# APM pipeline painless script vanishes after upgrade (runtime field instead?)

**URL:** <https://discuss.elastic.co/t/apm-pipeline-painless-script-vanishes-after-upgrade-runtime-field-instead/310115>\
**Category:** APM\
**Created:** [July 20, 2022, 8:52am UTC](https://discuss.elastic.co/t/apm-pipeline-painless-script-vanishes-after-upgrade-runtime-field-instead/310115 "2022-07-20T08:52:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmartinez/32/106337_2.png) [@mmartinez](https://discuss.elastic.co/u/mmartinez)\
**Post date:** [July 20, 2022, 8:52am UTC](https://discuss.elastic.co/t/apm-pipeline-painless-script-vanishes-after-upgrade-runtime-field-instead/310115/1 "2022-07-20T08:52:55Z")

</div>

Hello,

We used to have the following painless script for two of our APM pipelines (`traces-apm-8.1.2` & `traces-apm.rum-8.1.2`) that vanished after upgrading escloud version from 8.1.2 to 8.2.3.

```auto
{
  "script": {
    "lang": "painless",
    "source": "double apdex_t = 800.0 * 1000;\nif (ctx.labels==null) {\nctx.labels = [:];\n}\nif (ctx.transaction.duration.us <= apdex_t) {\nctx.labels.apdexscore=1.0;\n}\nelse f (ctx.transaction.duration.us <= (apdex_t * 4)) {\nctx.labels.apdexscore=0.5;\n}\nelse {\nctx.labels.apdexscore=0.0;\n}",
    "ignore_failure": true
  }
}

```

That script generates an apdex value an creates a new field with the value.

We don't only have the problem of removing the painless script when upgrading but we also have the problem of having new pipelines after the upgrade (`traces-apm.rum-8.2.0` & `traces-apm-8.2.0`)

We were thinking of moving that painless script to a runtime field for the Index Templates `traces-apm` & `traces-apm-rum` , but we don't know how to do that and we also don't know if that runtimefield will disappear when we upgrade escloud in the future.

Anybody has an idea how to fix this? Thanks

Kind regards

Mario

---

<div class="post-metadata">

**Author:** ![lahsivjar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lahsivjar/32/101451_2.png) [@lahsivjar](https://discuss.elastic.co/u/lahsivjar)\
**Post date:** [July 26, 2022, 2:42am UTC](https://discuss.elastic.co/t/apm-pipeline-painless-script-vanishes-after-upgrade-runtime-field-instead/310115/2 "2022-07-26T02:42:56Z")

</div>

Hi @mmartinez,

As of writing this comment, pipelines don't persist through upgrades. However, the feature to support optional and custom ingest pipelines is in work.

For runtime fields, you can define them on a data-view from the `Stack Management/Data Views` section. Documentation for the same can be found [here](https://www.elastic.co/guide/en/kibana/current/managing-data-views.html). Runtime fields also use painless script, an example of the script you shared translated to be used with runtime field would be something like:

```auto
if (!doc.containsKey('transaction.duration.us') ||
   doc['transaction.duration.us'].empty
) { return; }

def txnDuration = doc['transaction.duration.us'].value;
double apdex_t = 800.0 * 1000;

if (txnDuration <= apdex_t) {
    emit(1.0);
} else if (txnDuration <= (apdex_t * 4)) {
    emit(0.5);
} else {
    emit(0.0);
}

```

---

<div class="post-metadata">

**Author:** ![mmartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmartinez/32/106337_2.png) [@mmartinez](https://discuss.elastic.co/u/mmartinez)\
**Post date:** [July 28, 2022, 12:21pm UTC](https://discuss.elastic.co/t/apm-pipeline-painless-script-vanishes-after-upgrade-runtime-field-instead/310115/3 "2022-07-28T12:21:58Z")

</div>

Hi @lahsivjar,

Thanks for all your help. I created the runtime field at the Data View with the script you mentioned and it worked. I also modified some visualisations pointing to that new field and they worked too but there is a watcher failing since then.

I attach an screenshot of the runtime field set up.

 ![Screenshot 2022-07-27 at 15.57.41](https://us1.discourse-cdn.com/elastic/original/3X/7/5/75f44af61d2296338f8e405976f5455bc6dfde24.png)

And this is the watcher:

```auto
  "trigger": {
    "schedule": {
      "interval": "30m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "traces-apm*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-60m"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "services": {
              "terms": {
                "field": "service.name",
                "size": 30
              },
              "aggs": {
                "avg_apdexscore": {
                  "avg": {
                    "field": "apdexscore"
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script": {
      "source": """
      return ctx.payload.aggregations.services.buckets.stream()       
        .filter(services -> services.avg_apdexscore.value < 0.8)               
        .count() > 0 
      """,
      "lang": "painless"
    }
  },
  "actions": {
    "log": {
      "transform": {
        "script": {
          "source": """
        return ctx.payload.aggregations.services.buckets.stream()       
        .filter(services -> services.avg_apdexscore.value < 0.8)               
        .collect(Collectors.toList());
        """,
          "lang": "painless"
        }
      },
      "logging": {
        "level": "info",
        "text": """
        {{#ctx.payload._value}} Service {{key}} is below 0.8 with apdexscore value={{avg_apdexscore.value}}
        {{/ctx.payload._value}}
        """
      }
    }
  }
}

```

But all services are returning null values like this

```auto
          "services": {
            "doc_count_error_upper_bound": 0,
            "sum_other_doc_count": 0,
            "buckets": [
              {
                "doc_count": 1352150,
                "avg_apdexscore": {
                  "value": null
                },
                "key": "prod-wh"
              },

```

And this is the error related to those null values.

```auto
      "type": "null_pointer_exception",
      "reason": "Cannot invoke \"Object.getClass()\" because \"leftObject\" is null",
      "stack_trace": "java.lang.NullPointerException: Cannot invoke \"Object.getClass()\" because \"leftObject\" is null\n\tat 

```

Do you know why this is happening? Thanks in advance

Mario

---

<div class="post-metadata">

**Author:** ![lahsivjar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lahsivjar/32/101451_2.png) [@lahsivjar](https://discuss.elastic.co/u/lahsivjar)\
**Post date:** [July 29, 2022, 4:01am UTC](https://discuss.elastic.co/t/apm-pipeline-painless-script-vanishes-after-upgrade-runtime-field-instead/310115/4 "2022-07-29T04:01:06Z")

</div>

Glad that the runtime fields worked for you. I am not a watcher expert but, AFAIK, dataview runtime fields are not available to watcher for a query. [Dataview alerts](https://www.elastic.co/guide/en/kibana/8.3/discover.html#alert-from-Discover) can be used with runtime fields on dataview but I think they are available in 8.3+ versions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2022, 4:01am UTC](https://discuss.elastic.co/t/apm-pipeline-painless-script-vanishes-after-upgrade-runtime-field-instead/310115/5 "2022-08-26T04:01:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
