# Kibana inline script

**URL:** <https://discuss.elastic.co/t/kibana-inline-script/245331>\
**Category:** Kibana\
**Created:** [August 18, 2020, 2:05am UTC](https://discuss.elastic.co/t/kibana-inline-script/245331 "2020-08-18T02:05:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![kinlee](https://avatars.discourse-cdn.com/v4/letter/k/838e76/32.png) [@kinlee](https://discuss.elastic.co/u/kinlee)\
**Post date:** [August 18, 2020, 2:05am UTC](https://discuss.elastic.co/t/kibana-inline-script/245331/1 "2020-08-18T02:05:26Z")

</div>

As per docu, it says "If you use Kibana, set `script.allowed_types` to `both` or `inline` . Some Kibana features rely on inline scripts and do not function as expected if Elasticsearch does not allow inline scripts."

what all features of Kibana depend on "inline script" to function well????

Thanking you

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [August 18, 2020, 6:53am UTC](https://discuss.elastic.co/t/kibana-inline-script/245331/2 "2020-08-18T06:53:43Z")

</div>

Hi

For example if you want to use scripted fields in Kibana, inline scripts need to be enabled.

[https://www.elastic.co/guide/en/kibana/current/scripted-fields.html](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html)

Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![kinlee](https://avatars.discourse-cdn.com/v4/letter/k/838e76/32.png) [@kinlee](https://discuss.elastic.co/u/kinlee)\
**Post date:** [August 18, 2020, 11:06am UTC](https://discuss.elastic.co/t/kibana-inline-script/245331/3 "2020-08-18T11:06:30Z")

</div>

I found few issues reported when inline scripts are disabled such as Timelion not working, Elasticsearch watcher condition and Taskmanager failing.

Does that mean that apart from scripted fields all other feature of Kibana will work? And also, please correct me if I am wrong, I understood that it is safe to use sandboxed language and the risk is with another script language like Groovy or python. Or do we still have to follow scripting security for sandboxed language script as well.

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [September 1, 2020, 2:04pm UTC](https://discuss.elastic.co/t/kibana-inline-script/245331/4 "2020-09-01T14:04:00Z")

</div>

There is also usage in our saved\_object service, our task manager, and many more. I've checked, couldn't even install an index pattern when setting `script.allowed_types` to `none`.

About security, our scripting language painless, was designed for security and speed, and it replaced other scripting languages as default in Elasticsearch.

> Or do we still have to follow scripting security for sandboxed language script as well.

Could you elaborate what scripting security you mean?

Many thx & Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![kinlee](https://avatars.discourse-cdn.com/v4/letter/k/838e76/32.png) [@kinlee](https://discuss.elastic.co/u/kinlee)\
**Post date:** [September 1, 2020, 11:18pm UTC](https://discuss.elastic.co/t/kibana-inline-script/245331/5 "2020-09-01T23:18:01Z")

</div>

Hy Thank you so much for your help. I was wondering if there is a way I can enable only painless lang and disable all other lang on Elasticsearch for inline and stored.

BTW, is Lucene expression, Mustashe are different from painless script or both Lucene and Mustashe is an addition feature for painless lang.

Is there a way I can disable my client from using java lang with scripting engine??

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [September 2, 2020, 12:46am UTC](https://discuss.elastic.co/t/kibana-inline-script/245331/6 "2020-09-02T00:46:51Z")

</div>

The only [scripting language that is built-in](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-scripting.html) is Painless. Painless uses a [shared API](https://www.elastic.co/guide/en/elasticsearch/painless/7.9/painless-api-reference-shared.html) based on Java classes.

Are you asking if there is the ability to disable the shared API Java classes but keep Painless scripting?

---

<div class="post-metadata">

**Author:** ![kinlee](https://avatars.discourse-cdn.com/v4/letter/k/838e76/32.png) [@kinlee](https://discuss.elastic.co/u/kinlee)\
**Post date:** [September 2, 2020, 1:00am UTC](https://discuss.elastic.co/t/kibana-inline-script/245331/7 "2020-09-02T01:00:09Z")

</div>

Yes... just enable painless scripting and disable all.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2020, 1:00am UTC](https://discuss.elastic.co/t/kibana-inline-script/245331/8 "2020-09-30T01:00:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
