# Value Mapping in Kibana

**URL:** <https://discuss.elastic.co/t/value-mapping-in-kibana/311902>\
**Category:** Kibana\
**Created:** [August 11, 2022, 7:16am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902 "2022-08-11T07:16:39Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 11, 2022, 7:16am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/1 "2022-08-11T07:16:39Z")

</div>

Hi,

I'm setting up a dashboard and receiving data from prometheus through metricbeat, I'm facing problem when it comes to value mapping, in my case for "DoorStatus" i want to map the default integer values in 0 and 1 to display as 0=Unlocked, 1=Locked, similarly for "LockStatus" and for "BranchStatus" I need it as UP/DOWN, but I dont see any value in that field just a "-".  
So is there any way we could map the values?  
Screenshot is attached for reference.

Thanks in advance

 ![Screenshot (7)](https://us1.discourse-cdn.com/elastic/original/3X/1/9/194076a2b70e3f2ec090a243b8cc64a245ab9042.png)

---

<div class="post-metadata">

**Author:** ![JLeysens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jleysens/32/67404_2.png) [@JLeysens](https://discuss.elastic.co/u/JLeysens)\
**Post date:** [August 11, 2022, 10:52am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/2 "2022-08-11T10:52:19Z")

</div>

hello @saif.khan ! You should be able to do something like this using painless in your query or creating a [runtime field](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime.html) depending on how you are query for this data.

---

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 12, 2022, 10:43am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/3 "2022-08-12T10:43:17Z")

</div>

Thanks, Will give it a try!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 12, 2022, 9:00pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/4 "2022-08-12T21:00:17Z")

</div>

Just answered a similar question here with an example

> [@To convert the Integers into a String](https://discuss.elastic.co/t/to-convert-the-integers-into-a-string/311936/2):
>
> Hi @Maruthappan_Muthu What version are you on? There are a number of ways to do this but if you just want to see this in Kibana Visualizations and dashboards the easiest way is to add a runtime field to the the Index Pattern / Data View (you could add it to the actual mapping at some point if you want) Read on [runtime fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime.html) Go To Stack Management -\> Index / Pattern or Data View depending on the version Add Field Here is the sample code...replace with your field names etc... def status = …

---

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 15, 2022, 6:34am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/5 "2022-08-15T06:34:32Z")

</div>

@stephenb Thank you, Will give it a try.

---

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 15, 2022, 10:58am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/6 "2022-08-15T10:58:58Z")

</div>

@stephenb So I tried the script but it's giving me error " No field found for [cpiPduDoorStatus] in mapping"

My DataStream is "metricbeat-8.3.2\*"

Script used:

```auto
def status = doc['cpiPduDoorStatus'].value;
if (status != null ) {
    if (status == 1 ) {
        emit ("open");
        return;
    }
    else {
        emit ("closed");
        return;
    }
}
emit("Unknown");

```

Please rectify the error for me.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 15, 2022, 1:30pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/7 "2022-08-15T13:30:52Z")

</div>

Did you check the field exists in the mapping Data View?

Check the Data View

Or is it

`cpiPduDoorStatus.keyword`

---

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 15, 2022, 1:59pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/8 "2022-08-15T13:59:14Z")

</div>

Thanks for your response,  
Earlier i was getting `cpiPduDoorStatus` & `cpiPduDoorStatus.keyword`, along with the error "Limit of total fields [1000] has been exceeded" in logs which was fixed by increasing limit to 2000,

For your other question yes the field exists, maybe not in all Document ID's but in most of them,  
Attaching a whole screen screenshot for better understanding,  
On the left side you can see my discover search results, Add field script in the middle and the data preview on the right.

1- With one of the Document ID's containing the field

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bbd435fdbbb0336b43c7ba47fe6f62275b7074a5.png)

2- With Document ID not containing the field

 ![Screenshot (8)](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b1f324ce8ed92cbc20ccde86bd396225450cab74.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 15, 2022, 3:23pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/9 "2022-08-15T15:23:21Z")

</div>

What version stack are you on?

