# Script based transform during index

**URL:** <https://discuss.elastic.co/t/script-based-transform-during-index/22261>\
**Category:** Elasticsearch\
**Created:** [February 19, 2015, 10:54am UTC](https://discuss.elastic.co/t/script-based-transform-during-index/22261 "2015-02-19T10:54:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Demetris\_Lambrou](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@Demetris\_Lambrou](https://discuss.elastic.co/u/Demetris_Lambrou)\
**Post date:** [February 19, 2015, 10:54am UTC](https://discuss.elastic.co/t/script-based-transform-during-index/22261/1 "2015-02-19T10:54:03Z")

</div>

Hi Group  
First apologies if this is not the right way to ask the below question but  
this is my first time.

I have some documents with source IP and destination IP address. I want to  
enhance these documents with geo info with script transform when they  
arrive. So I created a script in python and I resolve geo info for every  
destination ip and store in \_source (from what I understand)

The template for the index is as below. Everything works fine however I  
have two issues.

1. The field (which does not exist and I create it namely "location") is  
not shown in a search unless explicitly asked.
2. Kibana 3 does not show this field or it shows as empty.

The field location is there if I explicitly ask for it. Can you please let  
me know how I can have these added fields prior to index available as  
normal fields ?

Thanks in advance !

P.S inside the python script I update the below  
ctx['location'] = ip2geo(dest\_ip)  
ctx['\_source']['location'] = ip2geo(dest\_ip)

POST /geotest/gdoc/\_search  
{  
"query": {  
"match\_all": {}  
},  
"fields": [  
"src\_ip",  
"dst\_ip",  
"location" \<-- This is the new field which I add via  
ctx['\_source']['location'] = ip2geo(dest\_ip)  
]  
}

My template

PUT /\_template/geo

{  
"template": "geo\*",  
"mappings": {  
"gdoc": {  
"transform": {  
"lang": "python",  
"script": "python\_ip2geo"  
},  
"\_source": {  
"enabled": "true"  
},  
"properties": {  
"src\_ip": {  
"type": "ip",  
"index": "not\_analyzed"  
},  
"dst\_ip": {  
"type": "ip",  
"index": "not\_analyzed"  
},  
"location": {  
"type": "geo\_point",  
"index": "analyzed", \<-- does not need to be analyzed  
really  
"store": "true",  
"doc\_values": "true",  
"null\_value": ""  
}  
}  
}  
}  
}

Can someone explain a bit more on how transform fields are stored and how  
they can be indexed ?

Thanks in advance

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3e552ca9-f110-47f0-aae5-63ea8f2a89d8%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3e552ca9-f110-47f0-aae5-63ea8f2a89d8%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:31am UTC](https://discuss.elastic.co/t/script-based-transform-during-index/22261/2 "2017-07-06T00:31:34Z")

</div>


