# Field \[\] used in expression does not exist in mappings, even after creating…?

**URL:** <https://discuss.elastic.co/t/field-used-in-expression-does-not-exist-in-mappings-even-after-creating/73515>\
**Category:** Kibana\
**Created:** [February 1, 2017, 12:49pm UTC](https://discuss.elastic.co/t/field-used-in-expression-does-not-exist-in-mappings-even-after-creating/73515 "2017-02-01T12:49:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![informatico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/informatico/32/15065_2.png) [@informatico](https://discuss.elastic.co/u/informatico)\
**Post date:** [February 1, 2017, 12:49pm UTC](https://discuss.elastic.co/t/field-used-in-expression-does-not-exist-in-mappings-even-after-creating/73515/1 "2017-02-01T12:49:11Z")

</div>

Hi,

I am very new to both Elasticsearch and Kibana, which I am using for a current project. I have data coming in from an external source, and one of the fields I have in Discover of Kibana is 'clearancetime'. This field is either empty or has a timestamp in the following format:

`January 22nd 2017, 00:00:00.000`

I have scripted a field which uses the clearance time in a ternary statement. I think get an error in Discover that the field cleartime used in the expression does not exist in mappings. So I tried adding it via sense with the following PUT request:

```
PUT source*/_mappings/clearancetime
{
   "properties": {
      "data": {
          "type": "date"
      }
   }
}

```

I get back the response : { "acknowledge": true }

But I still get the same field does not exist in mapping error.

Any ideas?

ADDITIONAL ERROR INFORMATION: (sorry about the format)....

```
Error: Request to Elasticsearch failed: {"error":
{"root_cause":[{"type":"script_exception",
"reason":"Field [clearancetime] used in expression does not exist in mappings"}],
"type":"search_phase_execution_exception","reason":"all shards failed",
"phase":"query","grouped":true,"failed_shards":
[{"shard:0,"index":"source-raw-2017.01","node":"dewddasOSada_0vJWA",
"reason":{"type":"script_exception","reason":"Error during search with inline script 
[doc['clearancetime'].value > 0 ? doc['clearancetime'].value - doc['initialtime'].value : 0] using lang [expression]",
"caused_by":{"type":"script_exception",
"reason":"Field [clearancetime] used in expression does not exist in mappings"}}}]}}

```

The scripted field called "duration" has the following ternary expression:

```
doc['clearancetime'].value > 0 ? doc['clearancetime'].value - doc['initialtime'].value : 0
```

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [February 1, 2017, 3:12pm UTC](https://discuss.elastic.co/t/field-used-in-expression-does-not-exist-in-mappings-even-after-creating/73515/2 "2017-02-01T15:12:02Z")

</div>

Hi @informatico,

by executing the `PUT` request you described you are adding a mapping for the document type `clearancetime` to indices matching `source*` with one field called `data` of type `date`.

I guess what you intend to do is add a mapping for the document type (replace `${YOURDOCTYPE}` with the proper value) containing the fields `clearancetime` and `initialtime`:

```
PUT source*/_mappings/${YOURDOCTYPE}
{
   "properties": {
      "clearancetime": {
          "type": "date"
      },
      "initialtime": {
          "type": "date"
      }
   }
}
```

---

<div class="post-metadata">

**Author:** ![informatico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/informatico/32/15065_2.png) [@informatico](https://discuss.elastic.co/u/informatico)\
**Post date:** [February 10, 2017, 2:15pm UTC](https://discuss.elastic.co/t/field-used-in-expression-does-not-exist-in-mappings-even-after-creating/73515/3 "2017-02-10T14:15:19Z")

</div>

This worked! Thank you so much for your response.

This is a little off topic, but do you know how I can get the value in the duration field in a more informative format such as... 00:00:00. Currenlty I am getting a single long value in milliseconds.

I have tried adding  
"format": "00:00:00"  
under the type properties in the mapping... however this does not change anything.

I am using .value in the expression of my scripted fields, according to the documentaton this returns a value in milliseconds. So what are the alternatives?

Thanks.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [February 14, 2017, 11:42am UTC](https://discuss.elastic.co/t/field-used-in-expression-does-not-exist-in-mappings-even-after-creating/73515/4 "2017-02-14T11:42:14Z")

</div>

You can customize the formatting of fields in Kibana using [field formatters](https://www.elastic.co/guide/en/kibana/current/field-formatters-numeric.html). It sounds like the `Duration` formatter could achieve what you're looking for.

---

<div class="post-metadata">

**Author:** ![informatico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/informatico/32/15065_2.png) [@informatico](https://discuss.elastic.co/u/informatico)\
**Post date:** [February 15, 2017, 4:01pm UTC](https://discuss.elastic.co/t/field-used-in-expression-does-not-exist-in-mappings-even-after-creating/73515/5 "2017-02-15T16:01:58Z")

</div>

Thanks for the response.

I should have mentioned that I'm restricted to Kibana 4.6.

Do you know of any alternatives in this case?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [February 15, 2017, 4:40pm UTC](https://discuss.elastic.co/t/field-used-in-expression-does-not-exist-in-mappings-even-after-creating/73515/6 "2017-02-15T16:40:38Z")

</div>

That is too bad. I would definitely recommend to update to Version 5 of the Elastic Stack if at all possible.

In the meantime you might be able to make due with a [scripted field](https://www.elastic.co/guide/en/kibana/4.6/managing-fields.html#create-scripted-field). Just keep in mind that these fields cannot be queried and can have a negative performance impact.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2017, 4:40pm UTC](https://discuss.elastic.co/t/field-used-in-expression-does-not-exist-in-mappings-even-after-creating/73515/7 "2017-03-15T16:40:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
