# Runtime field just stopped returning a value sometime around 4 AM this morning

**URL:** <https://discuss.elastic.co/t/runtime-field-just-stopped-returning-a-value-sometime-around-4-am-this-morning/293224>\
**Category:** Elasticsearch\
**Tags:** painless, runtime-fields\
**Created:** [December 30, 2021, 6:43pm UTC](https://discuss.elastic.co/t/runtime-field-just-stopped-returning-a-value-sometime-around-4-am-this-morning/293224 "2021-12-30T18:43:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kossde](https://avatars.discourse-cdn.com/v4/letter/k/f19dbf/32.png) [@kossde](https://discuss.elastic.co/u/kossde)\
**Post date:** [December 30, 2021, 6:43pm UTC](https://discuss.elastic.co/t/runtime-field-just-stopped-returning-a-value-sometime-around-4-am-this-morning/293224/1 "2021-12-30T18:43:50Z")

</div>

I created the following runtime field a couple of days ago and it was working fine. This morning, however it just stopped. The field is blank for all log entries that came in after around 4 AM this morning. Any idea why this might happen?

```auto
PUT CPODNS/_mapping
{

    "runtime":{
      "base_url":{
      "type":"keyword",
      "script": {
        "lang": "painless",
        "source": """
        if(doc['app.name'].value== "checkpoint" && doc['url.domain'].size() > 0){
          emit(doc['url.domain'].value)
        } else if(doc['app.name'].value== "opendns" && doc['dns.question.name'].size() > 0){
          emit(doc['dns.question.name'].value)
        } 
        """
        }
      }
    }
  }

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 30, 2021, 6:53pm UTC](https://discuss.elastic.co/t/runtime-field-just-stopped-returning-a-value-sometime-around-4-am-this-morning/293224/2 "2021-12-30T18:53:05Z")

</div>

Can you show an example of a document that has been indexed recently for which this does not work? Has something in the structure changed?

---

<div class="post-metadata">

**Author:** ![kossde](https://avatars.discourse-cdn.com/v4/letter/k/f19dbf/32.png) [@kossde](https://discuss.elastic.co/u/kossde)\
**Post date:** [December 30, 2021, 7:01pm UTC](https://discuss.elastic.co/t/runtime-field-just-stopped-returning-a-value-sometime-around-4-am-this-morning/293224/3 "2021-12-30T19:01:07Z")

</div>

Ok so from what I can tell, the indices rolled over this morning and I don't believe the mapping is applying to new indices as they are being created. I just added the mapping to the index template but the existing indices still don't have the runtime field. Do you know if mapping changes to an index template apply to existing indices or do they only apply to future indices?

---

<div class="post-metadata">

**Author:** ![kossde](https://avatars.discourse-cdn.com/v4/letter/k/f19dbf/32.png) [@kossde](https://discuss.elastic.co/u/kossde)\
**Post date:** [December 30, 2021, 7:03pm UTC](https://discuss.elastic.co/t/runtime-field-just-stopped-returning-a-value-sometime-around-4-am-this-morning/293224/4 "2021-12-30T19:03:34Z")

</div>

Ok I just found the answer to that last question as well, "Changes to index templates do not affect existing indices, including the existing backing indices of a data stream." So I will manually add this mapping back to the existing indices and, fingers crossed, the template will apply it to future indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2022, 7:03pm UTC](https://discuss.elastic.co/t/runtime-field-just-stopped-returning-a-value-sometime-around-4-am-this-morning/293224/5 "2022-01-27T19:03:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
