# Painless script query giving error for "message" field and working fine for other fields in filebeats

**URL:** <https://discuss.elastic.co/t/painless-script-query-giving-error-for-message-field-and-working-fine-for-other-fields-in-filebeats/161981>\
**Category:** Kibana\
**Created:** [December 24, 2018, 8:08am UTC](https://discuss.elastic.co/t/painless-script-query-giving-error-for-message-field-and-working-fine-for-other-fields-in-filebeats/161981 "2018-12-24T08:08:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sid\_nikhil](https://avatars.discourse-cdn.com/v4/letter/s/f9ae1b/32.png) [@sid\_nikhil](https://discuss.elastic.co/u/sid_nikhil)\
**Post date:** [December 24, 2018, 8:08am UTC](https://discuss.elastic.co/t/painless-script-query-giving-error-for-message-field-and-working-fine-for-other-fields-in-filebeats/161981/1 "2018-12-24T08:08:27Z")

</div>

I have 2 fields of **string** type in filebeat index:

1. **\_index** = kibana\_sample\_data\_flights  
**(This field is marked aggregatable by default)**

2. **message** : 2018-12-21 02:31:31,792;INFO ;XSYD.2.5.0.1a5e8-uye1-9d87-8744-5343db306cd8;1;0;;GETCONFPRO;0;

I want to split by ; and get the timestamp  
**(This field is marked non-aggregatable by default , i made it as aggregatable)**

Now I create a **scripted field** called **firstword** (i am splitting the string( **message** or **\_index** ) using underscore as delimiter and getting the firstword)

When i try for **\_index** field, **the _painless query_ works as expected:**

```auto
String[] parts = /_/.split(doc['_index'].value);
return parts[0]

```

But When i try for **message** field, **i get error ( 3 of 6 shards failed) when in click on Discover:**

```auto
String[] parts = /;/.split(doc['message'].value);
return parts[0]

```

Furthermore even simple parsing of message field using below query

`return doc['message'].value;`

is giving same error( 3 of 6 shards failed):

I am beginner to ELK . Can someone please help me resolve this.  
Thanks a lot in advance

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [December 24, 2018, 9:09am UTC](https://discuss.elastic.co/t/painless-script-query-giving-error-for-message-field-and-working-fine-for-other-fields-in-filebeats/161981/2 "2018-12-24T09:09:47Z")

</div>

If you changed it to aggregatable after the data was ingested,this will only apply to further data points that are ingested. You need to set the field as aggregatable in the template before the data is ingested in ES as the aggregation is done at ingest time.

---

<div class="post-metadata">

**Author:** ![sid\_nikhil](https://avatars.discourse-cdn.com/v4/letter/s/f9ae1b/32.png) [@sid\_nikhil](https://discuss.elastic.co/u/sid_nikhil)\
**Post date:** [December 24, 2018, 9:31am UTC](https://discuss.elastic.co/t/painless-script-query-giving-error-for-message-field-and-working-fine-for-other-fields-in-filebeats/161981/3 "2018-12-24T09:31:38Z")

</div>

I added new data .Even with that its not working  
Do you mean making the field aggregatable is the correct approach to solve above problem ?  
I am very new to ELK . Can you please guide me how to set the field aggregatable in the template **(by template do you mean filebeat.yml ? )** before the data is ingested .  
Should i delete existing index ?  
Will be thankful if you can mention the steps .

---

<div class="post-metadata">

**Author:** ![sid\_nikhil](https://avatars.discourse-cdn.com/v4/letter/s/f9ae1b/32.png) [@sid\_nikhil](https://discuss.elastic.co/u/sid_nikhil)\
**Post date:** [December 26, 2018, 9:36am UTC](https://discuss.elastic.co/t/painless-script-query-giving-error-for-message-field-and-working-fine-for-other-fields-in-filebeats/161981/4 "2018-12-26T09:36:01Z")

</div>

Can someone please guide how to fix this ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 23, 2019, 9:36am UTC](https://discuss.elastic.co/t/painless-script-query-giving-error-for-message-field-and-working-fine-for-other-fields-in-filebeats/161981/5 "2019-01-23T09:36:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
