# Painless scripting field question

**URL:** <https://discuss.elastic.co/t/painless-scripting-field-question/93667>\
**Category:** Elasticsearch\
**Created:** [July 18, 2017, 10:43pm UTC](https://discuss.elastic.co/t/painless-scripting-field-question/93667 "2017-07-18T22:43:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![xwang12345](https://avatars.discourse-cdn.com/v4/letter/x/49beb7/32.png) [@xwang12345](https://discuss.elastic.co/u/xwang12345)\
**Post date:** [July 18, 2017, 10:43pm UTC](https://discuss.elastic.co/t/painless-scripting-field-question/93667/1 "2017-07-18T22:43:12Z")

</div>

I have a number of document, each document will have a src\_ip field.  
Some of the documents MIGHT also have a srcip\_host field.

I would like to have scripted field, type is string(text), that takes the srcip\_host value if that exists, otherwise just take the src\_ip field.

The mapping of the src\_ip and srcip\_host are as follows:

```auto
"srcip_host": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
"srcip": {
            "type": "ip"
          },

```

In my Index\_pattern, the scripted field is as following:

```auto
src_host_or_ip	painless	if (doc["srcip_host.keyword"].value != null) return doc["srcip_host.keyword"].value; else return doc["srcip"].value

```

But I got the following runtime warning from kibana web page.  
Courier Fetch: 5 of 50 shards failed.

By investigating more, I found the following runtime error from kibana web client:

````auto
Object
index
:
"logstash-2017.07.17"
node
:
"iRl6kRKrTSGWqxFYI9i0rQ"
reason
:
Object
caused_by
:
Object
lang
:
"painless"
reason
:
"runtime error"
script
:
"if (doc['srcip_host.keyword'].value != null) return doc['srcip_host.keyword'].value;↵else return doc['srcip'].value"
script_stack
:
Array(3)
0
:
"org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:80)"
1
:
"if (doc['srcip_host.keyword'].value != null) "
2
:
" ^---- HERE"
length
:
3```

The ^---HERE seems to pointing to doc['srcip_host.keyword'].value, is that because the field might not exist for certain documents?

How to deal with this type of problems?

Thanks
````

---

<div class="post-metadata">

**Author:** ![shanec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanec/32/4004_2.png) [@shanec](https://discuss.elastic.co/u/shanec)\
**Post date:** [July 19, 2017, 12:16am UTC](https://discuss.elastic.co/t/painless-scripting-field-question/93667/2 "2017-07-19T00:16:27Z")

</div>

It's a little difficult to read your example. The following _does_ work:

```auto
PUT /foo
{
  "mappings": {
    "bar": {
      "properties": {
        "srcip": {
          "type": "ip"
        }
      }
    }
  }
}

PUT /foo/bar/1
{
  "srcip": "10.0.0.1"
}

PUT /foo/bar/2
{
  "srcip_host": "eskibars.com"
}

GET /foo/_search
{
  "script_fields": {
    "src_host_or_ip": {
      "script": {
        "lang": "painless",
        "inline": "if (doc['srcip_host.keyword'].value != null) { return doc['srcip_host.keyword'].value } else { return doc['srcip'].value }"
      }
    }
  }
}

```

Can you maybe format an example doc/query or at least the example response?

---

<div class="post-metadata">

**Author:** ![xwang12345](https://avatars.discourse-cdn.com/v4/letter/x/49beb7/32.png) [@xwang12345](https://discuss.elastic.co/u/xwang12345)\
**Post date:** [July 19, 2017, 5:01pm UTC](https://discuss.elastic.co/t/painless-scripting-field-question/93667/3 "2017-07-19T17:01:35Z")

</div>

The problem is that it failed in some shards, not all of the shards. So it works for this simple documents set does not mean it will work for large number of documents.

I got the error from kibana side:  
Courier Fetch: 5 of 50 shards failed.

The error is happening on the elasticsearch side in this file:  
./core/src/main/java/org/elasticsearch/search/lookup/LeafDocLookup.java

```auto
    @Override
    public ScriptDocValues<?> get(Object key) {
        // assume its a string...
        String fieldName = key.toString();
        ScriptDocValues<?> scriptValues = localCacheFieldData.get(fieldName);
        if (scriptValues == null) {
            final MappedFieldType fieldType = mapperService.fullName(fieldName);
            if (fieldType == null) {
                throw new IllegalArgumentException("No field found for [" + fieldName + "] in mapping with types " + Arrays.toString(types));
            }   

```

The fieldType is null. I do not understand the internals of the elastic search, the question is when the mapperService is populated for the shard. Is it shared across the shards or it is per shard thing?

Thanks

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [July 20, 2017, 6:59pm UTC](https://discuss.elastic.co/t/painless-scripting-field-question/93667/4 "2017-07-20T18:59:46Z")

</div>

Do you define your mappings up front, or rely on dynamic mappings? I could see this happening if you rolled over to a new day's index, and had not yet seen any documents which contained `srcip_host`. You can protect against that by checking the doc for the field before trying to access it, with `doc.containsKey('srcip_host.keyword')`.

---

<div class="post-metadata">

**Author:** ![xwang12345](https://avatars.discourse-cdn.com/v4/letter/x/49beb7/32.png) [@xwang12345](https://discuss.elastic.co/u/xwang12345)\
**Post date:** [July 20, 2017, 7:03pm UTC](https://discuss.elastic.co/t/painless-scripting-field-question/93667/5 "2017-07-20T19:03:35Z")

</div>

I will try this, Thanks for the reply.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2017, 7:09pm UTC](https://discuss.elastic.co/t/painless-scripting-field-question/93667/6 "2017-08-17T19:09:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
