# Map runtime field

**URL:** <https://discuss.elastic.co/t/map-runtime-field/263902>\
**Category:** Elasticsearch\
**Created:** [February 10, 2021, 4:37pm UTC](https://discuss.elastic.co/t/map-runtime-field/263902 "2021-02-10T16:37:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![paasi6666](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paasi6666/32/77617_2.png) [@paasi6666](https://discuss.elastic.co/u/paasi6666)\
**Post date:** [February 10, 2021, 4:37pm UTC](https://discuss.elastic.co/t/map-runtime-field/263902/1 "2021-02-10T16:37:12Z")

</div>

I got following query which should create a new field:

```
PUT filebeat*
{
  "mappings": {
    "runtime": {
      "sophos.utm.to.domain": {
        "type": "keyword",
        "script": {
          "source": "emit(def m = /@((?:(?:[a-z0-9](?:[a-z0-9-]*[a-z0-9])?\\.)+[a-z0-9](?:[a-z0-9-]*[a-z0-9])?|\\[(?:(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9]))\\.){3}(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9])|[a-z0-9-]*[a-z0-9]:(?:[\\x01-\\x08\\x0b\\x0c\\x0e-\\x1f\\x21-\\x5a\\x53-\\x7f]|\\\\[\\x01-\\x09\\x0b\\x0c\\x0e-\\x7f])+)\\]))/.matcher(doc['sophos.utm.to'].value); return m.find() ? m.group(1): '';)"
        }
      }
    }
  }
}

```

I get following error:

```
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "action [indices:admin/create] is unauthorized for user [test]"
      }
    ],
    "type" : "security_exception",
    "reason" : "action [indices:admin/create] is unauthorized for user [test]",
    "caused_by" : {
      "type" : "illegal_state_exception",
      "reason" : "There are no external requests known to support wildcards that don't support replacing their indices"
    }
  },
  "status" : 403
}

```

The role superuser is assigned to the "test" user

---

<div class="post-metadata">

**Author:** ![aj.pahl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aj.pahl/32/58989_2.png) [@aj.pahl](https://discuss.elastic.co/u/aj.pahl)\
**Post date:** [February 19, 2021, 12:50am UTC](https://discuss.elastic.co/t/map-runtime-field/263902/2 "2021-02-19T00:50:47Z")

</div>

@paasi6666 Do you get the same error if you applied your mapping to a single index versus a wildcard?

Also, if you need to apply this to future Filebeat indices, perhaps applying this to the index template for that pattern might be useful.

> **[Index templates | Elasticsearch Reference \[7.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.11/index-templates.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2021, 12:50am UTC](https://discuss.elastic.co/t/map-runtime-field/263902/3 "2021-03-19T00:50:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
