# HTTP request from Painless script?

**URL:** <https://discuss.elastic.co/t/http-request-from-painless-script/308884>\
**Category:** Elasticsearch\
**Tags:** painless\
**Created:** [July 5, 2022, 9:30am UTC](https://discuss.elastic.co/t/http-request-from-painless-script/308884 "2022-07-05T09:30:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kennyprisjakt](https://avatars.discourse-cdn.com/v4/letter/k/e19b73/32.png) [@kennyprisjakt](https://discuss.elastic.co/u/kennyprisjakt)\
**Post date:** [July 5, 2022, 9:30am UTC](https://discuss.elastic.co/t/http-request-from-painless-script/308884/1 "2022-07-05T09:30:39Z")

</div>

Hey,

I'm currently looking for a way to do HTTP requests from a Painless script.  
Is that possible? Because i have not seen any examples of it when searching for it.

**Use case:**  
Basically what i'm trying to do is runtime fields where i want to generate image and link fields, and to get this data i need to do API calls. It's not something used in prod, just for internal use (for Quepid).

**Here is an example of how i want to execute the script:**

```auto
PUT my-index/_mapping
{
  "runtime": {
    "image": {
      "type": "keyword",
      "script": {
        "source":
        """
          // HTTP request should happen here and then emit the image URL
        """
      }
    },
    "link": {
      "type": "keyword",
      "script": {
        "source":
        """
          // HTTP request should happen here and then emit the link URL
        """
      }
    },
  }
}

```

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 5, 2022, 9:56am UTC](https://discuss.elastic.co/t/http-request-from-painless-script/308884/2 "2022-07-05T09:56:05Z")

</div>

No, that is not possible. Apart from it being a very bad idea as it would have a huge impact on performance, I believe the security manager would not allow it as it would be a security risk.

---

<div class="post-metadata">

**Author:** ![kennyprisjakt](https://avatars.discourse-cdn.com/v4/letter/k/e19b73/32.png) [@kennyprisjakt](https://discuss.elastic.co/u/kennyprisjakt)\
**Post date:** [July 5, 2022, 10:19am UTC](https://discuss.elastic.co/t/http-request-from-painless-script/308884/3 "2022-07-05T10:19:59Z")

</div>

Thanks for the response! I will go a head with a different approach in that case.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2022, 10:20am UTC](https://discuss.elastic.co/t/http-request-from-painless-script/308884/4 "2022-08-02T10:20:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
