# Painless script to store field/column values in an array

**URL:** <https://discuss.elastic.co/t/painless-script-to-store-field-column-values-in-an-array/114706>\
**Category:** Elasticsearch\
**Created:** [January 9, 2018, 1:13pm UTC](https://discuss.elastic.co/t/painless-script-to-store-field-column-values-in-an-array/114706 "2018-01-09T13:13:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [January 9, 2018, 1:13pm UTC](https://discuss.elastic.co/t/painless-script-to-store-field-column-values-in-an-array/114706/1 "2018-01-09T13:13:45Z")

</div>

Hi All,  
Is there a way to store all field/column values in an array through painless script.  
request to share some sample script.

i want to calculate count of each unique value in a column/field, similar to group by option.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 9, 2018, 2:49pm UTC](https://discuss.elastic.co/t/painless-script-to-store-field-column-values-in-an-array/114706/2 "2018-01-09T14:49:28Z")

</div>

Why not using this: [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-cardinality-aggregation.html)?

---

<div class="post-metadata">

**Author:** ![scch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scch/32/25504_2.png) [@scch](https://discuss.elastic.co/u/scch)\
**Post date:** [January 10, 2018, 5:39am UTC](https://discuss.elastic.co/t/painless-script-to-store-field-column-values-in-an-array/114706/3 "2018-01-10T05:39:10Z")

</div>

Hi David,  
Thank you for revert... 🙂

i am able to achieve this in elasticsearch console with DSL query + Script below is the code.

However the requirement is, field(riskscore) should be dynamic based on time period. because if time period change, value\_count should also change hence facing challenge and thought to create a scripted field.  
Request help..on how to store all field/column values in an array through painless script.  
or any other workaround...

POST /sat4\*/\_search  
{  
"size": 0,  
"aggs" : {  
"dft" : {  
"date\_histogram" : {  
"field" : "@timestamp",  
"interval" : "day"  
},  
"aggs" : {  
"total\_count": {  
"value\_count": {  
"field": "Anomaly.keyword"  
}  
},  
"antype": {  
"filter": {  
"term": {  
"Anomaly.keyword": "CSSRR"  
}  
},  
"aggs": {  
"mycount": {  
"value\_count": {  
"field": "Anomaly.keyword"  
}  
}  
}  
},  
"riskscore": {  
"bucket\_script": {  
"buckets\_path": {  
"sc1": "antype\>mycount",  
"sc2": "total\_count"  
},  
"script": "if (params.sc1 \> 100) {10} else {1}"  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2018, 5:39am UTC](https://discuss.elastic.co/t/painless-script-to-store-field-column-values-in-an-array/114706/4 "2018-02-07T05:39:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
