# Scripted Field Help

**URL:** <https://discuss.elastic.co/t/scripted-field-help/316156>\
**Category:** Kibana\
**Created:** [October 9, 2022, 3:16pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156 "2022-10-09T15:16:00Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![snkhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snkhan/32/109912_2.png) [@snkhan](https://discuss.elastic.co/u/snkhan)\
**Post date:** [October 9, 2022, 3:16pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/1 "2022-10-09T15:16:00Z")

</div>

Hello,

I am trying to use a scripted field to compare the value of one field against another. A sample document extract is below:

**Field1** `C2_Host`: `["check.example.workers.dev"]`  
**Field2** `HostHeader`: `"Host: check.example.workers.dev\r\n"`

The scripted field I am trying to create, `DomainFronting`, is as follows:

```nohighlight
//Returns True if the HostHeader is different to C2_Host
if (doc['HostHeader.keyword'].value == "") {
    return "False";
}

else if (doc['HostHeader.keyword'].value == "Not Found") {
    return "False";
}

else {
    String CleanHostHeader = doc['HostHeader.keyword'].value.splitOnToken('Host: ')[1];
    String CleanHostHeader2 = CleanHostHeader.splitOnToken('\\')[0];

    if (doc['C2_Host.keyword'].value == CleanHostHeader2) {
        return "False";
    }
    else {
        return "True";
    }
}

```

Which should, in theory:

- Return False is `HostHeader.keyword` is empty;
- Return False if `HostHeader.keyword` has a value of `"Not Found"`;
- Return False if `HostHeader.keyword` is the same as `C2_Host`;
- Return True if `HostHeader.keyword` is different to `C2_Host`;

Unfortunately, for the above example, the outcome is `True`, despite both values being the same. When I change the return value to instead return `CleanHostHeader2`, I can see that the string is correct, and an exact match to `C2_Host`. Can someone steer me in the right direction, as to where I am going wrong please? I feel like I am very nearly there.

Many thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 9, 2022, 5:51pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/2 "2022-10-09T17:51:12Z")

</div>

> [@snkhan](#):
>
> **Field1** `C2_Host`: `["check.example.workers.dev"]`

Yes @snkhan Question before digging in do you really mean this fields is an Array?  
the `[]` signifies and array ... if so that may be why your script is not working...

2nd you should really be using a runtime field not a scripted field that is the new approach.

---

<div class="post-metadata">

**Author:** ![snkhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snkhan/32/109912_2.png) [@snkhan](https://discuss.elastic.co/u/snkhan)\
**Post date:** [October 9, 2022, 5:56pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/3 "2022-10-09T17:56:07Z")

</div>

Indeed it is, but I would have thought `doc['C2_Host.keyword'].value` would just pick out its value? I am very new to ELK, and running 7.17, so thought Scripted Fields were the way to go. I see the note about it in the interface, but the link simply takes me to the help page, and it seems that RunTime fields cannot be configured in the GUI ☹

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 9, 2022, 6:02pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/4 "2022-10-09T18:02:04Z")

</div>

> [@snkhan](#):
>
> but the link simply takes me to the help page, and it seems that RunTime fields cannot be configured in the GUI ☹

Yes the can very easily and you can see the results ... give me a couple minutes and I will show you

What version are you running...

I can also see that you did not create a mapping... you should that is why you are haveing to use the

QUESTION : if `C2_Host` is an Array what do you expect to happy if there are 2 or more values? Should it only compare the first? What is the logic...

---

<div class="post-metadata">

**Author:** ![snkhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snkhan/32/109912_2.png) [@snkhan](https://discuss.elastic.co/u/snkhan)\
**Post date:** [October 9, 2022, 6:05pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/5 "2022-10-09T18:05:40Z")

</div>

Thanks Stephen. I am running 7.17. Appreciate the comment if there are multiple `C2_Host` values, ideally I would have it as `if CleanHostHeader2 in C2_Host` (pseudocode), but for the time being happy for it to just pick the first value, as that is what I am seeing in 99% of cases.

