# Dynamically adding runtime fields

**URL:** <https://discuss.elastic.co/t/dynamically-adding-runtime-fields/298427>\
**Category:** Elasticsearch\
**Tags:** painless, runtime-fields\
**Created:** [February 28, 2022, 3:58pm UTC](https://discuss.elastic.co/t/dynamically-adding-runtime-fields/298427 "2022-02-28T15:58:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [February 28, 2022, 3:58pm UTC](https://discuss.elastic.co/t/dynamically-adding-runtime-fields/298427/1 "2022-02-28T15:58:02Z")

</div>

Dear all,

I have a few runtime fields with `painless` scripts in my mappings that work pretty well. So far I have a list of all the date fields to index. However, things are changing and now I have the problem that there may be an unknown amount of new date fields. I already have a dynamic mapping which also creates the date fields for me as a `date` data type. But when it comes to creating runtime fields for the `days of the week`, I'm at a loss.

**An excerpt from my current mapping:**

```auto
[...]
    "dynamic_templates": [
      {
        "DateValue": {
          "path_match": "*.DateValue",
          "mapping": {
            "type": "date",
            "format": "yyyy-MM-dd HH:mm:ss||strict_date_optional_time"
          }
        }
      },
[...]
    "runtime": {
      "Created.DayOfWeek": {
        "type": "keyword",
        "script": {
          "source": "String WeekDay = doc['Created'].value.dayOfWeekEnum.getDisplayName(TextStyle.FULL, Locale.ROOT); if ( ! WeekDay.empty ) emit( WeekDay )"
        }
      },
[...]

```

In my example I have a field that arrives as `Created.DateValue` and is recognized by the dynamic mapping and stored as a `date` data type.

**Question:**

How can I automate the mapping, so that every incoming date filed also gets a relevant `XXX.DayOfWeek` runtime field?

I was trying to get this done in the dynamic template using the `{name}` template variable, but without success.

```auto
[...]
    "dynamic_templates": [
      {
        "DateValue": {
          "path_match": "*.DateValue",
          "mapping": {
            "type": "date",
            "format": "yyyy-MM-dd HH:mm:ss||strict_date_optional_time",
            "fields": {
              "DayOfWeek": {
                "type": "keyword",
                "script": {
                  "source": "String WeekDay = doc[{name}].value.dayOfWeekEnum.getDisplayName(TextStyle.FULL, Locale.ROOT); if ( ! WeekDay.empty ) emit( WeekDay )"
                }
              }
            }
          }
        }
      },
[...]

```

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [March 2, 2022, 4:55am UTC](https://discuss.elastic.co/t/dynamically-adding-runtime-fields/298427/2 "2022-03-02T04:55:53Z")

</div>

I suppose the way to use multi-fields in runtime mappings is described here.

> **[Explore your data with runtime fields | Elasticsearch Guide \[8.0\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime-examples.html#runtime-examples-grok-composite)**

> <https://github.com/elastic/elasticsearch/issues/68203>
>
> We recently added support for runtime fields, that are computed at search time b…ased on a painless script. As of today, a runtime field script can emit values for a single field, the one that the script is declared under.
> 
> We would like to add the ability for a script to emit values for multiple fields. This will be achieved by introducing support for a new field type (name to be defined) as part of the runtime section. Its script emits fields that belong to such object. This is particularly useful given that scripts support grok and dissect (#68088):
> 
> \`\`\`
> PUT localhost:9200/logs/\_mappings
> {
> "runtime" : {
> "log" : {
> "type" : "tbd",
> "script": '''
> emit(grok('%{COMMONAPACHELOG}').extract(doc\["message"\].value)));
> ''',
> "fields" : {
> "clientip" : {
> "type" : "ip"
> },
> "verb" : {
> "type" : "keyword"
> },
> "request" : {
> "type" : "keyword"
> },
> "response" : {
> "type" : "long"
> }
> }
> }
> },
> "properties" : {
> "message" : {
> "type" : "keyword"
> }
> }
> }
> \`\`\`
> 
> In the example above, the \`grok\` function splits the message field into sub-fields based on the provided grok pattern, and each of the resulting fields is emitted in the following loop. The emitted fields need to be listed under the sub-fields in order to specify their type and make them searchable (and discoverable through field\_caps) like any other field:
> 
> \`\`\`
> POST /logs\*/\_search
> {
> "aggs": {
> "response\_codes": {
> "range": {
> "field": "log.response",
> "ranges": \[
> { "to": 300 },
> { "from": 300, "to": 400 },
> { "from": 500 }
> \]
> }
> }
> }
> }
> \`\`\`

I have no idea about how to use runtime fields as sub fields as [ordinal multi-fields mappings](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2022, 4:56am UTC](https://discuss.elastic.co/t/dynamically-adding-runtime-fields/298427/3 "2022-03-30T04:56:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
