# How to extract \_ttl field value on documents

**URL:** <https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893>\
**Category:** Elasticsearch\
**Created:** [September 17, 2018, 10:21pm UTC](https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893 "2018-09-17T22:21:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pbathala](https://avatars.discourse-cdn.com/v4/letter/p/c2a13f/32.png) [@pbathala](https://discuss.elastic.co/u/pbathala)\
**Post date:** [September 17, 2018, 10:21pm UTC](https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893/1 "2018-09-17T22:21:17Z")

</div>

Hello,  
I am migrating my 2.x indices to 6.x (to time based indices). My 2.x index has `_ttl` on them and no created timestamp, for me to migrate the index to 6.x cluster, I need to know the timestamp when the document is created, so i can place them in proper index in 6.x cluster, but unfortunately I am not able to fetch the `_ttl` field on the document (as mentioned by some people).

tried this with no luck

```
curl -XPOST -H "Content-Type: application/json" 'https://localhost:9200/index_v1/_search' -d'{
     "fields": ["_ttl"],
     "query": {
         "match_all": {}
     }
 }'

```

Is there a way i can get `_ttl` value on the document on 2.x cluster ?

Thanks

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [September 17, 2018, 10:52pm UTC](https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893/2 "2018-09-17T22:52:40Z")

</div>

I'm not sure why it won't work through `fields`, but the ttl field was stored by default in 2.x, so you could try a script field, and access it with `_fields['_ttl']`.

---

<div class="post-metadata">

**Author:** ![pbathala](https://avatars.discourse-cdn.com/v4/letter/p/c2a13f/32.png) [@pbathala](https://discuss.elastic.co/u/pbathala)\
**Post date:** [September 17, 2018, 11:24pm UTC](https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893/3 "2018-09-17T23:24:20Z")

</div>

That didn't work too

```
curl -XPOST -H "Content-Type: application/json" 'http://localhost:9200/index_v1/_search?pretty' -d '
{
  "query" : { "match_all" : {} },
  "script_fields" : {
    "test" : {
      "script" : "_fields['_ttl']"
    }
  }
}'
{
  "took" : 4,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 4,
    "failed" : 1,
    "failures" : [ {
      "shard" : 0,
      "index" : "index_v1",
      "node" : "mDZ5XrzMTmSxlNPRko4p6Q",
      "reason" : {
        "type" : "script_exception",
        "reason" : "failed to run inline script [_fields[_ttl]] using lang [groovy]",
        "caused_by" : {
          "type" : "missing_property_exception",
          "reason" : "No such property: _ttl for class: c98975b952ef7f243a7e138611da53f620a7532e"
        }
      }
    } ]
  },
  "hits" : {
    "total" : 195841,
    "max_score" : 1.0,
    "hits" : []
  }
}
```

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [September 19, 2018, 7:20pm UTC](https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893/4 "2018-09-19T19:20:12Z")

</div>

Could you show your mappings for ttl?

```auto
curl -XGET 'http://localhost:9200/index_v1/_mapping/*/field/_ttl'`

```

---

<div class="post-metadata">

**Author:** ![pbathala](https://avatars.discourse-cdn.com/v4/letter/p/c2a13f/32.png) [@pbathala](https://discuss.elastic.co/u/pbathala)\
**Post date:** [September 19, 2018, 8:00pm UTC](https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893/5 "2018-09-19T20:00:50Z")

</div>

```
{
  "index_v1": {
    "mappings": {
      "test": {
        "_ttl": {
          "full_name": "_ttl",
          "mapping": {
            "_ttl": {
              "enabled": true,
              "default": 7862400000
            }
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [September 19, 2018, 10:03pm UTC](https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893/6 "2018-09-19T22:03:59Z")

</div>

Ok I see it now. Notice in the error message the single quotes are missing from your script around `_ttl`:

```auto
failed to run inline script [_fields[_ttl]]

```

Your curl data is encapsulated with single quotes. You need to escape them so they are passed through to elasticsearch.

---

<div class="post-metadata">

**Author:** ![pbathala](https://avatars.discourse-cdn.com/v4/letter/p/c2a13f/32.png) [@pbathala](https://discuss.elastic.co/u/pbathala)\
**Post date:** [September 19, 2018, 10:49pm UTC](https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893/7 "2018-09-19T22:49:10Z")

</div>

OMG! that works. Thank you very much, really overlooked that

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 17, 2018, 10:49pm UTC](https://discuss.elastic.co/t/how-to-extract-ttl-field-value-on-documents/148893/8 "2018-10-17T22:49:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
