# Scripted field not working properly in ELK 7.2

**URL:** <https://discuss.elastic.co/t/scripted-field-not-working-properly-in-elk-7-2/188599>\
**Category:** Kibana\
**Created:** [July 3, 2019, 3:38am UTC](https://discuss.elastic.co/t/scripted-field-not-working-properly-in-elk-7-2/188599 "2019-07-03T03:38:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mark.quilates](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark.quilates/32/24802_2.png) [@mark.quilates](https://discuss.elastic.co/u/mark.quilates)\
**Post date:** [July 3, 2019, 3:38am UTC](https://discuss.elastic.co/t/scripted-field-not-working-properly-in-elk-7-2/188599/1 "2019-07-03T03:38:19Z")

</div>

Hi

Anyone can you help me? Below codes were from my ELK Version: 6.3.2 and everything works fine before. But, when I've upgraded this week to 7.2 these code not working as expected.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/ee0700ead3f7774c845bbc46cad7a6d0eab63942.png)

Also, tried this:

if (doc['os.keyword'].value != null || doc['os\_major.keyword'].value != null || doc['os\_minor.keyword'].value != null) { return doc['os.keyword'].value + ' ' + doc['os\_major.keyword'].value + '.' + doc['os\_minor.keyword'].value; } return "";

It say...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a14aadf97253dc1199878fa9dc73337a8289046c.png)

Once deleted the scripted field got this.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c6511fb68b6047b356a72595d7a088a825e71b39.png)

---

<div class="post-metadata">

**Author:** ![clintandrewhall](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clintandrewhall/32/45435_2.png) [@clintandrewhall](https://discuss.elastic.co/u/clintandrewhall)\
**Post date:** [July 3, 2019, 3:38pm UTC](https://discuss.elastic.co/t/scripted-field-not-working-properly-in-elk-7-2/188599/2 "2019-07-03T15:38:13Z")

</div>

Good morning! Admittedly, I don't know a lot about scripting in this way, but looking at the logic of your script block, it looks like you have a fundamental mistake: you're checking if things are null, but if one of them isn't, you use all three.

Perhaps you should try:

```auto
var result = '';
if (doc['os.keyword'].value != null) {
  result = result + doc['os.keyword'].value + ' ';
}
// etc
return result;

```

Have you debugged this at all? For example, try the following:

```auto
if (doc['os.keyword'].value != null) { return doc['os.keyword'].value; } return "";

```

If that doesn't work, I can reach out to the team about a bug.

---

<div class="post-metadata">

**Author:** ![mark.quilates](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark.quilates/32/24802_2.png) [@mark.quilates](https://discuss.elastic.co/u/mark.quilates)\
**Post date:** [July 4, 2019, 2:59am UTC](https://discuss.elastic.co/t/scripted-field-not-working-properly-in-elk-7-2/188599/3 "2019-07-04T02:59:14Z")

</div>

@clintandrewhall

Its a bug I guess, since that codes above working fine in my ELK 6.3. But, after upgraded to 7.2 those code not working now.

---

<div class="post-metadata">

**Author:** ![dreamer1](https://avatars.discourse-cdn.com/v4/letter/d/b5e925/32.png) [@dreamer1](https://discuss.elastic.co/u/dreamer1)\
**Post date:** [July 25, 2019, 9:05am UTC](https://discuss.elastic.co/t/scripted-field-not-working-properly-in-elk-7-2/188599/4 "2019-07-25T09:05:41Z")

</div>

Hi @mark.quilates,  
I have the same problem with ver. 6.3.0

> [@Scripted field: Read field data from a document using doc\[‘some\_field’\].value return null in some cases](https://discuss.elastic.co/t/scripted-field-read-field-data-from-a-document-using-doc-some-field-value-return-null-in-some-cases/187385):
>
> hi, on my document I have a field always populated. It's a string field and it can contains data like json or XML. I created this scripted field to find problem. def myField = doc['myfield'].value; if (payload != null){ return payload; } else{ return "payload is null"; } Now, in some cases I can see the payload data, but when I have an XML inside "myField", the scripted fields return "payload is null". I don't know the reason, it's unbelievable. Maybe the length of the string in XML…

They replied that it was a bug in 6.3.0 , but apparently it came back again in later versions(regression?).  
I'd like to know the "stable" version, and maybe before installing and configuring everything...

---

<div class="post-metadata">

**Author:** ![dreamer1](https://avatars.discourse-cdn.com/v4/letter/d/b5e925/32.png) [@dreamer1](https://discuss.elastic.co/u/dreamer1)\
**Post date:** [July 30, 2019, 8:57am UTC](https://discuss.elastic.co/t/scripted-field-not-working-properly-in-elk-7-2/188599/5 "2019-07-30T08:57:52Z")

</div>

Hi,  
I updated just kibana from **6.3.0** to **6.3.2** (I readed on support matrix and this is the latest "minor" version compatible with ELK 6.3.0), but it did **not solve the problem**. the behavior is the same as the previous version 6.3.0.  
Sometimes, the expression _doc['my-field'].value_ seems to be null.  
I just thought it was a Kibana bug but probably it's related to ELK 6.3.0 (6.3.2 stack works for @mark.quilates )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2019, 8:58am UTC](https://discuss.elastic.co/t/scripted-field-not-working-properly-in-elk-7-2/188599/6 "2019-08-27T08:58:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
