# Script params via Logstash, is it possible?

**URL:** <https://discuss.elastic.co/t/script-params-via-logstash-is-it-possible/226586>\
**Category:** Logstash\
**Created:** [April 5, 2020, 6:29pm UTC](https://discuss.elastic.co/t/script-params-via-logstash-is-it-possible/226586 "2020-04-05T18:29:38Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 16, 2020, 11:28pm UTC](https://discuss.elastic.co/t/script-params-via-logstash-is-it-possible/226586/6 "2020-04-16T23:28:52Z")

</div>

> [@parosio](#):
>
> Do I have advantages with `indexed` or `file` scripts over an `inline` one?

I would avoid the `file`.

If you use `inline`, the script is being sent together with the request each time.  
It will be cached after the first compilation, so there are no major performance improvements.  
The script will be sent each time.

If you use `indexed`, the script must be setup before starting Logstash and there will be less data to be transferred over network.

@Alex_Marquardt has a good tutorial in his blog: [Using Logstash and Elasticsearch scripted upserts to transform eCommerce purchasing data](https://alexmarquardt.com/2019/12/17/logstash-and-elasticsearch-painless-scripted-upserts-transform-data/)

If you enable `doc_as_upsert` you might miss the first `filename`.

I think the correct `elasticsearch` output should be:

```auto
 elasticsearch {
    index => "ecommerce_ls_transformed"
    document_id => "%{doc_id}"
    action => "update"
    scripted_upsert => true
    script_lang => "painless"
    script => "def fn = params.event.get('filename'); if (ctx._source.filenames != null) {ctx._source.filenames.add(fn)} else {ctx._source.filenames = [fn]} "
  }

```

Regarding the following error:

> [@parosio](#):
>
> [script] Too many dynamic script compilations within ... please use indexed, or scripts with parameters instead

If the `painless` script is valid, I wouldn't expect it to be recompiled several times (as it is cached at the first execution, if there is no dynamic content in it - meaning you access `params.event` and there is no templated text in the script).  
Are you sure this didn't occur just because you did some attempts adjusting the script and the compilation failed too many times in a short time frame?

---

_[View the full topic](https://discuss.elastic.co/t/script-params-via-logstash-is-it-possible/226586)._
