# Cannot search for events based on scripted fields

**URL:** <https://discuss.elastic.co/t/cannot-search-for-events-based-on-scripted-fields/244659>\
**Category:** Kibana\
**Created:** [August 12, 2020, 5:44am UTC](https://discuss.elastic.co/t/cannot-search-for-events-based-on-scripted-fields/244659 "2020-08-12T05:44:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![vivekkarne](https://avatars.discourse-cdn.com/v4/letter/v/f08c70/32.png) [@vivekkarne](https://discuss.elastic.co/u/vivekkarne)\
**Post date:** [August 12, 2020, 5:44am UTC](https://discuss.elastic.co/t/cannot-search-for-events-based-on-scripted-fields/244659/1 "2020-08-12T05:44:28Z")

</div>

Hi,  
When i search using scripted fields in kibana, i either get no matching hits or I get a shards failed error. Can anyone please help me to look into this. Entire ELK stack is 7.4.2.

 ![Screen Shot 2020-08-12 at 11.05.34 AM](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d047a4f00db5696583504f42931ea07dd59936d.png)

 ![Screen Shot 2020-08-12 at 11.06.57 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/7/9761ea4d05f7e7d77cbda9b3308bf247f75d33fe.png)

s\_query body:

```auto
    if(doc['querybody'].size() > 0) {
        String querybody=doc['querybody'].value;
        querybody=/[<>=] {1,}[0-9][^ )]*/.matcher(querybody).replaceAll("= ?");
        querybody=/[<>=] {1,}['][^']*'/.matcher(querybody).replaceAll("= ?");
        querybody=/ts_c_[^\.]*/.matcher(querybody).replaceAll("ts_c_?");
        querybody=/([a-z_]{1,})00[0-9]{2}/.matcher(querybody).replaceAll("\\1");
        querybody=/ IN {1,}\([^)]{1,}\)*/.matcher(querybody).replaceAll(" IN ?");
        querybody=/ LIKE {1,}['][^']*'/.matcher(querybody).replaceAll(" LIKE ?");    
        return querybody;
    }

```

Getting shards failed:

 ![Screen Shot 2020-08-12 at 11.09.07 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/0/80ff3adbb04b42d7b2e8d878e280893eb706dc45.png)

 ![Screen Shot 2020-08-12 at 11.10.11 AM](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3ded96115f65308b911fdb12163055db200493a6.png)

s\_querytimes:

`if(doc['querytimems'].size() > 0) { return doc['querytimems'].value/1000.0; }`

Regards,  
Vivek

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 12, 2020, 10:01am UTC](https://discuss.elastic.co/t/cannot-search-for-events-based-on-scripted-fields/244659/2 "2020-08-12T10:01:28Z")

</div>

When you are using a scripted field as comparison in KQL, it always needs to return a numeric value. Add an else condition and return `-1` or something similar in there, then it should work

---

<div class="post-metadata">

**Author:** ![vivekkarne](https://avatars.discourse-cdn.com/v4/letter/v/f08c70/32.png) [@vivekkarne](https://discuss.elastic.co/u/vivekkarne)\
**Post date:** [August 12, 2020, 10:15am UTC](https://discuss.elastic.co/t/cannot-search-for-events-based-on-scripted-fields/244659/3 "2020-08-12T10:15:27Z")

</div>

The scripted field will exist only when doc['querytimems'] field is present, else the scripted field will not be present. So writing an else condition will cause all the documents which does not have doc['querytimems'] field to contain the scripted field with value -1. Is this the expected behaviour?

---

<div class="post-metadata">

**Author:** ![vivekkarne](https://avatars.discourse-cdn.com/v4/letter/v/f08c70/32.png) [@vivekkarne](https://discuss.elastic.co/u/vivekkarne)\
**Post date:** [August 12, 2020, 10:23am UTC](https://discuss.elastic.co/t/cannot-search-for-events-based-on-scripted-fields/244659/4 "2020-08-12T10:23:10Z")

</div>

And also can we perform text searches on scripted fields?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 12, 2020, 11:52am UTC](https://discuss.elastic.co/t/cannot-search-for-events-based-on-scripted-fields/244659/5 "2020-08-12T11:52:09Z")

</div>

> The scripted field will exist only when doc['querytimems'] field is present, else the scripted field will not be present. So writing an else condition will cause all the documents which does not have doc['querytimems'] field to contain the scripted field with value -1. Is this the expected behaviour?

Yes, this would be necessary to use the scripted field in this way.

> And also can we perform text searches on scripted fields?

On scripted fields returning strings you can do text searches as well

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2020, 11:52am UTC](https://discuss.elastic.co/t/cannot-search-for-events-based-on-scripted-fields/244659/6 "2020-09-09T11:52:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
