# Runtime Fields disappearing after ILM Rollover

**URL:** <https://discuss.elastic.co/t/runtime-fields-disappearing-after-ilm-rollover/344815>\
**Category:** Elasticsearch\
**Tags:** painless, ilm-index-lifecycle-management, runtime-fields\
**Created:** [October 11, 2023, 12:06pm UTC](https://discuss.elastic.co/t/runtime-fields-disappearing-after-ilm-rollover/344815 "2023-10-11T12:06:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bigdaddy0918](https://avatars.discourse-cdn.com/v4/letter/b/c6cbf5/32.png) [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Post date:** [October 11, 2023, 12:06pm UTC](https://discuss.elastic.co/t/runtime-fields-disappearing-after-ilm-rollover/344815/1 "2023-10-11T12:06:56Z")

</div>

I added a runtime field to multiple indices using the following script:

```auto
PUT my-index-000309/_mapping
{"runtime":{"agent.host_prod_flag":{"type":"keyword","script":{"source":"if (doc['agent.hostname.keyword'].size () != 0 && \n (doc['agent.hostname.keyword'].value.regionMatches(true, 0, \"d\", 0, 1) ? true : false) == true && \n doc['agent.hostname.keyword'].value.contains(\"dc.dotomi.net\") && \n doc['agent.hostname.keyword'].value.contains(\"p.dc.dotomi.net\")) \n { def host_type_1 = 'prod'; if (host_type_1 != \"\")\n\n

{ emit(host_type_1) }

\n} \n else if (doc['agent.hostname.keyword'].size () != 0 && \n (doc['agent.hostname.keyword'].value.regionMatches(true, 0, \"d\", 0, 1) ? true : false) == true && \n doc['agent.hostname.keyword'].value.contains(\"dc.dotomi.net\") && \n !doc['agent.hostname.keyword'].value.contains(\"p.dc.dotomi.net\")) \n { def host_type_2 = 'non-prod'; if (host_type_2 != \"\")\n\n

{ emit(host_type_2) }

\n} \n else if (doc['agent.hostname.keyword'].size () != 0 && \n (doc['agent.hostname.keyword'].value.regionMatches(true, 0, \"p\", 0, 1) ? true : false) == true) \n { def host_type_3 = 'prod'; if (host_type_3 != \"\")\n\n

{ emit(host_type_3) }

\n} \n else if (doc['agent.hostname.keyword'].size () != 0 && \n !(doc['agent.hostname.keyword'].value.regionMatches(true, 0, \"p\", 0, 1) ? true : false) == true)\n { def host_type_4 = 'non-prod'; if (host_type_4 != \"\")\n\n

{ emit(host_type_4) }

\n}"}}}}

```

The runtime field is displayed and working in the index as shown here:

```auto
{
  "mappings": {
    "dynamic": "true",
    "dynamic_date_formats": [
      "strict_date_optional_time",
      "yyyy/MM/dd HH:mm:ss Z||yyyy/MM/dd Z"
    ],
    "dynamic_templates": [],
    "date_detection": true,
    "numeric_detection": false,
    "runtime": {
      "agent.host_prod_flag": {
        "type": "keyword",
        "script": {
          "source": "if (doc['agent.hostname.keyword'].size () != 0 && \n (doc['agent.hostname.keyword'].value.regionMatches(true, 0, \"d\", 0, 1) ? true : false) == true && \n doc['agent.hostname.keyword'].value.contains(\"dc.dotomi.net\") && \n doc['agent.hostname.keyword'].value.contains(\"p.dc.dotomi.net\")) \n { def host_type_1 = 'prod'; if (host_type_1 != \"\")\n\n{ emit(host_type_1) }\n} \n else if (doc['agent.hostname.keyword'].size () != 0 && \n (doc['agent.hostname.keyword'].value.regionMatches(true, 0, \"d\", 0, 1) ? true : false) == true && \n doc['agent.hostname.keyword'].value.contains(\"dc.dotomi.net\") && \n !doc['agent.hostname.keyword'].value.contains(\"p.dc.dotomi.net\")) \n { def host_type_2 = 'non-prod'; if (host_type_2 != \"\")\n\n{ emit(host_type_2) }\n} \n else if (doc['agent.hostname.keyword'].size () != 0 && \n (doc['agent.hostname.keyword'].value.regionMatches(true, 0, \"p\", 0, 1) ? true : false) == true) \n { def host_type_3 = 'prod'; if (host_type_3 != \"\")\n\n{ emit(host_type_3) }\n} \n else if (doc['agent.hostname.keyword'].size () != 0 && \n !(doc['agent.hostname.keyword'].value.regionMatches(true, 0, \"p\", 0, 1) ? true : false) == true)\n { def host_type_4 = 'non-prod'; if (host_type_4 != \"\")\n\n{ emit(host_type_4) }\n}",
          "lang": "painless"
        }
      }
    },
    "properties": {

```

However, after ILM Rolls over the index, the runtime field no longer appears:

```auto
{
  "mappings": {
    "dynamic": "true",
    "dynamic_date_formats": [
      "strict_date_optional_time",
      "yyyy/MM/dd HH:mm:ss Z||yyyy/MM/dd Z"
    ],
    "dynamic_templates": [],
    "date_detection": true,
    "numeric_detection": false,
    "properties": {

```

How can I get the runtime fields to propagate forward?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2023, 12:07pm UTC](https://discuss.elastic.co/t/runtime-fields-disappearing-after-ilm-rollover/344815/2 "2023-11-08T12:07:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
