# Create script-field and aggregate+filter+bucket on that

**URL:** <https://discuss.elastic.co/t/create-script-field-and-aggregate-filter-bucket-on-that/45329>\
**Category:** Elasticsearch\
**Created:** [March 24, 2016, 10:03am UTC](https://discuss.elastic.co/t/create-script-field-and-aggregate-filter-bucket-on-that/45329 "2016-03-24T10:03:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ddorian43](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddorian43/32/36093_2.png) [@ddorian43](https://discuss.elastic.co/u/ddorian43)\
**Post date:** [March 24, 2016, 10:03am UTC](https://discuss.elastic.co/t/create-script-field-and-aggregate-filter-bucket-on-that/45329/1 "2016-03-24T10:03:17Z")

</div>

Hi,

I have a complex \_uid, which can be used in aggregations.

The \_uid is like:

type#var1:var2:var3:var4

Is it possible to use a script (or something else), so I move each "var(x)" into a separate field, and use them for filtering, aggregating (top "var1" values), basically just use them like you would use a normal field.

Thank You

---

<div class="post-metadata">

**Author:** ![ywelsch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ywelsch/32/7751_2.png) [@ywelsch](https://discuss.elastic.co/u/ywelsch)\
**Post date:** [March 24, 2016, 10:17am UTC](https://discuss.elastic.co/t/create-script-field-and-aggregate-filter-bucket-on-that/45329/2 "2016-03-24T10:17:47Z")

</div>

Extracting data from one field into other fields at index time will be made possible by the upcoming _ingest_ functionality (see [https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html) ). An index-time alternative is to use Logstash.  
The simplest solution might just be to properly index the information that is now contained in the \_uid field.

---

<div class="post-metadata">

**Author:** ![ddorian43](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddorian43/32/36093_2.png) [@ddorian43](https://discuss.elastic.co/u/ddorian43)\
**Post date:** [March 24, 2016, 10:33am UTC](https://discuss.elastic.co/t/create-script-field-and-aggregate-filter-bucket-on-that/45329/3 "2016-03-24T10:33:48Z")

</div>

I don't need for index-time, I needed for query-time, to lower the storage and duplicate indexes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:05pm UTC](https://discuss.elastic.co/t/create-script-field-and-aggregate-filter-bucket-on-that/45329/4 "2017-07-05T23:05:33Z")

</div>


