# Exists scripted field

**URL:** <https://discuss.elastic.co/t/exists-scripted-field/95551>\
**Category:** Kibana\
**Created:** [August 2, 2017, 2:36pm UTC](https://discuss.elastic.co/t/exists-scripted-field/95551 "2017-08-02T14:36:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![annizaki](https://avatars.discourse-cdn.com/v4/letter/a/46a35a/32.png) [@annizaki](https://discuss.elastic.co/u/annizaki)\
**Post date:** [August 2, 2017, 2:36pm UTC](https://discuss.elastic.co/t/exists-scripted-field/95551/1 "2017-08-02T14:36:00Z")

</div>

Hi all,

I am monitoring a variety of components and have created visualisations to show whether the component is up, down or hasn't responded in a while. If the component is up or down, it sends a log to elastic search every minute with the field "Entry" set to true or false and the visualisation displays a green or red circle accordingly.. If the component has not answered in a while however, that circle is blank, since there is no data for it:

 ![4](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a361e189d18882b656843087009daa7355a9ac2.png)

For this visualisation, I am splitting the chart by component name and then filtering by the value of the "Entry" field in the last log received for that component

and in the "response" section of the visualisation, I get this for a component that's been sending logs:

"myComponent": {  
"3": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets": [  
{  
"key": "True",  
"doc\_count": 60  
}  
]  
},  
"doc\_count": 60  
},

and this for a component with no logs

"randomComponent": {  
"3": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets":   
},  
"doc\_count": 0  
}

What I am trying to do is write a scripted field that will check if the Entry field exists in the document and if yes, return its value, otherwise return the value "no logs". Or a scripted field that would see if the doc\_count = 0 and return the correct result. Any ideas?

P.S. this might be doable with json input, but I have no idea how to use that...

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [August 2, 2017, 4:58pm UTC](https://discuss.elastic.co/t/exists-scripted-field/95551/2 "2017-08-02T16:58:11Z")

</div>

Have you played around with the "Top Hit" metric aggregation? Coupled with the metric visualization, this may give you what you want.

1. Create a new metric visualization
2. Select the "Entry" field

Can you let me know if this is what you're trying to accomplish?

---

<div class="post-metadata">

**Author:** ![annizaki](https://avatars.discourse-cdn.com/v4/letter/a/46a35a/32.png) [@annizaki](https://discuss.elastic.co/u/annizaki)\
**Post date:** [August 3, 2017, 8:13am UTC](https://discuss.elastic.co/t/exists-scripted-field/95551/3 "2017-08-03T08:13:25Z")

</div>

Hi @lukas, thank you for the answer but I have no clue how to do what you said. I am currently using version 5.1.1 for Kibana, and there is not "top hit" aggregation available in the metric visualisation...

However it doesn't sound like something that would work, since there would be no log with the "Entry" field for components that haven't sent anything to elasticsearch?

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [August 3, 2017, 4:32pm UTC](https://discuss.elastic.co/t/exists-scripted-field/95551/4 "2017-08-03T16:32:30Z")

</div>

I think I originally misunderstood your question.

Unfortunately, it sounds like what you're trying to do would require a [scripted metric aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-scripted-metric-aggregation.html), which isn't currently supported in Kibana. Here's the corresponding issue to follow for updates: [https://github.com/elastic/kibana/issues/2646](https://github.com/elastic/kibana/issues/2646)

---

<div class="post-metadata">

**Author:** ![annizaki](https://avatars.discourse-cdn.com/v4/letter/a/46a35a/32.png) [@annizaki](https://discuss.elastic.co/u/annizaki)\
**Post date:** [August 4, 2017, 7:50am UTC](https://discuss.elastic.co/t/exists-scripted-field/95551/5 "2017-08-04T07:50:26Z")

</div>

I see, thank you for your time! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2017, 7:50am UTC](https://discuss.elastic.co/t/exists-scripted-field/95551/6 "2017-09-01T07:50:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