Did you trying saving it and see if it works anyway ... there were some early bugs in that window?

It is complaining that the mapping is not present (they are cached sometimes) especially if you have a really large number of fields

---

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 16, 2022, 6:26am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/10 "2022-08-16T06:26:45Z")

</div>

I'm on v8.3.2, I tried to save it but it didnt let me, kept highlighting the error. About the large number of fields, I have 128 fields only.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 16, 2022, 1:16pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/11 "2022-08-16T13:16:28Z")

</div>

Show me the mappings for that field

---

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 16, 2022, 1:36pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/12 "2022-08-16T13:36:40Z")

</div>

Sure, here it is

```auto
"cpiPduDoorStatus": {
        "properties": {
          "1": {
            "properties": {
              "12": {
                "properties": {
                  "48": {
                    "properties": {
                      "48": {
                        "properties": {
                          "48": {
                            "properties": {
                              "69": {
                                "properties": {
                                  "68": {
                                    "properties": {
                                      "51": {
                                        "properties": {
                                          "48": {
                                            "properties": {
                                              "48": {
                                                "properties": {
                                                  "70": {
                                                    "properties": {
                                                      "57": {
                                                        "properties": {
                                                          "57": {
                                                            "properties": {
                                                              "69": {
                                                                "type": "long"
                                                              }
                                                            }
                                                          }
                                                        }
                                                      }
                                                    }
                                                  }
                                                }
                                              }
                                            }
                                          }
                                        }
                                      }
                                    }
                                  }
                                }
                              }
                            }
                          }
                        }
                      }
                    }
                  }
                }
              }
            }
          },
          "2": {
            "properties": {
              "12": {
                "properties": {
                  "48": {
                    "properties": {
                      "48": {
                        "properties": {
                          "48": {
                            "properties": {
                              "69": {
                                "properties": {
                                  "68": {
                                    "properties": {
                                      "51": {
                                        "properties": {
                                          "48": {
                                            "properties": {
                                              "48": {
                                                "properties": {
                                                  "70": {
                                                    "properties": {
                                                      "57": {
                                                        "properties": {
                                                          "57": {
                                                            "properties": {
                                                              "69": {
                                                                "type": "long"
                                                              }
                                                            }
                                                          }
                                                        }
                                                      }
                                                    }
                                                  }
                                                }
                                              }
                                            }
                                          }
                                        }
                                      }
                                    }
                                  }
                                }
                              }
                            }
                          }
                        }
                      }
                    }
                  }
                }
              }
            }
          }
        }
      },

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 16, 2022, 1:45pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/13 "2022-08-16T13:45:43Z")

</div>

I'm not sure if that's intentional or not, but `cpiPduDoorStatus` that is an object not an actual concrete field so that is why it does not work.

The actual field is which is a `long` Is that last `69` for example

`cpiPduDoorStatus.1.12..........69`

All the way to the last number

---

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 16, 2022, 2:25pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/14 "2022-08-16T14:25:33Z")

</div>

I got your point, it's totally unintentional actually I'm collecting data from network devices through SNMP using `Logstash Snmp input plugin`, Just for your reference I'm attaching my logstash-snmp.conf, Honestly it's nothing complex so i dont think the cause for this issue would be here, but I'm sure you can help. 😁

