# How to use the script field for string

**URL:** <https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155>\
**Category:** Kibana\
**Created:** [March 18, 2020, 4:33pm UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155 "2020-03-18T16:33:40Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![somya](https://avatars.discourse-cdn.com/v4/letter/s/e0b2c6/32.png) [@somya](https://discuss.elastic.co/u/somya)\
**Post date:** [March 18, 2020, 4:33pm UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/1 "2020-03-18T16:33:40Z")

</div>

I have a message index pattern which has the below string

[INFO][callback][views][2020-03-18 13:06:21][xce\_web][PROD][user\_\_id\_1010510-18-03-2020-13-03-26][167]:For ABC start time is 2020-03-18 13:03:26.999778 & end time is 2020-03-18 13:06:21.507542 and pipeline takes 174507 milliseconds to complete.

How to get the substring i.e user\_id and 174507 in 2 diferent script fields.

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [March 18, 2020, 8:25pm UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/2 "2020-03-18T20:25:24Z")

</div>

Hi @somya,

Welcome to our community! Here is a blog post shows how to get a substring:

> **[Using Painless in Kibana scripted fields](https://www.elastic.co/blog/using-painless-kibana-scripted-fields)**
>
> This blog presents common use cases for Kibana scripted fields, and walks user through how to create scripted fields in a newly set-up Elastic Cloud instance.

Hope this helps,

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![somya](https://avatars.discourse-cdn.com/v4/letter/s/e0b2c6/32.png) [@somya](https://discuss.elastic.co/u/somya)\
**Post date:** [March 19, 2020, 3:37pm UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/3 "2020-03-19T15:37:54Z")

</div>

Hello @LizaD

Thanks for the reply. I tried using the below script  
def path = doc['message.keyword'].value;  
if (path != null) {  
int lastSlashIndex = path.IndexOf('[doc');  
if (lastSlashIndex \> 0) {  
return path.substring(lastSlashIndex,lastSlashIndex +10);  
}  
}  
return "";

But all in vain after saving and going to discover.it is showing the warning This field is present in your elasticsearch mapping but not in any documents in the search results. You may still be able to visualize or search on it.

---

<div class="post-metadata">

**Author:** ![stu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stu/32/75063_2.png) [@stu](https://discuss.elastic.co/u/stu)\
**Post date:** [March 19, 2020, 10:37pm UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/4 "2020-03-19T22:37:43Z")

</div>

Hi @somya

Based on the input, I slightly modified the script:

```auto
def path = doc['message.keyword'].value;
String userIdPrefix = '[user__id_';
int userIdLen = 7;
if (path != null) {
  int lastSlashIndex = path.indexOf(userIdPrefix);
  if (lastSlashIndex > 0) {
    return path.substring(lastSlashIndex + userIdPrefix.length(), lastSlashIndex + userIdPrefix.length() + userIdLen);
  }
}
return "";

```

With your input, that returns `1010510` as the user\_id. I didn't see `'[doc'` in your sample input, so I replaced it with `[user__id_` and I assumed your userId was always length 7.

**IMPORTANT** if you are modifying your scripted field in the kibana scripted field editor, you **MUST** refresh discover before it will use the updated script.

Kibana caches the scripted fields for an index when you load Discover.

---

<div class="post-metadata">

**Author:** ![somya](https://avatars.discourse-cdn.com/v4/letter/s/e0b2c6/32.png) [@somya](https://discuss.elastic.co/u/somya)\
**Post date:** [March 20, 2020, 10:58am UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/5 "2020-03-20T10:58:18Z")

</div>

Hello Stuart Hello Liza,

It seems the **message** field is of **text** type. Will this script will work on this.  
If no please provide your suggestion

Regards,  
Somya Chawla

---

<div class="post-metadata">

**Author:** ![somya](https://avatars.discourse-cdn.com/v4/letter/s/e0b2c6/32.png) [@somya](https://discuss.elastic.co/u/somya)\
**Post date:** [March 20, 2020, 11:00am UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/6 "2020-03-20T11:00:01Z")

</div>

Is there any way to export the saved search data in CSV format from UI or from API

---

<div class="post-metadata">

**Author:** ![somya](https://avatars.discourse-cdn.com/v4/letter/s/e0b2c6/32.png) [@somya](https://discuss.elastic.co/u/somya)\
**Post date:** [March 22, 2020, 7:48pm UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/7 "2020-03-22T19:48:52Z")

</div>

@stu @LizaD please provide your inputs for above query

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [March 23, 2020, 3:07pm UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/8 "2020-03-23T15:07:03Z")

</div>

Hi @somya

For the CSV question, you can save your data into CSV from Discover -\> Share -\> CSV Reports.

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![stu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stu/32/75063_2.png) [@stu](https://discuss.elastic.co/u/stu)\
**Post date:** [March 23, 2020, 9:48pm UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/9 "2020-03-23T21:48:49Z")

</div>

> It seems the **message** field is of **text** type. Will this script will work on this.

You'd have to change  
`def path = doc['message.keyword'].value;`  
to  
`def path = params['_source']['message'];`  
if [field data](https://www.elastic.co/guide/en/elasticsearch/reference/current/fielddata.html) is disabled. This change accesses the [`_source`](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-source-field.html) to get at the raw data.

However, if field data is enabled (and depending how it is tokenized), then `doc['message']` will be a list of strings, so you'll have to look for values in that start with `user__id_`. Here's one way you can do that:

```auto
def path = doc['message'];
for (String m: path) {
    if (m.startsWith('user__id_')) {
        // returns user__id_1010510, use the techniques above to extract 1010510
        return m;
    }
}
return "";

```

Our [Field Context](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-field-context.html) documentation may be helpful to you.

> please provide your inputs for above query.

I am using the example log line you provided in your initial post.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2020, 10:02pm UTC](https://discuss.elastic.co/t/how-to-use-the-script-field-for-string/224155/10 "2020-04-20T22:02:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
