# Replace legend values in Kibana visualizations using Elasticsearch

**URL:** <https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862>\
**Category:** Kibana\
**Created:** [November 6, 2019, 9:09pm UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862 "2019-11-06T21:09:58Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [November 6, 2019, 9:09pm UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/1 "2019-11-06T21:09:58Z")

</div>

How can I replace the ID values at the bottom of this graph with something like A, B, C using Elasticsearch or Kibana UI tool?

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/9/39f785fe8317bb03919538b614f2fb9365c6c3ec.png)

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [November 8, 2019, 4:45am UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/2 "2019-11-08T04:45:28Z")

</div>

Bump

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [November 11, 2019, 3:07pm UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/3 "2019-11-11T15:07:50Z")

</div>

Hello,

Can you please tell me which graph is this? You can map the fields values to something else using kibana field formatters. But I am not sure if that is the optimum solution in this case.

cc @markov00

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [November 12, 2019, 6:39am UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/4 "2019-11-12T06:39:56Z")

</div>

I appreciate your feedback. The name of the graph is a line graph, but I changed the setting to be a bar graph instead. I can also switch it to TVSB, Timelion as well. If you know a solution that is associated with those graphs, I'm fine as well.

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [November 12, 2019, 1:04pm UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/5 "2019-11-12T13:04:21Z")

</div>

Hi @EZprogramming  
There are few ways to handle this:

- you can create a scripted fields through Kibana Advanced Settings -\> Index Patterns -\> Scripted Fields with a [Painless](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/modules-scripting-painless.html) script similar to:

```auto
if (doc['YOUR_ID_FIELD'].value == 'id12345') {
  return 'A'
} else {
  return 'B'
}

```

- or you can add this field directly during the indexing/ingestion or reindexing your data: [https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html)

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [November 12, 2019, 11:31pm UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/6 "2019-11-12T23:31:34Z")

</div>

Thank you! This worked.

Also, to anyone using the solution, you might have to use the \<field\_name\>.keyword instead of just the \<field\_name\> to get the result that you want.

Edit:  
Checking if the field exists is also helpful to avoid searching for fields that don't exist in your documents in your index pattern. Returning null will return '-' in Kibana discover page and void shard failure.

**Better solution:** ✅

```
if (!doc['YOUR_ID_FIELD.keyword'].empty){
	if (doc['YOUR_ID_FIELD'].value == 'id12345') {
	  return 'A'
	} else {
	  return 'B'
	}
} else {
    return null;
}
```

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [November 14, 2019, 5:45pm UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/7 "2019-11-14T17:45:12Z")

</div>

@markov00, I tried to filter scripted fields but it didn't work. Do you know if this feature is possible?

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [November 14, 2019, 6:24pm UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/8 "2019-11-14T18:24:52Z")

</div>

> [@EZprogramming](#):
>
> filter scripted fields

yes that should work, but maybe depends on the version you are working on

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [November 14, 2019, 11:14pm UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/9 "2019-11-14T23:14:24Z")

</div>

I am using Elasticsearch version **7.3.2** , and I just did it and I got shard failure and this error message. I can only share part of the information:

**Error Output:**

_2 out of 4 shards failed_

`[esaggs] > Request to Elasticsearch failed: {"error":{"root_cause":[{"type":"script_exception","reason":"compile error","script_stack":["... rn s.get() == v;}compare(() -> { if (doc['id ..."," ^---- HERE"],"script":"boolean compare(Supplier s, def v) {return s.get() == v;}compare(() -> { if (doc['customer_id.keyword'].value == '***') {\n return '***'\n} else if(doc['id.keyword'].value == '***') {\n return '***'\n} else if(doc['id.keyword'].value == '***') {\n return '***'\n} else if(doc['id.keyword'].value == '***') {\n return '***'\n} }, params.value);","lang":"painless"},{"type":"script_exception","reason":"compile error","script_stack":["... rn s.get() == v;}compare(() -> { if (doc['id ..."," ^---- HERE"],"script":"boolean compare(Supplier s, def v) {return s.get() == v;}`

**Edit:**

I have named the scripted field as id, and not id.keyword. I've realized \<field\_name\>.keyword is usually how things are filtered out in Kibana, but not sure if this is the issue.

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [November 15, 2019, 9:34am UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/10 "2019-11-15T09:34:14Z")

</div>

Hi, I don't think this is the issue. Could you please check if the error, near the end of the message, report something like:

```auto
"caused_by":{"type":"illegal_argument_exception","reason":"Not all paths provide a return value for method [lambda$0]."}}},"status":400}

```

Because seems that your script doesn't have return values if not one of the value checked:

```auto
if (doc['customer_id.keyword'].value == '***') {
   return '***'
} else if(doc['id.keyword'].value == '***') {
   return '***'
} else if(doc['id.keyword'].value == '***') {
   return '***'
} else if(doc['id.keyword'].value == '***') {
   return '***'
}

```

adding a final `return 'other'` or something similar should fix the issue

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [November 24, 2019, 9:23am UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/11 "2019-11-24T09:23:28Z")

</div>

You are right, I forgot the else clause which returns null. I added it for some indexes but forgot to add it to this one. By adding the else clause to return null, I fixed the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2019, 9:23am UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862/12 "2019-12-22T09:23:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
