# Scripted fields for Kibana alerting not showing

**URL:** <https://discuss.elastic.co/t/scripted-fields-for-kibana-alerting-not-showing/281913>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring, elastic-stack-alerting\
**Created:** [August 19, 2021, 7:18am UTC](https://discuss.elastic.co/t/scripted-fields-for-kibana-alerting-not-showing/281913 "2021-08-19T07:18:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![aniket.sonavane](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@aniket.sonavane](https://discuss.elastic.co/u/aniket.sonavane)\
**Post date:** [August 19, 2021, 7:18am UTC](https://discuss.elastic.co/t/scripted-fields-for-kibana-alerting-not-showing/281913/1 "2021-08-19T07:18:29Z")

</div>

**The objective is to setup an email alert on heap\_utilization where heap\_utilization% is greater than 85% group by jvm\_name for production enviroment.**

I am working on elastic stack version 7.13.0 where I also set up APM agents in the production environment. now I am trying to create a rule or alert on JVM heap usage percentage but there is no such prebuild filed available so I have to create an additional field using a scripted field  
"( doc['jvm.memory.heap.used].value / doc['jvm.memory.heap.max'].value ) \* 100"  
as **memoryUsedPct** for index pattern " **apm-\***", this field is visible under discover but for creating rule or email alert the field memoryUsed is not available.

please suggest how to achieve the given objective.

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [August 19, 2021, 3:49pm UTC](https://discuss.elastic.co/t/scripted-fields-for-kibana-alerting-not-showing/281913/2 "2021-08-19T15:49:42Z")

</div>

Hello Aniket!

What rule type is this that you're creating? Is it the index threshold, or elasticsearch query rule type, or is it one of the observability rule types?

---

<div class="post-metadata">

**Author:** ![aniket.sonavane](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@aniket.sonavane](https://discuss.elastic.co/u/aniket.sonavane)\
**Post date:** [August 20, 2021, 11:35am UTC](https://discuss.elastic.co/t/scripted-fields-for-kibana-alerting-not-showing/281913/3 "2021-08-20T11:35:35Z")

</div>

Hi Patrick

Thanks for replying

I'm trying to create an index threshold rule as there is no any pre configured observability rule.

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [August 20, 2021, 12:40pm UTC](https://discuss.elastic.co/t/scripted-fields-for-kibana-alerting-not-showing/281913/4 "2021-08-20T12:40:12Z")

</div>

I just tried, and am unable to use a scripted field defined in a Kibana Index Pattern, in the "grouped over" field. Which means it probably doesn't work for numeric fields used in the actual threshold value being checked.

This did work at some point, so I think we should get an issue opened for this. If you'd like to open one, that's fine, post the link to the issue here and I'll make sure it has all the right labels on it. Or I can open one.

Use the following URL to open a new issue: [Sign in to GitHub · GitHub](https://github.com/elastic/kibana/issues/new?assignees=&labels=bug&template=Bug_report.md)

---

<div class="post-metadata">

**Author:** ![aniket.sonavane](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@aniket.sonavane](https://discuss.elastic.co/u/aniket.sonavane)\
**Post date:** [August 23, 2021, 10:39am UTC](https://discuss.elastic.co/t/scripted-fields-for-kibana-alerting-not-showing/281913/5 "2021-08-23T10:39:42Z")

</div>

HI,  
request to open/create a new issue and share the link to track the issue.

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [August 23, 2021, 12:54pm UTC](https://discuss.elastic.co/t/scripted-fields-for-kibana-alerting-not-showing/281913/6 "2021-08-23T12:54:32Z")

</div>

Thanks for reporting. I've opened the following issue to track:

> <https://github.com/elastic/kibana/issues/109640>
>
> \*\*Kibana version:\*\* 7.14.0
> 
> The index threshold rule type does not list runtim…e fields in the "grouped over" selector, for runtime fields defined in a data view (nee index pattern). I happened to try it on a data view which has a keyword runtime field, and it was not listed as a possibility. It also does not list runtime fields on the "of" selector (when doing an aggregation over a numeric field).
> 
> field definition - the icon to the right of the field name indicates it's scripted; it's type is \`keyword\`:
> 
> !\[image\](https://user-images.githubusercontent.com/25117/130448380-860fe5f0-96a6-4c69-9ffb-ae6a63d0d9ac.png)
> 
> should have appeared here, but didn't:
> 
> !\[image\](https://user-images.githubusercontent.com/25117/130449864-3445b384-c5c6-4813-95fb-82ae26b1b009.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2021, 12:54pm UTC](https://discuss.elastic.co/t/scripted-fields-for-kibana-alerting-not-showing/281913/7 "2021-09-20T12:54:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
