# Visualisations - change values

**URL:** <https://discuss.elastic.co/t/visualisations-change-values/150539>\
**Category:** Kibana\
**Created:** [October 1, 2018, 9:24am UTC](https://discuss.elastic.co/t/visualisations-change-values/150539 "2018-10-01T09:24:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daz762](https://avatars.discourse-cdn.com/v4/letter/d/f4b2a3/32.png) [@Daz762](https://discuss.elastic.co/u/Daz762)\
**Post date:** [October 1, 2018, 9:24am UTC](https://discuss.elastic.co/t/visualisations-change-values/150539/1 "2018-10-01T09:24:38Z")

</div>

Hi,

We currently use OSQuery to gather data about our laptops. The logs from these queries are shipped to Elasticsearch service in AWS using Filebeat and then visualisations are created in Kibana.

My question is, is it possible to update the values in a visualisation to have more readable and friendly names? for example, if the logs show the following:

osquery.result.column.model: MacBook Pro 11,3

Is it possible to update the MacBook Pro 11,3 to a different value in the visualisation within kibana or do you need to use Logstash before the logs hit Elastic to convert the value?

I found the following thread that suggests the above functionality was on the roadmap but i can't find any docs on how to perform these actions if they are now available features in Kibana.

[Rename a field value in Kibana](https://discuss.elastic.co/t/rename-a-field-value-in-kibana/35505) **strong text**

Thanks,  
Daz

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [October 1, 2018, 5:34pm UTC](https://discuss.elastic.co/t/visualisations-change-values/150539/2 "2018-10-01T17:34:24Z")

</div>

Hey @Daz762, the most performant way is going to be using something like Logstash before you ingest your data into Elasticsearch. Depending on the size/structure of your data, and the type of formatting that you'd like to accomplish, you could potentially use [Scripted Fields](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html) as well; however, this will be done at query-time so it can have a performance impact.

---

<div class="post-metadata">

**Author:** ![Daz762](https://avatars.discourse-cdn.com/v4/letter/d/f4b2a3/32.png) [@Daz762](https://discuss.elastic.co/u/Daz762)\
**Post date:** [October 2, 2018, 8:56am UTC](https://discuss.elastic.co/t/visualisations-change-values/150539/3 "2018-10-02T08:56:15Z")

</div>

Thanks for your reply Brandon. It looks like adding Logstash to our configuration is the best option.

Thanks again,  
Daz

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 30, 2018, 8:56am UTC](https://discuss.elastic.co/t/visualisations-change-values/150539/4 "2018-10-30T08:56:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
