# Dynamic templates and transform script

**URL:** <https://discuss.elastic.co/t/dynamic-templates-and-transform-script/35840>\
**Category:** Elasticsearch\
**Created:** [November 29, 2015, 7:00pm UTC](https://discuss.elastic.co/t/dynamic-templates-and-transform-script/35840 "2015-11-29T19:00:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![RR\_PHOTOSOFT](https://avatars.discourse-cdn.com/v4/letter/r/9de053/32.png) [@RR\_PHOTOSOFT](https://discuss.elastic.co/u/RR_PHOTOSOFT)\
**Post date:** [November 29, 2015, 7:00pm UTC](https://discuss.elastic.co/t/dynamic-templates-and-transform-script/35840/1 "2015-11-29T19:00:06Z")

</div>

Hi,  
I'm using logback to generate some logs from my java app and FILEBEAT to add them to elasticsearch All that is working fine.  
I DO NOT want to use logstash because I have memory constraints, and currently no budget to buy more RAM.  
So what I am trying to do is use a transform script in the dynamic template provided with filebeat, to transform the "msg" field using a Groovy Script. Unfortunately I have no idea, why my script is never invoked. I have stored the script in config/scripts , while dynamic\_scripting is disabled. Can someone please help to correct my syntax.

```
{
"mappings": {
"_default_": {
  "_all": {
    "enabled": true,
    "norms": {
      "enabled": false
    }
  },
  "dynamic_templates": [
    {
      "template1": {
        "mapping": {
          "doc_values": true,
          "ignore_above": 1024,
          "index": "not_analyzed",
          "type": "{dynamic}",
          "transform":{
             "script":{
                  "file":"transformer"
             }
           }
        },
        "match": "message"
      }
    }
  ],
  "properties": {
    "message": {
      "type": "string",
      "index": "analyzed"
    },
   "test_field":{
     "type":"string',
    "index":"not_analyzed"
    }
  }
 }

```

Here is my transformer

```
transformer.groovy
ctx._test_field = "test";

```

I do not see any test\_field in the log index documents, while the message field contains the usual log output. My final intention is to use a regex to parse out certain contents from the message field and append them to other fields.

Thanks.  
RRphotosoft.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:35pm UTC](https://discuss.elastic.co/t/dynamic-templates-and-transform-script/35840/2 "2017-07-05T23:35:02Z")

</div>


