# Spammed by deprication warnings on scripted fields

**URL:** <https://discuss.elastic.co/t/spammed-by-deprication-warnings-on-scripted-fields/286032>\
**Category:** Kibana\
**Tags:** painless\
**Created:** [October 6, 2021, 1:17pm UTC](https://discuss.elastic.co/t/spammed-by-deprication-warnings-on-scripted-fields/286032 "2021-10-06T13:17:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![flalar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flalar/32/85777_2.png) [@flalar](https://discuss.elastic.co/u/flalar)\
**Post date:** [October 6, 2021, 1:17pm UTC](https://discuss.elastic.co/t/spammed-by-deprication-warnings-on-scripted-fields/286032/1 "2021-10-06T13:17:33Z")

</div>

We' getting spammed in kibana dashboards with following deprecation messages

`Warning: 299 Elasticsearch-7.15.0-79d65f6e357953a5b3cbcc5e2c7c21073d89aa29 "[script][1:1019] Deprecated field [inline] used, expected [source] instead", 299 Elasticsearch-7.15.0-79d65f6e357953a5b3cbcc5e2c7c21073d89aa29 "Use of the joda time method [getMillis()] is deprecated. Use [toInstant().toEpochMilli()] instead."`  
It seems to popup for each search request done by the deadhboard.

We figure these two are related to a scripted field we've implemented to get the local time in hours

`LocalDateTime.ofInstant(Instant.ofEpochMilli(doc['@timestamp'].value.millis), ZoneId.of('Europe/Paris')).getHour()`

We expected this would go away using `LocalDateTime.ofInstant(Instant.ofEpochMilli(doc['@timestamp'].value.toInstant().toEpochMilli()),ZoneId.of('Europe/Paris')).getHour()` instead, but the deprication warning keeps making the dashboards unusable.

Any tips on how to resolve this?

The `Deprecated field [inline] used, expected [source] instead` we have no clue what to do with... any tips on this is also apreciated

---

<div class="post-metadata">

**Author:** ![Jack\_Conradson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_conradson/32/47236_2.png) [@Jack\_Conradson](https://discuss.elastic.co/u/Jack_Conradson)\
**Post date:** [October 6, 2021, 3:32pm UTC](https://discuss.elastic.co/t/spammed-by-deprication-warnings-on-scripted-fields/286032/2 "2021-10-06T15:32:06Z")

</div>

Hi flalar!

Two questions:

1. With the change to the script are you only receiving  
`Deprecated field [inline] used, expected [source] instead`  
deprecation warning now? Or are you still seeing both deprecation messages?

2. Is your Kibana version older than 7.15?

-- Jack

---

<div class="post-metadata">

**Author:** ![flalar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flalar/32/85777_2.png) [@flalar](https://discuss.elastic.co/u/flalar)\
**Post date:** [October 6, 2021, 6:45pm UTC](https://discuss.elastic.co/t/spammed-by-deprication-warnings-on-scripted-fields/286032/3 "2021-10-06T18:45:40Z")

</div>

1. I can confirm both deprication warnings are showing after updating the scripts.
2. Complete stack updated to 7.15. This is when the deprication warnings started getting very bad

---

<div class="post-metadata">

**Author:** ![Jack\_Conradson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_conradson/32/47236_2.png) [@Jack\_Conradson](https://discuss.elastic.co/u/Jack_Conradson)\
**Post date:** [October 7, 2021, 12:00am UTC](https://discuss.elastic.co/t/spammed-by-deprication-warnings-on-scripted-fields/286032/4 "2021-10-07T00:00:24Z")

</div>

Hi flalar,

I tried the specified scripts using the dev tools console in Kibana. Note I replaced `@timestamp` with `dt` in this test. I ran the following:

```auto
PUT /my-index-test
{
  "mappings": {
    "properties": {
      "dt": {
        "type": "date"
      }
    }
  }
}

POST /_scripts/painless/_execute
{
  "script": {
    "inline": "LocalDateTime.ofInstant(
                       Instant.ofEpochMilli(doc['dt'].value.millis), 
                       ZoneId.of('Europe/Paris')).getHour()"
  },
  "context": "score",
  "context_setup": {
    "index": "my-index-test",
    "document": {
      "dt": 1633563238
    }
  }
}

```

This gives me two deprecation warnings and the result as the following:

```auto
#! [script][3:15] Deprecated field [inline] used, 
                  expected [source] instead
#! Use of the joda time method [getMillis()] is deprecated. 
   Use [toInstant().toEpochMilli()] instead.
{
  "result" : 22.0
}

```

I modified this where I changed `inline` to `source` as part of the script DSL structure and used the second specified script.

```auto
POST /_scripts/painless/_execute
{
  "script": {
    "source": "LocalDateTime.ofInstant(
                       Instant.ofEpochMilli(
                       doc['dt'].value.toInstant().toEpochMilli()), 
                       ZoneId.of('Europe/Paris')).getHour()"
  },
  "context": "score",
  "context_setup": {
    "index": "my-index-test",
    "document": {
      "dt": 1633563238
    }
  }
}

```

This removes both deprecations and gives the following result:

```auto
{
  "result" : 22.0
}

```

Is it possible there are other scripts that could causing the deprecation warnings to appear or that your script wasn't updated as part of the visualization?

--Jack

---

<div class="post-metadata">

**Author:** ![flalar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flalar/32/85777_2.png) [@flalar](https://discuss.elastic.co/u/flalar)\
**Post date:** [October 7, 2021, 8:27am UTC](https://discuss.elastic.co/t/spammed-by-deprication-warnings-on-scripted-fields/286032/5 "2021-10-07T08:27:53Z")

</div>

Thanks for your reply @Jack_Conradson

We are basic users of Elastic stack so I assume the dashboards have been built and then the scripted field has been added to provide an option to split the chars and segment the data on hourly basis. This has all been done through standard Kibana interface, no custom query scripting. Dashboard is using some saved queries though... Might that be the reason shomehow?

Tried to delete the scripted field and then the warinings went away, then I created it again with the updated script and now both errors were back 🤔

I saw a notice that scripted fields in general was depricated as well, so will give runtime fields a go as that should provide the same functionality

---

<div class="post-metadata">

**Author:** ![flalar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flalar/32/85777_2.png) [@flalar](https://discuss.elastic.co/u/flalar)\
**Post date:** [October 7, 2021, 9:44am UTC](https://discuss.elastic.co/t/spammed-by-deprication-warnings-on-scripted-fields/286032/6 "2021-10-07T09:44:32Z")

</div>

Converting the scripted field to a runtime field and applying that to all indexes, then updating the dashboards to use that and lastly removing the scripted field did the trick.

Thanks your input @Jack_Conradson

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2021, 9:45am UTC](https://discuss.elastic.co/t/spammed-by-deprication-warnings-on-scripted-fields/286032/7 "2021-11-04T09:45:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