```auto
input {
  snmp {
    walk => ["1.3.6.1.4.1.30932.1.10.1.2.10","1.3.6.1.4.1.30932.1.10.1.3.110","1.3.6.1.4.1.30932.1.10.1.7.100"]
    get => ["1.3.6.1.4.1.30932.1.1.3.8.1","1.3.6.1.4.1.30932.1.1.3.9.1"]
    hosts => [{host => "udp:device1-IP/161" community => "public" version => "2c"},{host => "udp:device2-IP/161" community => "public" version => "2c"},{host => "udp:device3-IP/161" community => "public" version => "2c"}]
    mib_paths => "/etc/logstash/mibs/CPI-PDU-MIB.dic"
    #oid_root_skip => 13
    oid_path_length => 15
    interval => 30
  }
}
filter {
    mutate {
        rename => {"iso.org.dod.internet.private.enterprises.cpi.products.unity.econnect.branch.cpiPduBranchTable" => "C"}
        rename => {"iso.org.dod.internet.private.enterprises.cpi.products.unity.econnect.systeminfo.cpiPduTable" => "9"}
        rename => {"iso.org.dod.internet.private.enterprises.cpi.products.unity.econnect.easData.cpiEasTable" => "-"}
        rename => {"iso.org.dod.internet.private.enterprises.cpi.products.legacy.metrics.humidity.humidityProbe1" => "Humidity_Probe1"}
        rename => {"iso.org.dod.internet.private.enterprises.cpi.products.legacy.metrics.temperature.temperatureProbe1" => "Temperature_Probe1"}
    }
}
output {
    stdout
    {
        codec => rubydebug
    }
     elasticsearch {
        action => "index"
        hosts => ["https://esIP:9200"]
        cacert => "/etc/logstash/certs/http_ca.crt"
        index => "snmp"
     user => "xxxxxx"
     password => "xxxxxxxxx"
    }
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 16, 2022, 3:35pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/15 "2022-08-16T15:35:13Z")

</div>

> [@stephenb](#):
>
> cpiPduDoorStatus.1.12..........69

1st I know nothing about SNMP and the logstash plugin etc.. apologies looks like you know more about it thatn me 🙂

2nd You don't actually need to "Fix" anything .. you just need to reference the correct concrete field and it should work.

So in the code.

```auto
def status = doc['ccpiPduDoorStatus.1.12.the.correct.numbers.etc......69'].value;
if (status != null ) {
    if (status == 1 ) {
        emit ("open");
        return;
    }
    else {
        emit ("closed");
        return;
    }
}
emit("Unknown");

```

the `.` in json indicate a sub-object / field .. that is all that is happening.

---

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 17, 2022, 6:48am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/16 "2022-08-17T06:48:54Z")

</div>

Thanks alot for your support,  
I understood your point now, Basically this is another refinement issue I'm trying to fix.  
The correct numbers you are referring here are actually the OID's for the pdu fields,  
So I have tried using `oid_root_skip` and `oid_path_length` function to shorten the extra parameters.

The typical raw output I was receiving was something like `iso.org.dod.internet.private.enterprises.cpi.products.unity.econnect.easData.cpiEasTable.cpiPduDoorStatus= (value- 0/1). 1.12...........69` ,  
Where the required field is only `cpiPduDoorStatus= Value`,  
unfortunately I'm only able to reduce it to `cpiPduDoorStatus= (value- 0/1). 1.12...........69` using `oid_path_length` hence the issue you rectified above.  
Just to mention the issue is only when I'm using WALK, its basically giving the whole path length of the parent tree, sub tree etc.  
While using GET I can perfectly rename it, but again not the most efficient way.

Hopefully you or someone else from the team will be able to help me with this, I could open a new topic for this but I feel with the above discussion it gives a better idea of the issue and how it is affecting while in use, rather than me trying to explain it in words.

Once again Thank you for your support.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 17, 2022, 6:16pm UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/17 "2022-08-17T18:16:14Z")

</div>

Hi @saif.khan I am not sure what your question is / what you are asking.

and Again I know just enough about SNMP to be dangerous 🙂

The long `.` name is fine and perfectly acceptable if it works for you

If you want a "Shorter / Easier" Name I can think of some possible approaches

Options...

Simple:  
Use a simple field alias to point to the long name See [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/field-alias.html)

Harder:  
Fix / change the field names prior to ingest e.g. substitute example `.` with `_` or something, that would require some coding in logstash

I am not sure what issue you are really trying to solve at this point.

---

<div class="post-metadata">

**Author:** ![saif.khan](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Post date:** [August 18, 2022, 6:52am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/18 "2022-08-18T06:52:42Z")

</div>

Right, I ll look into it.

No issues actually just refinements.  
Thanks for the support

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2022, 6:52am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902/19 "2022-09-15T06:52:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
