# Elasticsearch profiling, script error

**URL:** <https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343>\
**Category:** Elasticsearch\
**Created:** [November 27, 2018, 1:03pm UTC](https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343 "2018-11-27T13:03:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akaren](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@Akaren](https://discuss.elastic.co/u/Akaren)\
**Post date:** [November 27, 2018, 1:03pm UTC](https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343/1 "2018-11-27T13:03:31Z")

</div>

Hi, I have ELK v 6.1 and I am doing profiling of my queries from charts - I just copy request that I can see from kibana. But I always get error:

```
{"error":{"root_cause":[{"type":"script_exception","reason":"compile error","script_stack":["if(doc[attrs.sip-code].value == ..."," ^---- HERE"],"script"

```

So profiling can't see **doc** values?

Here is my profile query

```
 curl -X GET "localhost:9200/logstash*/_search" -H 'Content-Type: application/json' -d'{"profile": true, 
 "size":"500","sort":[{"@timestamp":{"order":"desc","unmapped_type":"boolean"}}],"script_fields": 
 {"sip_name_translate":{"script":{"inline":"if(doc['attrs.sip-code'].value == 200) { return \"OK\" } else 
 {return doc['type'].value}","lang":"painless"}},"docvalue_fields":["@timestamp","ts"],"query":{"bool":{"must":[{"query_string": 
 {"query":"type: call-start OR type: call-end OR type:call- 
 attempt"}},{"range":{"@timestamp": 
{"gte":1529428284890,"lte":1529540016737,"format":"epoch_millis"}}}],"filter":[],"should":[],"must_not": 
[]}}}'
```

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [November 27, 2018, 4:31pm UTC](https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343/2 "2018-11-27T16:31:28Z")

</div>

Notice in the error the single quotes are removed from your field name:

```auto
doc[attrs.sip-code].value

```

Your single quotes are being eaten by curl.

---

<div class="post-metadata">

**Author:** ![Akaren](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@Akaren](https://discuss.elastic.co/u/Akaren)\
**Post date:** [November 27, 2018, 10:51pm UTC](https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343/3 "2018-11-27T22:51:29Z")

</div>

AH, so how should I do it?

doc[\'attrs.sip-code\'].value

or

doc[\"attrs.sip-code\"].value

doesn't work

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [November 27, 2018, 11:17pm UTC](https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343/4 "2018-11-27T23:17:10Z")

</div>

There are a number of ways to handle it. One way is to put your data in a file and reference via `-d @myfile.json`, another is to unicode escape the single quote by replacing with `\u0027`.

---

<div class="post-metadata">

**Author:** ![Akaren](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@Akaren](https://discuss.elastic.co/u/Akaren)\
**Post date:** [November 28, 2018, 1:15pm UTC](https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343/5 "2018-11-28T13:15:01Z")

</div>

I have tried both options on simple example, here is the one with \u0027:

```
  curl -X GET "localhost:9200/logstash*/_search" -H 'Content-Type: application/json' -d' {"_source": 
 ["from"],"aggs":{"agg":{"sum":{"field":"duration","script": 
 {"source":"doc[\u0027duration\u0027].value/60"}}}}}'

```

But both options has the same error:

```
 {"error":{"root_cause":[{"type":"parsing_exception","reason":"[sum] failed to parse field 
 [script]","line":1,"col":85}],"type":"parsing_exception","reason":"[sum] failed to parse field 
 [script]","line":1,"col":85,"caused_by":{"type":"illegal_argument_exception","reason":"[script] unknown 
 field [source], parser not found"}},"status":400}[root@sbcmon ~]#
```

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [November 28, 2018, 8:08pm UTC](https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343/6 "2018-11-28T20:08:06Z")

</div>

I don't think this new error has anything to do with single quotes. What version of elasticsearch are you running against? If you replace "source" with "inline" does it work?

---

<div class="post-metadata">

**Author:** ![Akaren](https://avatars.discourse-cdn.com/v4/letter/a/8dc957/32.png) [@Akaren](https://discuss.elastic.co/u/Akaren)\
**Post date:** [November 29, 2018, 8:01am UTC](https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343/7 "2018-11-29T08:01:12Z")

</div>

Yes! You are right, I have two different version of ELK running and testing.  
Thank you for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2018, 8:01am UTC](https://discuss.elastic.co/t/elasticsearch-profiling-script-error/158343/8 "2018-12-27T08:01:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
