# Scripted Field - Loop through documents in an index and add field value to list

**URL:** <https://discuss.elastic.co/t/scripted-field-loop-through-documents-in-an-index-and-add-field-value-to-list/153947>\
**Category:** Kibana\
**Created:** [October 25, 2018, 8:32am UTC](https://discuss.elastic.co/t/scripted-field-loop-through-documents-in-an-index-and-add-field-value-to-list/153947 "2018-10-25T08:32:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![chickennuggets](https://avatars.discourse-cdn.com/v4/letter/c/5daacb/32.png) [@chickennuggets](https://discuss.elastic.co/u/chickennuggets)\
**Post date:** [October 25, 2018, 8:32am UTC](https://discuss.elastic.co/t/scripted-field-loop-through-documents-in-an-index-and-add-field-value-to-list/153947/1 "2018-10-25T08:32:58Z")

</div>

Hi, I've just started using Kibana and was wondering how to solve the problem in the title. I've looked through somewhat related posts, but they haven't been any help.

Essentially, what I'd like to do is loop through all my documents in an index. If any of the documents match a condition, the document's type would be added to a list. Then if that list contains "RESPONSE", the scripted field's result would be "False", and the opposite would be "True".

For example:  
for doc1 in documents:  
for doc2 in documents:  
if doc1.invoice\_id.equals(doc2.invoice\_id):  
list.add(doc1.type)

if list.contains("RESPONSE"):  
return "False"  
else:  
return "True"

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [October 25, 2018, 6:06pm UTC](https://discuss.elastic.co/t/scripted-field-loop-through-documents-in-an-index-and-add-field-value-to-list/153947/2 "2018-10-25T18:06:03Z")

</div>

Hi @chickennuggets, scripted fields only work on a per document basis. You cannot create a scripted field based on multiple documents in an index.

---

<div class="post-metadata">

**Author:** ![chickennuggets](https://avatars.discourse-cdn.com/v4/letter/c/5daacb/32.png) [@chickennuggets](https://discuss.elastic.co/u/chickennuggets)\
**Post date:** [October 26, 2018, 1:56am UTC](https://discuss.elastic.co/t/scripted-field-loop-through-documents-in-an-index-and-add-field-value-to-list/153947/3 "2018-10-26T01:56:07Z")

</div>

Thanks for the reply @Bargs. Is there any way to accomplish the task and have it visualized in a data table through Kibana? Or would I have to do it through Logstash?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [October 29, 2018, 5:30pm UTC](https://discuss.elastic.co/t/scripted-field-loop-through-documents-in-an-index-and-add-field-value-to-list/153947/4 "2018-10-29T17:30:03Z")

</div>

There isn't really a great way to accomplish this since your condition relies on comparing one document against another. Anything that's essentially a join like that will be problematic. For this case you may be best off denormalizing your data, including all of the info relevant to a given invoice in a single doc.

---

<div class="post-metadata">

**Author:** ![chickennuggets](https://avatars.discourse-cdn.com/v4/letter/c/5daacb/32.png) [@chickennuggets](https://discuss.elastic.co/u/chickennuggets)\
**Post date:** [October 31, 2018, 6:50am UTC](https://discuss.elastic.co/t/scripted-field-loop-through-documents-in-an-index-and-add-field-value-to-list/153947/5 "2018-10-31T06:50:00Z")

</div>

Got it, thanks for the help @Bargs!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2018, 6:50am UTC](https://discuss.elastic.co/t/scripted-field-loop-through-documents-in-an-index-and-add-field-value-to-list/153947/6 "2018-11-28T06:50:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
