# Splitting Using Runtime Field / Scripting Field

**URL:** <https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468>\
**Category:** Elasticsearch\
**Tags:** runtime-fields\
**Created:** [June 20, 2023, 11:10am UTC](https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468 "2023-06-20T11:10:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksaimohan2k](https://avatars.discourse-cdn.com/v4/letter/k/f4b2a3/32.png) [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Post date:** [June 20, 2023, 11:10am UTC](https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468/1 "2023-06-20T11:10:48Z")

</div>

In one of the alerts, in the field host.ip, I am seeing a bunch of IP addresses. So I want to create a scripted or runtime field where I want to split each IP address and place them in a new field like host.ip1 and host.ip2.

Below is the code I used it to split, but it's showing "value not set" . Can anyone let me know the issue

```auto
def ipList = doc['host.ip'].value;
def parts = /,/.split(ipList);
if (parts.length > 0) {
  return parts[0];
} else {
  return;
}

```

Below is the sample Field for reference

```auto
host.ip: ["fe80::7bc0:29c:eb66:5bc4", "192.167.101.229", "fe80::1049:a9ce:a62g:6656", "192.167.180.4"]

```

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [July 10, 2023, 9:19am UTC](https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468/2 "2023-07-10T09:19:55Z")

</div>

Hi @ksaimohan2k,

For scripted fields the correct syntax is to use simply `return` statement.  
But for runtime fields make sure to wrap the result into `emit(...)`. For example:

```auto
if (parts.length > 0) {
  emit(parts[0]);
}

```

---

<div class="post-metadata">

**Author:** ![ksaimohan2k](https://avatars.discourse-cdn.com/v4/letter/k/f4b2a3/32.png) [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Post date:** [July 10, 2023, 10:25am UTC](https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468/3 "2023-07-10T10:25:51Z")

</div>

Thank You @jughosta.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2023, 10:26am UTC](https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468/4 "2023-08-07T10:26:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
