# Pipeline question

**URL:** <https://discuss.elastic.co/t/pipeline-question/286494>\
**Category:** Elasticsearch\
**Created:** [October 12, 2021, 12:49pm UTC](https://discuss.elastic.co/t/pipeline-question/286494 "2021-10-12T12:49:07Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Worlock](https://avatars.discourse-cdn.com/v4/letter/w/c77e96/32.png) [@Worlock](https://discuss.elastic.co/u/Worlock)\
**Post date:** [October 12, 2021, 12:49pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/1 "2021-10-12T12:49:07Z")

</div>

Hi all,

I have a field in my index that is named "Severity". The values can be either 2, 1 or 0. I want to rename those values to Critical, Warning or Informational.

I looked into pipelines and also read the documentation on that, but I don't really know what I should do or use. Any ideas on this?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 12, 2021, 1:33pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/2 "2021-10-12T13:33:49Z")

</div>

Welcome!

You need to reindex everything in a new index.  
How did you index your data the first time?

---

<div class="post-metadata">

**Author:** ![Worlock](https://avatars.discourse-cdn.com/v4/letter/w/c77e96/32.png) [@Worlock](https://discuss.elastic.co/u/Worlock)\
**Post date:** [October 12, 2021, 1:44pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/3 "2021-10-12T13:44:35Z")

</div>

Hi, thanks!

I am very very new to Elasticsearch, so I hope I explain myself right. I upload the data with a CSV file the first time, and now I also created a PowerShell script that uploads the same data. I previously made some pipelines to lowercase some fields and transform some date field, and I indeed reindexed after that.

The data is being indexed by a index template I made, and the Severity field is mapped as a keyword.

I hope I answered your question by this, otherwise please let me know.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 12, 2021, 1:57pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/4 "2021-10-12T13:57:10Z")

</div>

It would be easier if you can modify the CSV file or your PowerShell script.

But you can also add a script processor which transforms the values you have to a text. Have a look at [Script processor | Elasticsearch Guide [7.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/script-processor.html)

---

<div class="post-metadata">

**Author:** ![Worlock](https://avatars.discourse-cdn.com/v4/letter/w/c77e96/32.png) [@Worlock](https://discuss.elastic.co/u/Worlock)\
**Post date:** [October 12, 2021, 2:01pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/5 "2021-10-12T14:01:44Z")

</div>

Thanks, I did realise that I can adjust my script, and that's an option. But I am also trying to learn, so I am very curious to know how I could to this in Elasticsearch if I couldn't control the datasource, which I'm sure will be the case in the future with other data.

I looked at your link, and find it very hard to follow. But I will see if I can find some further information about that. Thanks so far.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 12, 2021, 3:20pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/6 "2021-10-12T15:20:50Z")

</div>

> [@Worlock](#):
>
> so I am very curious to know how I could to this in Elasticsearch if I couldn't control the datasource

Yes. You can create an ingest pipeline and make it the default pipeline for a given index.

> [@Worlock](#):
>
> I looked at your link, and find it very hard to follow.

Agreed. Writing a Script with painless is not as straightforward as the other processors. 🙂

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 12, 2021, 5:57pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/7 "2021-10-12T17:57:17Z")

</div>

Just a Drive By Thought.... 🙂

Or you can just add a runtime field and skip the whole reindex process.

> **[Runtime fields | Elasticsearch Guide \[7.15\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime.html)**

Just add a runtime field with an if / else block based on the code and emit the value you want 🙂

