# Runtime conditional

**URL:** <https://discuss.elastic.co/t/runtime-conditional/324210>\
**Category:** Elasticsearch\
**Tags:** runtime-fields\
**Created:** [January 30, 2023, 9:38am UTC](https://discuss.elastic.co/t/runtime-conditional/324210 "2023-01-30T09:38:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![LorensiusOksigii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lorensiusoksigii/32/111670_2.png) [@LorensiusOksigii](https://discuss.elastic.co/u/LorensiusOksigii)\
**Post date:** [January 30, 2023, 9:38am UTC](https://discuss.elastic.co/t/runtime-conditional/324210/1 "2023-01-30T09:38:23Z")

</div>

Hi,

i get confuse how to set a new value for msg value from message field. i want set if message value == { "msg" : "ICMP flood" }, msg value will show only ICMP flood

i have try this but getting error

 ![mumet](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e50d799aa9576ff672de1b226a49075143162467.png)

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [January 30, 2023, 10:23am UTC](https://discuss.elastic.co/t/runtime-conditional/324210/2 "2023-01-30T10:23:06Z")

</div>

Hi 0ksigi,

Welcome to the community! For future, can you share the script snippet as `code`. It makes it easier to validate and try out than sharing via screenshot.

Looking at your script I immediately see 3 issues:

1. For your if condition you seem to be containing the query in braces, aka `{`, instead of brackets `(`. You should have something like this [as per the syntax guide](https://www.elastic.co/guide/en/elasticsearch/painless/8.6/painless-runtime-fields-context.html):

```auto
if (condition) { 
  // actionable code
}

```

1. I immediately see is you have an open string in your first emit statement. You should have `emit('ICMP flood')`.

2. [The `emit` function cannot not accept null values](https://www.elastic.co/guide/en/elasticsearch/painless/8.6/painless-runtime-fields-context.html). I would suggest emitting either an empty string, aka `''`, or another alternative value.

Taking all into consideration, I think you need to try something like this:

```auto
if (doc['message'].value == {'msg': 'ICMP flood'}) {
  emit('ICMP flood')
} else {
emit('')
}

```

Can you try the above and see what you get?

---

<div class="post-metadata">

**Author:** ![LorensiusOksigii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lorensiusoksigii/32/111670_2.png) [@LorensiusOksigii](https://discuss.elastic.co/u/LorensiusOksigii)\
**Post date:** [January 30, 2023, 5:08pm UTC](https://discuss.elastic.co/t/runtime-conditional/324210/3 "2023-01-30T17:08:45Z")

</div>

hi Carly, thank you for replying my question.

i have try your suggestion you have suggest to me, but it still get error.

before i continue my if else condition, i am trying to extract message field using  
`emit (doc["message"].value)` but getting match\_only\_text fields do not support sorting and aggregations error.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6c2664dc315b4fdbea21b463768e0266daab6266.png)

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [January 30, 2023, 5:31pm UTC](https://discuss.elastic.co/t/runtime-conditional/324210/4 "2023-01-30T17:31:28Z")

</div>

> [@LorensiusOksigii](#):
>
> match\_only\_text fields do not support sorting and aggregations

So this new error is due to a sort or aggregation being applied to a text field. If you use the keyword field `message.keyword` instead of just `message` you should eliminate that error.

---

<div class="post-metadata">

**Author:** ![LorensiusOksigii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lorensiusoksigii/32/111670_2.png) [@LorensiusOksigii](https://discuss.elastic.co/u/LorensiusOksigii)\
**Post date:** [January 31, 2023, 6:03am UTC](https://discuss.elastic.co/t/runtime-conditional/324210/5 "2023-01-31T06:03:30Z")

</div>

i am sorry, i am still confuse how to use

> message keyword. i have try on my running field but get another error like `No field found for [message.keyword] in mapping`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/a/baaa73987a47aa49c27e4e61a5e85fa10b2aac06.png)

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [January 31, 2023, 10:42am UTC](https://discuss.elastic.co/t/runtime-conditional/324210/6 "2023-01-31T10:42:41Z")

</div>

Interesting, looks like `message.keyword` isn't available on your index mapping. From the index pattern name it looks like you're using Filebeat. Can you share the index mapping and filebeat config?

I did find [another related thread](https://discuss.elastic.co/t/message-keyword-does-not-exists/181028/6), albeit old, that suggests reindexing which could be worth a try.

---

<div class="post-metadata">

**Author:** ![LorensiusOksigii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lorensiusoksigii/32/111670_2.png) [@LorensiusOksigii](https://discuss.elastic.co/u/LorensiusOksigii)\
**Post date:** [January 31, 2023, 6:38pm UTC](https://discuss.elastic.co/t/runtime-conditional/324210/7 "2023-01-31T18:38:51Z")

</div>

and this is my filebeat config

# ============================== Filebeat inputs ===============================

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so

# you can use different inputs for various configurations.

# Below are the input specific configurations.

# filestream is an input for collecting log messages from files.

- type: log

# ================================== Outputs ===================================

# Configure what output to use when sending the data collected by the beat.

# ---------------------------- Elasticsearch Output ----------------------------

output.elasticsearch:

# Array of hosts to connect to.

hosts: ["localhost:9200"]

---

<div class="post-metadata">

**Author:** ![LorensiusOksigii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lorensiusoksigii/32/111670_2.png) [@LorensiusOksigii](https://discuss.elastic.co/u/LorensiusOksigii)\
**Post date:** [January 31, 2023, 6:39pm UTC](https://discuss.elastic.co/t/runtime-conditional/324210/8 "2023-01-31T18:39:59Z")

</div>

this is my index mapping

```auto
{
  "mappings": {
    "_doc": {
      "_meta": {
        "beat": "filebeat",
        "version": "7.17.8"
      },
      "dynamic_templates": [
        {
          "labels": {
            "path_match": "labels.*",
            "match_mapping_type": "string",
            "mapping": {
              "type": "keyword"
            }
          }
        },
        {

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2023, 6:40pm UTC](https://discuss.elastic.co/t/runtime-conditional/324210/9 "2023-02-28T18:40:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
