# How to find number of characters in a text field

**URL:** <https://discuss.elastic.co/t/how-to-find-number-of-characters-in-a-text-field/310189>\
**Category:** Elasticsearch\
**Tags:** painless\
**Created:** [July 20, 2022, 6:23pm UTC](https://discuss.elastic.co/t/how-to-find-number-of-characters-in-a-text-field/310189 "2022-07-20T18:23:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nestor1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nestor1/32/123438_2.png) [@nestor1](https://discuss.elastic.co/u/nestor1)\
**Post date:** [July 20, 2022, 6:23pm UTC](https://discuss.elastic.co/t/how-to-find-number-of-characters-in-a-text-field/310189/1 "2022-07-20T18:23:59Z")

</div>

I have an application that is writing many documents in Elasticsearch. After a year or two, I figured out that some of these documents are scams because they contain large strings (more than 10000 characters). E.g. one document looks like this:

```auto
Message: "bnfgbjkcywcbyftetzodbpgipcdoxgedjxqbfmcjiwlkceyehnwpwhlcfpbivaflaphvlplgeqirctmdyyoasqhhgfopvktgeupughwrteqadrlcmeauxktggoopycijrwenoesdtewvkgsdhafptepxqfidgdpjozvqafbkkshoiokaosqypwxpmttgzntpbdnk...[up to 10000 characters]"

```

Mapping of the `Message` field is set as a `Text` and as a `keyword`. In cases when that kind of document gets in the index, only the `Text` field is mapped, because the `keyword` has "ignore above 256" setting enabled by default.

I wanted to check documents with a **Message** field value larger than 1000, but I can't apply the script because the `Message.keyword` does not exist, only the Message (as a `Text`).

```auto
GET my-index/_search
{
  "query": {
    "bool": {
      "filter": {
        "script": {
          "script": {
            "source": "doc['Message'].value.length() > 1000",
            "lang": "painless"
          }
        }
      }
    }
  }
}

```

will throw an error that the Text fields are not optimized for operations that require per-document field data like aggregations and sorting.

If I put `doc['Message.keyword'].value.length() > 1000` I get an error cause those documents don't have `keyword` (because it's larger than 256).

Any idea how else can I check these documents that contain only 1 long string (greater than N number of characters), I would like to reindex into a new index without those documents, and apply proper mapping so in the future those documents will be rejected by Elastic.

Thanks!

---

<div class="post-metadata">

**Author:** ![stu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stu/32/75063_2.png) [@stu](https://discuss.elastic.co/u/stu)\
**Post date:** [July 20, 2022, 6:59pm UTC](https://discuss.elastic.co/t/how-to-find-number-of-characters-in-a-text-field/310189/2 "2022-07-20T18:59:20Z")

</div>

> Any idea how else can I check these documents that contain only 1 long string (greater than N number of characters)

Hi @nestor1,  
Because there's no keyword field, you'll have to hit the source.

While the [filter context](https://www.elastic.co/guide/en/elasticsearch/painless/8.3/painless-filter-context.html) does not have source access, the [runtime field context](https://www.elastic.co/guide/en/elasticsearch/painless/8.3/painless-runtime-fields-context.html) has access to source via `params[_source]`.

You can use a boolean runtime field along with a term query to perform the logic you want.

```auto
GET my-index/_search
{
  "runtime_mappings": {
    "tooLong": {
      "type": "boolean",
      "script": {
        "source": """
        def msg = params['_source'].get('Message');
        if (msg instanceof List) {
          emit(msg.size() == 1 && msg[0].length() >= params.maxSize);
        } else if (msg instanceof String) {
          emit(msg.length() >= params.maxSize);
        } else {
          emit(false);
        }
        """,
        "params": {"maxSize": 1000}
      }
    }
  },
  "query": {
    "term": {
      "tooLong": true
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![nestor1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nestor1/32/123438_2.png) [@nestor1](https://discuss.elastic.co/u/nestor1)\
**Post date:** [July 20, 2022, 7:56pm UTC](https://discuss.elastic.co/t/how-to-find-number-of-characters-in-a-text-field/310189/3 "2022-07-20T19:56:13Z")

</div>

Thank you, sir, this works wonderful, didn't even know about the runtime field context feature. Thanks a lot

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2022, 7:56pm UTC](https://discuss.elastic.co/t/how-to-find-number-of-characters-in-a-text-field/310189/4 "2022-08-17T19:56:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
