# Static lookup

**URL:** <https://discuss.elastic.co/t/static-lookup/280182>\
**Category:** Kibana\
**Created:** [August 2, 2021, 4:09am UTC](https://discuss.elastic.co/t/static-lookup/280182 "2021-08-02T04:09:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![IsAa](https://avatars.discourse-cdn.com/v4/letter/i/6bbea6/32.png) [@IsAa](https://discuss.elastic.co/u/IsAa)\
**Post date:** [August 2, 2021, 4:09am UTC](https://discuss.elastic.co/t/static-lookup/280182/1 "2021-08-02T04:09:40Z")

</div>

Hi ELK Users,

I was working on static look up table on index pattern.

As you can observe that, I have two keys which I am mapping to the same value

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/e/3edd8db7f68076cf272571fbeb6c40813a7c3db7.png)

I can see in the Discover section, that these values are getting re-named

But when building visualization using term aggregation,

I see the two value fields in the visualization

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/0/00b72fe770b2581b4c3b3795b195aa1d78f7f5c9.png)

Is there a bug here, or my implementation for the static look-up table is not correct?

Basically, I was hoping that after using a new value for the key, they would have been aggregated together under the same term.

What would be a good approach to aggregate keys and their values together?

Kind regards.

---

<div class="post-metadata">

**Author:** ![Marta\_Bondyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_bondyra/32/102122_2.png) [@Marta\_Bondyra](https://discuss.elastic.co/u/Marta_Bondyra)\
**Post date:** [August 2, 2021, 7:01am UTC](https://discuss.elastic.co/t/static-lookup/280182/2 "2021-08-02T07:01:17Z")

</div>

Hi there, what version of Kibana are you on? Depends on that you could either use scripted fields or runtime fields.

For scripted fields, go to Stack management and Index Patterns and add a scripted field according to this scheme (replace `field_name` in this script):

```auto
if(doc['field_name'].size()== 0) return null;

if (doc['field_name'].value == 'Resolutions')
    return "Meetings";
return doc['field_name'].value;

```

Then use your scripted field in your visualization instead of your original field.

---

<div class="post-metadata">

**Author:** ![Marta\_Bondyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_bondyra/32/102122_2.png) [@Marta\_Bondyra](https://discuss.elastic.co/u/Marta_Bondyra)\
**Post date:** [August 2, 2021, 7:09am UTC](https://discuss.elastic.co/t/static-lookup/280182/3 "2021-08-02T07:09:46Z")

</div>

For kibana v7.11 or later, use runtime field instead.  
Steps to do it:

1. Open lens or discover.

2. In Lens, click on the button close to the index pattern switcher:  
 ![Screenshot 2021-08-02 at 09.08.03](https://us1.discourse-cdn.com/elastic/original/3X/d/e/de6e26ba17531da548f1e9dbb7c8a1463e789d5f.png)

3. Write your script (example with category.keyword):  

```auto
String m = doc["category.keyword"].value;
if (doc['category.keyword'].value == "Men's Clothing")
    m = "Women's Clothing";
emit(m)

```

And use it in your visualization, here I merged men's clothing with women's clothing.

---

<div class="post-metadata">

**Author:** ![IsAa](https://avatars.discourse-cdn.com/v4/letter/i/6bbea6/32.png) [@IsAa](https://discuss.elastic.co/u/IsAa)\
**Post date:** [August 2, 2021, 9:16pm UTC](https://discuss.elastic.co/t/static-lookup/280182/4 "2021-08-02T21:16:48Z")

</div>

Hi,

I am on elastic cloud instance, and the version is 7.12.1.

I tried giving lens a go. But I don't see this index pattern switcher either in lens or discover

But the scripting approach is working for me 😃

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7f838357b28877b2134c2dab4d75c867b21476d6.png)

Hmm !

Thanks

---

<div class="post-metadata">

**Author:** ![ghudgins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghudgins/32/138532_2.png) [@ghudgins](https://discuss.elastic.co/u/ghudgins)\
**Post date:** [August 3, 2021, 1:06pm UTC](https://discuss.elastic.co/t/static-lookup/280182/5 "2021-08-03T13:06:04Z")

</div>

Ah, the UI in lens/discover was added in 7.13.0

You can write scripted runtime fields from Stack Management in the Index Pattern any time after 7.11. Once you have your field, it'll show up as a normal field in your list in discover & lens

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2021, 1:06pm UTC](https://discuss.elastic.co/t/static-lookup/280182/6 "2021-08-31T13:06:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
