seem like the best option for your use case.

> - In your answer, when you refer to 100k, is it key-value pairs or `server.maxPayloadBytes` ?

That was referring to key-value pairs

For best performance I would recommend putting the value into the documents within Elasticsearch via the "update\_by\_query" API: [Update By Query API | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-update-by-query.html)

Then Kibana doesn't have to know about the lookup and can just use the nice format. But of course that approach comes with its own downsides.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2020, 1:23pm UTC](https://discuss.elastic.co/t/mapping-ids-to-labels-with-a-scripted-field/221841/7 "2020-04-01T13:23:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
