# Query Result Value not in Script available with ctx.payload

**URL:** <https://discuss.elastic.co/t/query-result-value-not-in-script-available-with-ctx-payload/143157>\
**Category:** Elasticsearch\
**Created:** [August 6, 2018, 11:47am UTC](https://discuss.elastic.co/t/query-result-value-not-in-script-available-with-ctx-payload/143157 "2018-08-06T11:47:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![djuentgen](https://avatars.discourse-cdn.com/v4/letter/d/a5b964/32.png) [@djuentgen](https://discuss.elastic.co/u/djuentgen)\
**Post date:** [August 6, 2018, 11:47am UTC](https://discuss.elastic.co/t/query-result-value-not-in-script-available-with-ctx-payload/143157/1 "2018-08-06T11:47:19Z")

</div>

Hi together,

i'm not sure whether i am correct in this forum or not 🙂

I am really new to elastic & kibana stuff and cant find a solution to what i'm trying.

in the query section: i'am filtering the eventlog data for the event id and substatus.  
The total count value filtered by the query is not accessible in the script below

```
   Post eventlog/_search
    {
      "query": {
    "query_string":{
      "query": "event_id:4625 AND @timestamp:>now-24h AND (sub_status:/0..000005[e|E]/ OR sub_status:/0..0000064/ OR sub_status:/0..000006[A|a]/ OR sub_status:/0..000006[D|d]/)"
      }
      },
      "script_fields": {
    "hourlyLogonAttemptSnapShot": {
      "script": {
        "lang": "painless",
        "source": """
          long lLogonAttempts = ctx.payload.hits.total;
          long lTotalAccounts = 40000; /* zweite indexabfrage einbauen*/
          long lOrangeThreshold = lTotalAccounts *5;
          long lYellowThreshold = lTotalAccounts *4;
          long lGreenThreshold = lTotalAccounts * 3;
          String sThreshold;
          
          if (lLogonAttempts <= lGreenThreshold) {
            sThreshold = "green";
          }
          else if (lLogonAttempts > lGreenThreshold && lLogonAttempts <= lYellowThreshold) {
            sThreshold ="yellow";
          }
          else if (lLogonAttempts > lYellowThreshold && lLogonAttempts <= lOrangeThreshold){
            sThreshold = "orange";
          }
          else {
            sThreshold ="red";
          }
          return sThreshold;
        """
      }
    }
      }
    }

```

the error i am receiving is as follows:

```
"shard": 0,
"index": "eventlog-2018.08.05",
"node": "HMx4WRB_Sfqxt4A2R1O45g",
"reason": {
  "type": "script_exception",
  "reason": "runtime error",
  "script_stack": [
    "lLogonAttempts = ctx.payload.hits.total;\n long ",
    " ^---- HERE"
  ],

```

the final target to achiev is to hourly execute the query by a watcher and gather the total count and the color according to the threholds and write them in a new index. but first i need to understand how to have the query result available in the script part. to put the ctx.payload.. in {} or " is not helping ;(

many thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 6, 2018, 3:55pm UTC](https://discuss.elastic.co/t/query-result-value-not-in-script-available-with-ctx-payload/143157/2 "2018-08-06T15:55:16Z")

</div>

Hey

`ctx.payload` is a construct that is only accessible during a watch execution. a script field has only access to the `doc` variable to access doc value fields. See [https://www.elastic.co/guide/en/elasticsearch/reference/6.3/search-request-script-fields.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/search-request-script-fields.html)

---

<div class="post-metadata">

**Author:** ![djuentgen](https://avatars.discourse-cdn.com/v4/letter/d/a5b964/32.png) [@djuentgen](https://discuss.elastic.co/u/djuentgen)\
**Post date:** [August 10, 2018, 11:05am UTC](https://discuss.elastic.co/t/query-result-value-not-in-script-available-with-ctx-payload/143157/3 "2018-08-10T11:05:40Z")

</div>

Hey Alex,

thanks for the answer helped me alot 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2018, 11:05am UTC](https://discuss.elastic.co/t/query-result-value-not-in-script-available-with-ctx-payload/143157/4 "2018-09-07T11:05:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
