# Keyword field update with existing value

**URL:** <https://discuss.elastic.co/t/keyword-field-update-with-existing-value/261522>\
**Category:** Elasticsearch\
**Created:** [January 19, 2021, 10:02am UTC](https://discuss.elastic.co/t/keyword-field-update-with-existing-value/261522 "2021-01-19T10:02:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajaraman](https://avatars.discourse-cdn.com/v4/letter/r/eada6e/32.png) [@rajaraman](https://discuss.elastic.co/u/rajaraman)\
**Post date:** [January 19, 2021, 10:02am UTC](https://discuss.elastic.co/t/keyword-field-update-with-existing-value/261522/1 "2021-01-19T10:02:04Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/c/0/c0ae77e4e3113b713aa78456ecdf8e4716e39436.png)  
Hi, is it possible to update value in TEAM (keyword field) with existing value in the form ("NETWORK TEAM","DBA TEAM") when, i update , it updates as whole text.("NETWORK TEAM,DBA TEAM") please, help

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 19, 2021, 11:02am UTC](https://discuss.elastic.co/t/keyword-field-update-with-existing-value/261522/2 "2021-01-19T11:02:28Z")

</div>

Welcome!

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

Could you provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

A full reproduction script is something anyone can copy and paste in Kibana dev console, click on the run button to reproduce your use case. It will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.

---

<div class="post-metadata">

**Author:** ![rajaraman](https://avatars.discourse-cdn.com/v4/letter/r/eada6e/32.png) [@rajaraman](https://discuss.elastic.co/u/rajaraman)\
**Post date:** [January 19, 2021, 11:35am UTC](https://discuss.elastic.co/t/keyword-field-update-with-existing-value/261522/3 "2021-01-19T11:35:35Z")

</div>

Thanks for the reply sir,  
my mappings code:

````auto
PUT first_project/_mapping
{
  "properties":{
    "ALERT_ID":{
      "type":"text"
    },
    "COUNT":{
      "type":"integer"
    },
    "CINAME":{
      "type":"text"
    },
    "ENVIRONMENT":{
      "type":"text"
    },
    "IP":{
      "type":"ip"
    },
    "SEVERITY":{
      "type":"text"
    },
    "SUMMARY":{
      "type":"text"
    },
    "SOURCE":{
      "type":"text"
    },
    "SOURCE_TIME":{
      "type":"date"
    },
    "CREATED_TIME":{
      "type":"date"
    },
    "LAST_MODIFIED_TIME":{
      "type":"date"
    },
    "STATUS":{
      "type":"text"
    },
    "MODIFIED_BY":{
      "type":"text"
    },
    "TAGS":{
      "type":"keyword"
    },
    "TEAM": {
      "type": "keyword"
    }
  }
}```

 i need to update my TEAM field (keyword type) with existing value("NETWORK TEAM") and adding one more value ("DBA TEAM"), output like ("NETWORK TEAM","DBA TEAM"). when i using update query

````

````
POST first_project/_update/RV8l4XYBkg9Xo5ZNaP0x/
{
"script": {
  "source": "ctx._source.TEAM +=',DBA Team';",
  "lang": "painless"
  }
}```

````

it gives output like this ("NETWORK TEAM,DBA TEAM"), please tell suggestions to get separate value like ("NETWORK TEAM","DBA TEAM") adding separate value

---

<div class="post-metadata">

**Author:** ![rajaraman](https://avatars.discourse-cdn.com/v4/letter/r/eada6e/32.png) [@rajaraman](https://discuss.elastic.co/u/rajaraman)\
**Post date:** [January 20, 2021, 7:21am UTC](https://discuss.elastic.co/t/keyword-field-update-with-existing-value/261522/4 "2021-01-20T07:21:28Z")

</div>

I understand ("NETWORK TEAM","DBA TEAM") this update not possible, gives syntax error, i follow this update method ("NETWORK TEAM,DBA TEAM") in keyword field, remaining extraction, i will do in my code. Thanks Elastic Team for the reply.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 20, 2021, 10:57am UTC](https://discuss.elastic.co/t/keyword-field-update-with-existing-value/261522/5 "2021-01-20T10:57:18Z")

</div>

Having separate values won't change a lot the way it's indexed as everything will be flattened at the end.

So indexing:

```auto
{
  "TEAM": "foo bar"
}

```

is quite similar to:

```auto
{
  "TEAM": ["foo", "bar"]
}

```

Note the array here.

If you want to do this, you need to create an array, instead of doing string manipulations.

```auto
DELETE first_project
PUT first_project
{
  "mappings": {
    "properties": {
      "TEAM": {
        "type": "keyword"
      }
    }
  }
}
PUT first_project/_doc/1
{
  "TEAM": "foo"
}
POST first_project/_update/1/
{
  "script": {
    "source": """def result = new ArrayList();
result.add(ctx._source.TEAM);
result.add("bar");
ctx._source.TEAM =result;""",
    "lang": "painless"
  }
}
GET first_project/_doc/1

```

It gives:

```auto
{
  "_index" : "first_project",
  "_type" : "_doc",
  "_id" : "1",
  "_version" : 2,
  "_seq_no" : 1,
  "_primary_term" : 1,
  "found" : true,
  "_source" : {
    "TEAM" : [
      "foo",
      "bar"
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![rajaraman](https://avatars.discourse-cdn.com/v4/letter/r/eada6e/32.png) [@rajaraman](https://discuss.elastic.co/u/rajaraman)\
**Post date:** [January 21, 2021, 11:29am UTC](https://discuss.elastic.co/t/keyword-field-update-with-existing-value/261522/6 "2021-01-21T11:29:53Z")

</div>

Very Thanks sir, I understood this concept.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 18, 2021, 11:30am UTC](https://discuss.elastic.co/t/keyword-field-update-with-existing-value/261522/7 "2021-02-18T11:30:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
