# Doc\['field'\]. value not returning the correct value

**URL:** <https://discuss.elastic.co/t/doc-field-value-not-returning-the-correct-value/250386>\
**Category:** Kibana\
**Created:** [September 29, 2020, 3:11pm UTC](https://discuss.elastic.co/t/doc-field-value-not-returning-the-correct-value/250386 "2020-09-29T15:11:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![raviswam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raviswam/32/76302_2.png) [@raviswam](https://discuss.elastic.co/u/raviswam)\
**Post date:** [September 29, 2020, 3:11pm UTC](https://discuss.elastic.co/t/doc-field-value-not-returning-the-correct-value/250386/1 "2020-09-29T15:11:08Z")

</div>

```
`indent preformatted text by 4 spaces`

```

Hi Guys,

Very new to painless scripting and have the simplest of scripted fields which is not working. I am trying to extract a pattern from doc["message"] field but it fails.  
So I was looking at the value returned by doc["message"].value and its not same  
as the actual value in the field.

I am getting value returned as "0000" highlighted in yellow (image below) where as the actual value can be seen along with it. (screenshot of preview results).

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/8/2/82e940fcc2ee7a1b4e88748105f7cef3fae4cbc1.png)

What am I missing here . I am sure its something very basic.

Thanks

Ravi

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [September 29, 2020, 3:32pm UTC](https://discuss.elastic.co/t/doc-field-value-not-returning-the-correct-value/250386/2 "2020-09-29T15:32:49Z")

</div>

Hi

Might be an issue with your mapping, could you share the mapping of the "message" field?

Thx & best,  
Matthias

---

<div class="post-metadata">

**Author:** ![raviswam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raviswam/32/76302_2.png) [@raviswam](https://discuss.elastic.co/u/raviswam)\
**Post date:** [September 29, 2020, 3:48pm UTC](https://discuss.elastic.co/t/doc-field-value-not-returning-the-correct-value/250386/3 "2020-09-29T15:48:04Z")

</div>

Hi Matw,

Thanks for your quick response.

I switched to using message.keyword instead and its working fine.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d68ece48c47de069c7071e9f16bf64b1778ef613.png)

Thanks

Ravi

---

<div class="post-metadata">

**Author:** ![raviswam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raviswam/32/76302_2.png) [@raviswam](https://discuss.elastic.co/u/raviswam)\
**Post date:** [September 30, 2020, 6:39am UTC](https://discuss.elastic.co/t/doc-field-value-not-returning-the-correct-value/250386/4 "2020-09-30T06:39:50Z")

</div>

Sorry this issue is not resolved yet. The value returned for doc["message"].value is still incorrect (see first comment).

The mapping for the field is below

```
   "message" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 1000
        }
      }
    },
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2020, 6:39am UTC](https://discuss.elastic.co/t/doc-field-value-not-returning-the-correct-value/250386/5 "2020-10-28T06:39:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
