# Scripted fields if value exists

**URL:** <https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887>\
**Category:** Kibana\
**Created:** [June 18, 2015, 12:56am UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887 "2015-06-18T00:56:22Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mark\_Farina](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_farina/32/3397_2.png) [@Mark\_Farina](https://discuss.elastic.co/u/Mark_Farina)\
**Post date:** [June 18, 2015, 12:56am UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/1 "2015-06-18T00:56:23Z")

</div>

I'm desperately trying to use the scripted fields feature of Kibana in order to apply a minor transform on a display value. Based on everything I've read in the [scripted fields](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/search-request-script-fields.html#search-request-script-fields) guide and [scripts in aggregation](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#search-aggregations-bucket-terms-aggregation-script) guide, I should be able to do something as simple as the following:

```
if (doc['field_name'].value > 0) { (ceil(doc['field_name'].value) / 1000) / 60 }

```

But when I do that, I end up with an error on every page that says " **Discover: An error occurred with your request. Reset your inputs and try again.**"

Furthermore, if I simply transform the value:

```
(ceil(doc['field_name'].value) / 1000) / 60

```

Everything works great, except when I run a query which contains elements that don't have the doc['field\_name'] in question...hence my attempt at an "if" statement.

Does anyone have a good resource for scripting these fields, or see anything wrong with my logic?

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [June 18, 2015, 5:00am UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/2 "2015-06-18T05:00:58Z")

</div>

Default scripting language for Kibana 4 scripted fields is [Lucene expressions](http://lucene.apache.org/core/4_9_0/expressions/index.html?org/apache/lucene/expressions/js/package-summary.html), which has limited support for conditionals (only a [ternary operator](https://en.wikipedia.org/wiki/%3F:), no "if"). Alternatively, you can try using static Groovy scripts, described here: [Calling groovy script from Kibana](https://discuss.elastic.co/t/calling-groovy-script-from-kibana/2542/3)

---

<div class="post-metadata">

**Author:** ![Mark\_Farina](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_farina/32/3397_2.png) [@Mark\_Farina](https://discuss.elastic.co/u/Mark_Farina)\
**Post date:** [June 18, 2015, 6:25pm UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/3 "2015-06-18T18:25:05Z")

</div>

Yes, I came across the ternary operator, but couldn't get that working either :(. I expected this...

```
(doc['field_name'].empty) ? 0 : (ceil(doc['field_name'].value) / 1000) / 60

```

to produce the desired result. It did not. I assume it's because the simple test for doc['field\_name'] errors since the field may not exist within the resultset.

I would imagine there is an easy way to rule that out, however I can't seem to find it ☹ .

Thank you for your response 😄

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [June 19, 2015, 12:00am UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/4 "2015-06-19T00:00:21Z")

</div>

Kibana scripted fields documentation says: _"If a field is sparse (only some documents contain a value), documents missing the field will have a value of 0"_, which leads me to believe that your expression **(ceil(doc['field\_name'].value) / 1000) / 60** should work without a conditional. What error are you getting when you use that?

---

<div class="post-metadata">

**Author:** ![Mark\_Farina](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_farina/32/3397_2.png) [@Mark\_Farina](https://discuss.elastic.co/u/Mark_Farina)\
**Post date:** [June 19, 2015, 12:45am UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/5 "2015-06-19T00:45:13Z")

</div>

I get that message that says " **Discover: An error occurred with your request. Reset your inputs and try again.**" anytime I execute a query that has a timeframe wider than the dataset. Also, the data I do have fails to load.

For example, I have 7 days worth of data containing the "field\_name." If I use the Discover tab and ask it to give me the last 90 days of data, it returns 7 days worth of data with no error. If I add a scripted field to the system containing just my simple math, and ask for anything over 7 days worth of data, I get that error, and the UI spins forever with no return values.

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [June 19, 2015, 5:33am UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/6 "2015-06-19T05:33:23Z")

</div>

Just to be sure, are you replacing "field\_name" with the name of your field? I indexed a document that is missing the a value for "bytes", which I'm referencing in the same script you tried above. I haven't gotten any failures in Discover and the value of the scripted field is 0, as expected (see screenshots below), without the need for conditionals.

That's not to say that there isn't something else odd going on...

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/2773384751e88e89ae1047cfa8ed152e2261cb30.png)  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0572e70fbf3935a6c9ff48351d742c84c911d116.png)

---

<div class="post-metadata">

**Author:** ![Mark\_Farina](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_farina/32/3397_2.png) [@Mark\_Farina](https://discuss.elastic.co/u/Mark_Farina)\
**Post date:** [June 22, 2015, 9:52pm UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/7 "2015-06-22T21:52:21Z")

</div>

Ya, absolutely :). I've verified the field exists, in fact...it does work as long as I don't hit the buffer of days.

---

<div class="post-metadata">

**Author:** ![Yasho](https://avatars.discourse-cdn.com/v4/letter/y/c2a13f/32.png) [@Yasho](https://discuss.elastic.co/u/Yasho)\
**Post date:** [June 15, 2016, 9:31am UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/8 "2016-06-15T09:31:01Z")

</div>

This should work

(doc['filesize'].value \> 0 && doc['response\_time'].value \> 0) (doc['filesize'].value)/(doc['response\_time'].value) : 0

---

<div class="post-metadata">

**Author:** ![harsh1](https://avatars.discourse-cdn.com/v4/letter/h/6de8d8/32.png) [@harsh1](https://discuss.elastic.co/u/harsh1)\
**Post date:** [September 27, 2016, 4:08am UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/9 "2016-09-27T04:08:16Z")

</div>

Hi

Can anyone help me in this .  
i created a scripted field in kibana  
doc['used memory'].value / doc['total memory'].value  
but the output is not returning anything,the value is blank.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/3/345bf7619783458c3f4653d742c678a56338ecc2.png)

---

<div class="post-metadata">

**Author:** ![sasauz](https://avatars.discourse-cdn.com/v4/letter/s/df705f/32.png) [@sasauz](https://discuss.elastic.co/u/sasauz)\
**Post date:** [February 23, 2017, 9:46am UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/10 "2017-02-23T09:46:27Z")

</div>

I have a same question. In my case only some documents contain a value. If I use script like this **doc['field\_name'].value) / 1000** then all empty fields will fill with 0. It leads to the worng avg value in diagramms. I've try to use script with if-then-else-condition like this **! doc['field\_name'].empty ? doc['field\_name'].value / 1000**, but in this case I need also else condition. or?

Is there some opption to use **do nothing** as else-condition?  
**! doc['field\_name'].empty ? doc['field\_name'].value / 1000 : _do nothing_**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:33pm UTC](https://discuss.elastic.co/t/scripted-fields-if-value-exists/23887/11 "2017-07-06T13:33:01Z")

</div>