What I also do not understand is, if I return the value of `CleanHostHeader2` instead, the string is **exactly** the same as `C2_Host` if there is 1 domain, so in that case I would absolutely expect the condition to return `False`, and yet it still returns `True`.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 9, 2022, 6:27pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/6 "2022-10-09T18:27:02Z")

</div>

```auto
    // You had a trailing space
    String CleanHostHeader2 = CleanHostHeader.splitOnToken('\\')[0].trim(); <!--- trim

```

You have a bug... a trailing space... that will get you started...

Here is my current code for a runtime field

```auto
if (doc['HostHeader'].value == "") {
    return emit("false");
}

else if (doc['HostHeader'].value == "Not Found") {
    return emit("false");
}

else {
    String CleanHostHeader = doc['HostHeader'].value.splitOnToken('Host: ')[1];
    
    // You had a trailing space
    String CleanHostHeader2 = CleanHostHeader.splitOnToken('\\')[0].trim();

    if (CleanHostHeader2.equals(doc['C2_Host'].value)) {
     return emit("true");
    }
    else {
     return emit("false");
    }
}

```

This code will looks like it will look at the first in the array... if you really wanted to you would have to loop through...

---

<div class="post-metadata">

**Author:** ![snkhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snkhan/32/109912_2.png) [@snkhan](https://discuss.elastic.co/u/snkhan)\
**Post date:** [October 9, 2022, 6:30pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/7 "2022-10-09T18:30:08Z")

</div>

> [@stephenb](#):
>
> `String CleanHostHeader2 = CleanHostHeader.splitOnToken('\\')[0].trim();`

OMG, thank you! That fixed it 🙂

---

<div class="post-metadata">

**Author:** ![snkhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snkhan/32/109912_2.png) [@snkhan](https://discuss.elastic.co/u/snkhan)\
**Post date:** [October 9, 2022, 6:35pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/8 "2022-10-09T18:35:49Z")

</div>

Incidentally, where do you create a RunTime field? Via mappings?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 9, 2022, 6:35pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/9 "2022-10-09T18:35:53Z")

</div>

Ok so now here is the interesting Part

You can add this through the index Pattern

Kibana - Stack Management - Index Pattern - Add Runtime Field

(Mine is 8.x index patterns are now called Data Views (you should get to 8.x lots of good stuff there)

So if you add a runtime field in an index pattern it **will** work in visualizations etc... BUT it will **not** work in DSL queries etc...

If you want it to work everywhere you add it to the mapping

I like creating them in the UI then I move them to the mapping ... just a suggestion

You can click through the docs in your index to see how the code is working

 ![Screen Shot 2022-10-09 at 11.30.12 AM](https://us1.discourse-cdn.com/elastic/original/3X/7/b/7b9aeeda65bc5caacc2b8b26a240d25d43d80957.jpeg)

Speaking of the mapping you should be declaring yours...

Example plus all your other fields

```auto
PUT discuss-test-runtime/
{
  "mappings": {
    "properties": {
      "C2_Host": {"type": "keyword"},
       "HostHeader": {"type": "keyword"}
    }
  }
}

```

So you should read up on [Mapping](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/mapping.html) which is a big topic in general then look at adding your [runtime field](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/runtime.html)

All that said adding the field to your index pattern is a great way to start...

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 9, 2022, 6:37pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/10 "2022-10-09T18:37:48Z")

</div>

> [@snkhan](#):
>
> OMG, thank you! That fixed it 🙂

Basically I use `emit` like `printf` good old string debugging I always put leading / trailing characters to see what is there...

---

<div class="post-metadata">

**Author:** ![snkhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/snkhan/32/109912_2.png) [@snkhan](https://discuss.elastic.co/u/snkhan)\
**Post date:** [October 9, 2022, 6:41pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/11 "2022-10-09T18:41:47Z")

</div>

I am new to ELK and very very new to Painless, so I was doing the equivalent by returning the value of the variable, haha!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 9, 2022, 6:44pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/12 "2022-10-09T18:44:40Z")

</div>

Yeah it's pretty much like Java I find in the UI just put the type and then the dot and then it'll show you all the functions. But the editor is not super helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2022, 6:45pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156/13 "2022-11-06T18:45:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
