# Post processing of aggregation data

**URL:** <https://discuss.elastic.co/t/post-processing-of-aggregation-data/24651>\
**Category:** Kibana\
**Created:** [June 30, 2015, 5:39pm UTC](https://discuss.elastic.co/t/post-processing-of-aggregation-data/24651 "2015-06-30T17:39:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cbax007](https://avatars.discourse-cdn.com/v4/letter/c/3be4f8/32.png) [@cbax007](https://discuss.elastic.co/u/cbax007)\
**Post date:** [June 30, 2015, 5:39pm UTC](https://discuss.elastic.co/t/post-processing-of-aggregation-data/24651/1 "2015-06-30T17:39:47Z")

</div>

I posted a feature request for Kibana around getting label data for numerical ids that are stored in elasticsearch before displaying that data in a visualization:

> <https://github.com/elastic/kibana/issues/4357>

We don't want to denormalize our event data to contain all of the other relevant info besides the ids so I'm looking for an alternative solution. They suggested that I post here as well. Anyone out there have a good solution for storing ids in elasticsearch but then being able to associate those ids with their labels (from another data store but can be made available via a rest endpoint or by syncing them into elasticsearch) for presentation purposes?

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [July 1, 2015, 4:24am UTC](https://discuss.elastic.co/t/post-processing-of-aggregation-data/24651/2 "2015-07-01T04:24:31Z")

</div>

If the mapping is sufficiently static, you can consider doing it at index time and just storing the descriptive label as a separate field in the same document (for instance using the [Logstash translate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html)).

---

<div class="post-metadata">

**Author:** ![cbax007](https://avatars.discourse-cdn.com/v4/letter/c/3be4f8/32.png) [@cbax007](https://discuss.elastic.co/u/cbax007)\
**Post date:** [July 1, 2015, 11:53am UTC](https://discuss.elastic.co/t/post-processing-of-aggregation-data/24651/3 "2015-07-01T11:53:18Z")

</div>

That's not a bad idea Tanya. Unfortunately, the labels can and will change, so having stale data in the index is not desirable. That's one of the main reasons why we don't want to de-normalize the data stored in the index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:17pm UTC](https://discuss.elastic.co/t/post-processing-of-aggregation-data/24651/4 "2017-07-06T14:17:14Z")

</div>


