# Kibana scripted field: doc\['some\_field'\] doesnt work when the field has a lot of data

**URL:** <https://discuss.elastic.co/t/kibana-scripted-field-doc-some-field-doesnt-work-when-the-field-has-a-lot-of-data/285106>\
**Category:** Elasticsearch\
**Tags:** painless\
**Created:** [September 24, 2021, 6:15pm UTC](https://discuss.elastic.co/t/kibana-scripted-field-doc-some-field-doesnt-work-when-the-field-has-a-lot-of-data/285106 "2021-09-24T18:15:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Felipsz](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@Felipsz](https://discuss.elastic.co/u/Felipsz)\
**Post date:** [September 24, 2021, 6:15pm UTC](https://discuss.elastic.co/t/kibana-scripted-field-doc-some-field-doesnt-work-when-the-field-has-a-lot-of-data/285106/1 "2021-09-24T18:15:34Z")

</div>

Hi everyone,

Im creating some scripted fields to improve the visualization of the data that comes into Kibana 7.5.

I have a big field that its a JSON, and it has a lot of data, and i want to separate this data in multiple scripted fields. To exemplify, lets say that the JSON looks something like this:

```auto
{
  "data": {
    "data1": "123",
    "data2": "plane",
    "data3": "car",
     ......
    "dataXX": "321",
   }
}

```

And i want scripted fields to look like this: data1: 123, data2: plane, data3: car, dataXX: 321.

I know that the scripted field doesnt have an API to deal with JSON, so what i do is just use the .substring function to split the string, no problem at all. The thing is, when i use the doc['my\_json\_field.keyword'].value function only works when the data is small.

To exemplify, i've created the scripted field "data1", you can see the code of this script below, it just copies the data from the field "proxyRequest.message.content"

```auto
def data1 = doc['proxyRequest.message.content.keyword'];
return data1;

```

You can see the outputs below, when i have some big data, and when i have a smaller one (i've hidden the data with this red lines for obvious reasons):

 ![problem](https://us1.discourse-cdn.com/elastic/original/3X/a/e/ae78b191c1d10e9d59f0ffb03550eb04f230374c.png)

I've tried to use params['\_source']['proxyRequest.message.content'], but it doesnt output any data at all.

Any ideias of how to make the doc['some\_field'] work for big amounts of data?

Thanks.

---

<div class="post-metadata">

**Author:** ![Felipsz](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@Felipsz](https://discuss.elastic.co/u/Felipsz)\
**Post date:** [September 24, 2021, 6:22pm UTC](https://discuss.elastic.co/t/kibana-scripted-field-doc-some-field-doesnt-work-when-the-field-has-a-lot-of-data/285106/2 "2021-09-24T18:22:28Z")

</div>

Just forgot to add, I've seen some people with the same issue as me, in the following topics:  
[https://discuss.elastic.co/t/scripted-field-read-field-data-from-a-document-using-doc-some-field-value-return-null-in-some-cases/187385/8](https://discuss.elastic.co/t/scripted-field-read-field-data-from-a-document-using-doc-some-field-value-return-null-in-some-cases/187385/8)

> [@Scripted field: Read field data from a document using doc\['some\_filed'\].value statement is not working for bigger field data](https://discuss.elastic.co/t/scripted-field-read-field-data-from-a-document-using-doc-some-filed-value-statement-is-not-working-for-bigger-field-data/113775):
>
> Hi Everyone, I am new to kibana. Need your help to solve the following problem which am facing from a day. I am working on kibana scripted field approach to transform a field value by accessing it using "doc[some\_field].value" statement and perform some computation using groovy script then finally return a new field. Problem: "doc[some\_field].value" is returning null in-case if the field value is large. Kibana version is : 6.0.1 field name: message.keyword =\> doc[message.keyword].value langu…

---

<div class="post-metadata">

**Author:** ![Felipsz](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@Felipsz](https://discuss.elastic.co/u/Felipsz)\
**Post date:** [September 27, 2021, 4:33pm UTC](https://discuss.elastic.co/t/kibana-scripted-field-doc-some-field-doesnt-work-when-the-field-has-a-lot-of-data/285106/3 "2021-09-27T16:33:02Z")

</div>

Hi,

Any help from anyone?

Im starting to think that this issue is caused by a limitation of Kibana, but im not sure.

---

<div class="post-metadata">

**Author:** ![stu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stu/32/75063_2.png) [@stu](https://discuss.elastic.co/u/stu)\
**Post date:** [September 27, 2021, 5:31pm UTC](https://discuss.elastic.co/t/kibana-scripted-field-doc-some-field-doesnt-work-when-the-field-has-a-lot-of-data/285106/4 "2021-09-27T17:31:06Z")

</div>

Can you post your mappings? I'm guessing you have [`ignore_above`](https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-above.html).

> I've tried to use params['\_source']['proxyRequest.message.content'], but it doesnt output any data at all.

I'm wondering if `params['_source']['proxyRequest']['message']['content']` works for you?

The `_source` contains the document closer to the raw JSON, whereas `doc` flattens the document, which is why the syntax is `doc['proxyRequest.message.content']` for `doc`.

You can look at the contents of `params['_source']` by doing `Debug.explain(params['_source'])`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2021, 5:31pm UTC](https://discuss.elastic.co/t/kibana-scripted-field-doc-some-field-doesnt-work-when-the-field-has-a-lot-of-data/285106/5 "2021-10-25T17:31:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