Your script would look something like (I did not check for syntax)

```auto
PUT my-index-000001/
{
  "mappings": {
    "runtime": {
      "serverity_code": {
        "type": "keyword",
        "script": {
          "source": "if (doc['severity'].value.equals('2') {emit('Critical');}
        else if (doc['severity'].value.equals('1') {emit('Warning');}
        else {emit('Informational');}"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 12, 2021, 7:26pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/8 "2021-10-12T19:26:41Z")

</div>

I just forgot about this very nice feature 😁

---

<div class="post-metadata">

**Author:** ![Worlock](https://avatars.discourse-cdn.com/v4/letter/w/c77e96/32.png) [@Worlock](https://discuss.elastic.co/u/Worlock)\
**Post date:** [October 13, 2021, 8:03am UTC](https://discuss.elastic.co/t/pipeline-question/286494/9 "2021-10-13T08:03:07Z")

</div>

Will this also work for a lence dashboard? For example a pie chart? Now I see 0/1/2 in the pie and I would like to have the names there.

---

<div class="post-metadata">

**Author:** ![Worlock](https://avatars.discourse-cdn.com/v4/letter/w/c77e96/32.png) [@Worlock](https://discuss.elastic.co/u/Worlock)\
**Post date:** [October 13, 2021, 8:25am UTC](https://discuss.elastic.co/t/pipeline-question/286494/10 "2021-10-13T08:25:26Z")

</div>

It gives me this error:

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "parse_exception",
        "reason" : "Failed to parse content to map"
      }
    ],
    "type" : "parse_exception",
    "reason" : "Failed to parse content to map",
    "caused_by" : {
      "type" : "json_parse_exception",
      "reason" : "Illegal unquoted character ((CTRL-CHAR, code 10)): has to be escaped using backslash to be included in string value\n at [Source: (ByteArrayInputStream); line: 7, column: 79]"
    }
  },
  "status" : 400
}

```

I tried to resolve it myself by searching this forum and Google, it seems that is has something to do with line breaks but so far I was not able to resolve it. I will continue trying, but if you have any idea in the meantime, please let me know!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 13, 2021, 10:47am UTC](https://discuss.elastic.co/t/pipeline-question/286494/11 "2021-10-13T10:47:12Z")

</div>

> [@Worlock](#):
>
> Will this also work for a lence dashboard? For example a pie chart? Now I see 0/1/2 in the pie and I would like to have the names there.

Yes.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 13, 2021, 10:48am UTC](https://discuss.elastic.co/t/pipeline-question/286494/12 "2021-10-13T10:48:07Z")

</div>

What exactly did you run?

---

<div class="post-metadata">

**Author:** ![Worlock](https://avatars.discourse-cdn.com/v4/letter/w/c77e96/32.png) [@Worlock](https://discuss.elastic.co/u/Worlock)\
**Post date:** [October 13, 2021, 12:35pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/13 "2021-10-13T12:35:39Z")

</div>

```auto
PUT alert_data/
{
  "mappings": {
    "runtime": {
      "severity_code": {
        "type": "keyword",
        "script": {
          "source": "if (doc['severity'].value.equals('2') {emit('Critical');
          }
          else if (doc['severity'].value.equals('1') {emit('Warning');
          }
          else {emit('Informational');
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 13, 2021, 1:00pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/14 "2021-10-13T13:00:10Z")

</div>

Try this:

```auto
DELETE alert_data
PUT alert_data/
{
  "mappings": {
    "properties": {
      "severity": {
        "type": "keyword"
      }
    }, 
    "runtime": {
      "severity_code": {
        "type": "keyword",
        "script": {
          "source": """if (doc['severity'].value.equals('2')) { emit('Critical'); }
          else if (doc['severity'].value.equals('1')) { emit('Warning'); }
          else { emit('Informational'); }"""
        }
      }
    }
  }
}
POST alert_data/_doc
{
  "severity": "2"
}
POST alert_data/_doc
{
  "severity": "2"
}
POST alert_data/_doc
{
  "severity": "1"
}
POST alert_data/_doc
{
  "severity": "0"
}
GET alert_data/_search
{
  "size": 0,
  "aggs": {
    "sev": {
      "terms": {
        "field": "severity_code"
      }
    }
  }
}

```

It gives:

```auto
{
  "took" : 7,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 4,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  },
  "aggregations" : {
    "sev" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "Critical",
          "doc_count" : 2
        },
        {
          "key" : "Informational",
          "doc_count" : 1
        },
        {
          "key" : "Warning",
          "doc_count" : 1
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2021, 1:00pm UTC](https://discuss.elastic.co/t/pipeline-question/286494/15 "2021-11-10T13:00:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
