# Script field for search msg

**URL:** <https://discuss.elastic.co/t/script-field-for-search-msg/241879>\
**Category:** Kibana\
**Created:** [July 20, 2020, 10:19am UTC](https://discuss.elastic.co/t/script-field-for-search-msg/241879 "2020-07-20T10:19:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ali4](https://avatars.discourse-cdn.com/v4/letter/a/2acd7d/32.png) [@Ali4](https://discuss.elastic.co/u/Ali4)\
**Post date:** [July 20, 2020, 10:19am UTC](https://discuss.elastic.co/t/script-field-for-search-msg/241879/1 "2020-07-20T10:19:29Z")

</div>

Hello,

Please i need your help.

I need to create script field to search msg "error" in field message.

the field message is:  
'''  
{"@timestamp":"2020-07-20T12:14:43+02:00","@version":"1","message":" time="Jul 20 12:14:43" level=debug msg=Finished code=403 **error** ="No token provided" mw=CoProcessMiddleware ns=1981606 "severity":"debug","facility":"kern","programname":""}  
'''  
i created  
if (doc['message.keyword'].value.contains ("error") {  
return "Error"  
}

its not works

Help please

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [July 20, 2020, 10:48pm UTC](https://discuss.elastic.co/t/script-field-for-search-msg/241879/2 "2020-07-20T22:48:39Z")

</div>

First of all, I would highly recommend setting this during index time as each document needs analyzed using this method.

If you're OK with the performance cost here, this can be done.

Here is my test data:

```auto
DELETE /discuss-241879

PUT /discuss-241879
{
  "settings": {
    "index": {
      "number_of_shards": 1,
      "number_of_replicas": 0
    }
  },
  "mappings": {
    "properties": {
      "message": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      }
    }
  }
}

POST /discuss-241879/_doc
{
    "@timestamp" : "July 20th 2020, 16:17:55.029",
    "message" : "This is an error"
}

POST /discuss-241879/_doc
{
    "@timestamp" : "July 20th 2020, 16:18:55.029",
    "message" : "This was a success"
}

```

I have then created an index pattern on `discuss-241879` with the following scriped field:

```auto
if (doc.containsKey('message.keyword') && 
    doc['message.keyword'].value.contains("error")) {
  return true
}

return false

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f4572ba219b433e57f7673364273bce4e4f7782.png)

What error were you getting?

---

<div class="post-metadata">

**Author:** ![Ali4](https://avatars.discourse-cdn.com/v4/letter/a/2acd7d/32.png) [@Ali4](https://discuss.elastic.co/u/Ali4)\
**Post date:** [July 21, 2020, 8:57am UTC](https://discuss.elastic.co/t/script-field-for-search-msg/241879/3 "2020-07-21T08:57:03Z")

</div>

Hello,

Thank you for your response.

I shared wih you my output json.

{  
"\_index": "tyk\_gateway\_prod-2020-07-21",  
"\_type": "doc",  
"\_version": 1,  
"\_score": null,  
"\_source": **{**  
"tags": [  
"\_grokparsefailure"  
],  
"@version": "1",  
"type": "syslog",  
"host": "X.X.X.X",  
"@timestamp": "2020-07-21T07:33:20.441Z",  
"message": " **{**"@timestamp":"2020-07-21T09:33:20+02:00","@version":"1","message":" time=\\\"Jul 21 09:33:20\\\" level=debug msg=Finished api\_id=xxxxxxxxxxxxxxx api\_name=xxxxxxxxxxxx code=403 **error** =\\\"No token provided\\\" mw=CoProcessMiddleware ns=2075904 org\_id=xxxxxxx origin=xxxxxxxxx path=xxxxxxxxx "@sysloghost":"xxxxxxxxxx","severity":"debug","facility":"kern\*\*"}\*\*\n"  
**}** ,  
"fields": {  
"@timestamp": [  
"2020-07-21T07:33:20.441Z"  
]  
},  
"sort": [  
1595316800441  
]  
}

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a4982444db3ad5ecd3f4d185f943249b44f5807d.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1cbe14c8d982bd2748eaad845f28980495bbc493.png)

i have message on elasticsearch : Fielddata is disabled on text fields by default. Set fielddata=true on [message] in order to load fielddata in memory by uninverting the inverted index.

the problem is the field "message" in to "\_source"

Have you idea how to enabled this field please.

I tried with :  
PUT tyk\_gateway\_prod  
{

"mappings": {  
"properties": {  
"\_source": {  
"message": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}  
}  
}  
}  
}

but i have message error:  
{  
"error": {  
"root\_cause": [  
{  
"type": "mapper\_parsing\_exception",  
"reason": "Mapping definition for [\_source] has unsupported parameters: [message : {type=text, fields={keyword={ignore\_above=256, type=keyword}}}]"  
}  
],

Thank you :

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2020, 8:57am UTC](https://discuss.elastic.co/t/script-field-for-search-msg/241879/4 "2020-08-18T08:57:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
