# How to create a scripted field with multiple conditions check?

**URL:** <https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427>\
**Category:** Kibana\
**Created:** [March 24, 2018, 6:26am UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427 "2018-03-24T06:26:18Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [March 24, 2018, 6:26am UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/1 "2018-03-24T06:26:19Z")

</div>

Hi,

I am using ELK GA 5.0.0. In my index, I have a string field named `name`. I want to create a field named `category` based on the value of `name`. Below is the pseudo code;

```
if(name== 'elephant' || name== 'lion' || name== 'rabbit' || name== 'zebra' || name== 'monkey'){
    category = 'animals'
}else if(name== 'tuna' || name== 'whale' || name== 'shark'){
    category = 'fish'
}else if(name== 'cobra' || name== 'viper' || name== 'python' || name== 'mamba'){
    category = 'snake'
}else if(name== 'crocodile' || name== 'alligator'){
    category = 'reptile'
}else if(name== 'butterfly' || name== 'spider' || name== 'beetle' || name== 'bug' || name== 'dragonfly'){
    category = 'insect'
}else if(name== 'parrot' || name== 'eagle' || name== 'crow' || name== 'owl' || name== 'nightingale'){
    category = 'birds'
}else{
    category = 'others'
}

```

How can I create this field?

Thank you.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2018, 12:18pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/2 "2018-03-24T12:18:16Z")

</div>

I more recent versions you should be able to do this using a [scripted field using Painless](https://www.elastic.co/guide/en/kibana/6.2/scripted-fields.html). Not sure whether but is possible in earlier versions. In general it would however probably be faster and more efficient to add this as a field at index time.

---

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [March 24, 2018, 12:20pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/3 "2018-03-24T12:20:48Z")

</div>

Ok @Christian_Dahlqvist I refered that before, but how to create such a painless rule?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2018, 12:22pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/4 "2018-03-24T12:22:43Z")

</div>

Well, first you probably need to upgrade to Elasticsearch 5.6 or 6.x as Painless is not available in Elasticsearch 5.0.0.

---

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [March 24, 2018, 12:25pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/5 "2018-03-24T12:25:14Z")

</div>

Ok, but previously, I have created fields like;

```
doc['category.keyword'].value == 'vegetable' || doc['category.keyword'].value == 'meat' ? 1 : 0

```

This is working fine for me.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2018, 12:26pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/6 "2018-03-24T12:26:39Z")

</div>

Why not simply add this at index time?

---

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [March 24, 2018, 12:29pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/7 "2018-03-24T12:29:48Z")

</div>

Good question 😜👍

But actually, my logstash is generic and taking much cpu already. Thought of adding this to logsatsh, so that I can easily modify my data accordingly, but there are reasons. My only possible hope is scripted field now, thats y ☹

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2018, 12:36pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/8 "2018-03-24T12:36:35Z")

</div>

[This blog post](https://www.elastic.co/blog/using-painless-kibana-scripted-fields) provides a good introduction, and actually points out that Painless is available in version 5.0, so I was remembering wrong earlier.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2018, 12:57pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/9 "2018-03-24T12:57:25Z")

</div>

Something like this may work (although I have not tested it):

```auto
def birds = ["parrot", "eagle", "crow"]; 
def insects = ["spider", "beatle];
if(birds.contains(doc["name"].value)) { 
    return "bird"; 
} else if (insects.contains(doc["name"].value) { 
    return "insect"; 
} else {
    return "other";
}

```

---

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [March 24, 2018, 1:24pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/10 "2018-03-24T13:24:29Z")

</div>

Ok. Lemme see.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2018, 1:24pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427/11 "2018-04-21T13:24:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
