# Painless Scripted Field

**URL:** <https://discuss.elastic.co/t/painless-scripted-field/100052>\
**Category:** Kibana\
**Created:** [September 11, 2017, 12:44pm UTC](https://discuss.elastic.co/t/painless-scripted-field/100052 "2017-09-11T12:44:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [September 11, 2017, 12:44pm UTC](https://discuss.elastic.co/t/painless-scripted-field/100052/1 "2017-09-11T12:44:45Z")

</div>

Hello,

I can't make it work my scripted painless field.

Here some lines example :

```
xxx|code_z|octets|xxx|xxx
  X|11|500|X|X
  X|12|40|X|X
  X|13|5|X|X
  X|14,4|240|X|X

```

11,12,13,14 =\> Same zone but she has différents codes. (all of these codes form the primary zone)  
500,40,5,240 =\> Octets use

So, i want create graphic with the total octets (here 500 + 40 + 5 + 240 = **785** ) by **zone**

I thought this :

```
if (doc['code_z'].value == '11' || doc['code_z'].value == '12' || doc['code_z'].value == '13' || doc['code_z'].value == '14,4' ) {
 return doc['octets'].value
}
return 0

```

But it's doesn't work 😕 Look at this blank graph ...:

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/4/5/452e47b519d1e81d6cf2db0958fc521576b289e3.JPG)

I know that is very difficult.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [September 11, 2017, 8:42pm UTC](https://discuss.elastic.co/t/painless-scripted-field/100052/2 "2017-09-11T20:42:00Z")

</div>

Instead of returning the `octets` value in your script, return some unique identifier for the zone that the conditional matches. Then on your visualization's x-axis you can do a terms agg on the scripted field which will get you the split by zone. The y-axis metric would be a simple sum aggregation on the `octets` field.

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [September 12, 2017, 9:07am UTC](https://discuss.elastic.co/t/painless-scripted-field/100052/3 "2017-09-12T09:07:59Z")

</div>

> [@Bargs](#):
>
> Instead of returning the octets value in your script, return some unique identifier for the zone that the conditional matches. Then on your visualization's x-axis you can do a terms agg on the scripted field which will get you the split by zone. The y-axis metric would be a simple sum aggregation on the octets field.

Humm, i don't understand.

how can do that ?

I want the sum of the bytes on a single curve for the set of chosen codes

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [September 12, 2017, 9:33am UTC](https://discuss.elastic.co/t/painless-scripted-field/100052/4 "2017-09-12T09:33:03Z")

</div>

I have an early solution @Bargs . Directly in kibana visualize :

Sum of octets (X-axis), timestamp on Y-axis and split series by terms (so this is codes zones : z\_code).  
You can see that my graph is split into multiple curve (because it's have many code) :

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f27e0979ab56687c09f392892beea5282d98ebe.JPG)

Now, i Use json filter :

```
{
  "query": {
    "constant_score": {
      "filter": {
        "match": {
          "z_code": "14"
        }
      }
    }
  },
  "aggs": {
    "sumcustom": {
      "sum": {
        "field": "AmountVol"
      }
    }
  }
}

```

So, i have configure only one z\_code field, so want add multiple z\_code at my json but i don't how to make that . Here ma graph with json filter :

 ![Capture2](https://us1.discourse-cdn.com/elastic/original/3X/6/1/6185e3817f9c00b16c9c5141c459e143551a0bfa.JPG)

So, how to add multiple z\_code at my json filter ? :

```
{
      "query": {
        "constant_score": {
          "filter": {
            "match": {
              "z_code": "14"
            },
            "match": {
              "z_code": "11"
        }
          }
        }
      },
      "aggs": {
        "sumcustom": {
          "sum": {
            "field": "AmountVol"
          }
        }
      }
    }

```

or

```
{
  "query": {
    "constant_score": {
      "filter": {
        "match": {
          "PLMNid": [
            "11",
            "12",
            "13"
          ]
        }
      }
    }
  },
  "aggs": {
    "sumnat": {
      "sum": {
        "field": "AmountVol"
      }
    }
  }
}

```

But doesn't work these methods  
In first case : it take only one of code  
In second case : i have error message :`[illegal_state_exception] Can't get text on a START_ARRAY`

Can you show how to ?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [September 12, 2017, 3:13pm UTC](https://discuss.elastic.co/t/painless-scripted-field/100052/5 "2017-09-12T15:13:43Z")

</div>

If you only need this grouping for this one visualization, why not use the filters aggregation with a query string? You could do something like the screenshot below. Instead of `extension` you would query on `z_code`.

 ![44 AM](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c6147751fe7d8d16331ce30c0e44514e832e1acd.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2017, 3:14pm UTC](https://discuss.elastic.co/t/painless-scripted-field/100052/6 "2017-10-10T15:14:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
