# Painless script - check for null

**URL:** <https://discuss.elastic.co/t/painless-script-check-for-null/122176>\
**Category:** Elasticsearch\
**Created:** [March 2, 2018, 2:46am UTC](https://discuss.elastic.co/t/painless-script-check-for-null/122176 "2018-03-02T02:46:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bluemalkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluemalkin/32/28162_2.png) [@bluemalkin](https://discuss.elastic.co/u/bluemalkin)\
**Post date:** [March 2, 2018, 2:46am UTC](https://discuss.elastic.co/t/painless-script-check-for-null/122176/1 "2018-03-02T02:46:58Z")

</div>

Hi,

I have a painless script custom field using regex:

> if (doc['message.keyword'].value != null) {  
> def m = /((GET|POST|PUT)\s{1}(/v1/[\w/-]+))(?|\s){1}/.matcher(doc['message.keyword'].value);  
> if (m.find()) { return m.group(1) } else { return "No match" }  
> }  
> else { return "NULL"}

It works mostly but I also get lots of messages which return NULL even though there IS a message.  
For example this returned NULL

> message: x.x.x.x - - [02/Mar/2018:13:42:10 +1100] "GET /v1/search/products?  
> api\_key=\*\*\*\*\*\*\*\*\*\*\* HTTP/1.1" 200 7952 "-" "Java/1.8.0\_31 RestSDK/1.4.5"

Any idea why it's not matching doc['message.keyword'].value != null ?

Thanks,

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [March 3, 2018, 4:45pm UTC](https://discuss.elastic.co/t/painless-script-check-for-null/122176/2 "2018-03-03T16:45:50Z")

</div>

Are you escaping the `/` inside the regex? I'm surprised that does not throw a syntax error...

---

<div class="post-metadata">

**Author:** ![bluemalkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluemalkin/32/28162_2.png) [@bluemalkin](https://discuss.elastic.co/u/bluemalkin)\
**Post date:** [March 9, 2018, 5:24am UTC](https://discuss.elastic.co/t/painless-script-check-for-null/122176/3 "2018-03-09T05:24:22Z")

</div>

Sorry I am escaping the / it's the rendering here that removes them

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [March 9, 2018, 5:50am UTC](https://discuss.elastic.co/t/painless-script-check-for-null/122176/4 "2018-03-09T05:50:07Z")

</div>

What are the mappings for your index? You should only get null there if no values exist for the document for that field, but that could happen if you have docvalues disabled. What version of elasticsearch is this?

---

<div class="post-metadata">

**Author:** ![bluemalkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluemalkin/32/28162_2.png) [@bluemalkin](https://discuss.elastic.co/u/bluemalkin)\
**Post date:** [March 12, 2018, 3:29am UTC](https://discuss.elastic.co/t/painless-script-check-for-null/122176/5 "2018-03-12T03:29:25Z")

</div>

I'm using the docker ES version 6.2.1

Mapping: [https://pastebin.com/hw9fuK3T](https://pastebin.com/hw9fuK3T)

It returns null for items that do have a docvalue "messages", very strange.

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [March 17, 2018, 6:23am UTC](https://discuss.elastic.co/t/painless-script-check-for-null/122176/6 "2018-03-17T06:23:46Z")

</div>

Are you sure _every_ document has a value for the field? Also, in your example before, your field was `message.keyword`, but in your last response it was `messages`. Can you run an [exists query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-exists-query.html) for the field name you are using and compare the total hits with those from a [match all query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-match-all-query.html)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2018, 6:23am UTC](https://discuss.elastic.co/t/painless-script-check-for-null/122176/7 "2018-04-14T06:23:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
