# New scripted fields causes shards failed

**URL:** <https://discuss.elastic.co/t/new-scripted-fields-causes-shards-failed/222465>\
**Category:** Kibana\
**Created:** [March 6, 2020, 1:30pm UTC](https://discuss.elastic.co/t/new-scripted-fields-causes-shards-failed/222465 "2020-03-06T13:30:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![beam022](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beam022/32/63962_2.png) [@beam022](https://discuss.elastic.co/u/beam022)\
**Post date:** [March 6, 2020, 1:30pm UTC](https://discuss.elastic.co/t/new-scripted-fields-causes-shards-failed/222465/1 "2020-03-06T13:30:19Z")

</div>

Hi, I've defined a new scripted field that extracts a substring based on a regex. Immediately after adding that field, I've been observing warning messages on our Kibana and it's impossible to look at any logs right now.

```
Courier fetch: 251 of 2203 shards failed.

```

Here's the scripted field (painless, string, default format):

```
if (!doc["@message"].empty) {
  def msg = doc["@message"].value;
  def match = /([A-Z]L[A-Z]M?\d+R\d+)/.matcher(msg);
  if (match.matches()) {
    return match.group(1)
  }
}

```

Could someone help me with this please? What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 12, 2020, 2:52pm UTC](https://discuss.elastic.co/t/new-scripted-fields-causes-shards-failed/222465/2 "2020-03-12T14:52:41Z")

</div>

Hi,

Can you use the scripted field testing tool that you have in the scripted field editor in Kibana? That should show what values you get or what error it throws out, more verbose.  
That shards failed is a generic error when a scripted field isn't working properly.

---

<div class="post-metadata">

**Author:** ![beam022](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/beam022/32/63962_2.png) [@beam022](https://discuss.elastic.co/u/beam022)\
**Post date:** [March 12, 2020, 3:32pm UTC](https://discuss.elastic.co/t/new-scripted-fields-causes-shards-failed/222465/3 "2020-03-12T15:32:47Z")

</div>

Hi Marius, thanks for taking the time to reply.  
I'd gladly do that, but I don't see such option there:

 ![Screenshot from 2020-03-12 16-31-23](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3d1a1a1deb4a68ccc60dfd9f4a14dd6850b0f71c.png)

We're using Kibana 6.3.1  
Where should I look for that option?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 12, 2020, 3:35pm UTC](https://discuss.elastic.co/t/new-scripted-fields-causes-shards-failed/222465/4 "2020-03-12T15:35:06Z")

</div>

Aww, damn. The feature was added in 6.4.0: [https://github.com/elastic/kibana/pull/20746](https://github.com/elastic/kibana/pull/20746)

There should be a detailed log message about the error in the Elasticsearch logs. Can you check there and post the error message?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2020, 3:35pm UTC](https://discuss.elastic.co/t/new-scripted-fields-causes-shards-failed/222465/5 "2020-04-09T15:35:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
