# Scripted field in kibana - finding string

**URL:** <https://discuss.elastic.co/t/scripted-field-in-kibana-finding-string/184150>\
**Category:** Kibana\
**Created:** [June 4, 2019, 10:09am UTC](https://discuss.elastic.co/t/scripted-field-in-kibana-finding-string/184150 "2019-06-04T10:09:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [June 4, 2019, 10:09am UTC](https://discuss.elastic.co/t/scripted-field-in-kibana-finding-string/184150/1 "2019-06-04T10:09:01Z")

</div>

Hi there  
I have field named 'message' (not aggregatable) and I want to find in this field string /error/.

I.E.

2019-06-04T11:56:24,190 | ERROR | qtp734591330-952813 | AbstractFaultChainInitiatorObserver | 74 - org.apache.cxf.cxf-core - 3.3.1 | An unexpected error occurred during error handling. No further error processing will occur.  
org.apache.cxf.interceptor.Fault: The OUT message was not received within: 1000 millis due reply message with correlationID: Camel-ID-uom2x86-1559055137239-9-38024 not received on destination: temp-queue://ID:uom2x86-52983-1559055135200-14:4:4. Exchange[ID-uom2x86-1559055137239-9-38023] while invoking public void pl.com.agora.services.frontend.searcher.text.ws.SearcherTextService.searchArticleByQueryForExtUser(pl.com.agora.services.frontend.searcher.text.ws.SearchArticleByQueryForExtUser) with params [SearchArticleByQueryForExtUser(portalId=837, rootId=null, sectionId=null, withSubsections=false, articleTypes=[LIVE, PHOTOSTORY, SM\_ARTICLE, BAUBLES, GALLERY, CMS\_ARTICLE, QUIZ\_ARTICLE], titleOrLead=null, content=null, signature=null, authorId=null, tags=, beginPublicationDateFrom=null, endPublicationDateFrom=null, vitality=ALL, pageSize=500, pageNumber=1, orderBy=ID\_DESC, textStates=, checkedByCorrector=null, checkedByEditor=null, sendToNewspaper=null, userId=59593)].  
and so on

I have tried with regex but that does not work and I even can not see my data after adding that kind of scripted field.

Could it be replaced by:

- contains ?
- indexOf?  
Thank you for your help

---

<div class="post-metadata">

**Author:** ![jen-huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jen-huang/32/74327_2.png) [@jen-huang](https://discuss.elastic.co/u/jen-huang)\
**Post date:** [June 4, 2019, 5:47pm UTC](https://discuss.elastic.co/t/scripted-field-in-kibana-finding-string/184150/2 "2019-06-04T17:47:49Z")

</div>

What is the end goal for this scripted field? If you want to filter to documents that have `error` in the `message` field for the purposes of creating Visualizations, you can simply add a filter in your visualization.

---

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [June 5, 2019, 6:46am UTC](https://discuss.elastic.co/t/scripted-field-in-kibana-finding-string/184150/3 "2019-06-05T06:46:38Z")

</div>

I have visualisations for those fields 🙂  
This time I want to count errors and set a level when there are too many of those.  
That is why I need scripted field

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2019, 6:46am UTC](https://discuss.elastic.co/t/scripted-field-in-kibana-finding-string/184150/4 "2019-07-03T06:46:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
