# Missing fields and value on Kibana runtime fields

**URL:** <https://discuss.elastic.co/t/missing-fields-and-value-on-kibana-runtime-fields/359034>\
**Category:** Elasticsearch\
**Tags:** runtime-fields\
**Created:** [May 8, 2024, 8:38am UTC](https://discuss.elastic.co/t/missing-fields-and-value-on-kibana-runtime-fields/359034 "2024-05-08T08:38:08Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![imst](https://avatars.discourse-cdn.com/v4/letter/i/f6c823/32.png) [@imst](https://discuss.elastic.co/u/imst)\
**Post date:** [May 8, 2024, 8:38am UTC](https://discuss.elastic.co/t/missing-fields-and-value-on-kibana-runtime-fields/359034/1 "2024-05-08T08:38:08Z")

</div>

Hi,

I was attempting to creating field on fly in Kibana using runtime fields  
The following is my attempt try to temporarily label the value of the 'aws.waf.id' field as 'tmp' fields in Discover

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/35378dcb26bfa41b89e8f520b7208f627f13f036.png)

Both field and value of 'aws.waf.id' does exist but somehow the script shows that the field is missing or null.

However if I tried to access the field using "params.\_source.aws.waf.id" in DEV tool, I was able to retrieve the value.  
The request I pass on DEV tools

```auto
GET .ds-logs-aws.waf-default-2024.04.25-000973/_search
{
  "size": 1,
  "query": {
      "match_all": {}
  },
  "script_fields": {
    "FIELD": {
      "script": "params._source.aws.waf.id"
    }
  }
}

```

The respond I got

```auto
{
  "took": 5,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 10000,
      "relation": "gte"
    },
    "max_score": 1,
    "hits": [
      {
        "_index": ".ds-logs-aws.waf-default-2024.04.25-000973",
        "_id": "0c0e0c302f-000001301929",
        "_score": 1,
        "fields": {
          "FIELD": [
            "regional/webacl/<REDACTED>/<REDACTED>"
          ]
        }
      }
    ]
  }
}

```

The elastic was set up using integration WAF (ref: [AWS WAF | Documentation](https://docs.elastic.co/en/integrations/aws/waf)).  
Is there any explanation for this ? Thanks !
