# Tried making a runtime script to modify field, but now visualize with the index shows all empty fields

**URL:** <https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708>\
**Category:** Kibana\
**Created:** [July 18, 2023, 6:00pm UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708 "2023-07-18T18:00:05Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![michael\_c\_michael](https://avatars.discourse-cdn.com/v4/letter/m/ecccb3/32.png) [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Post date:** [July 18, 2023, 6:00pm UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708/1 "2023-07-18T18:00:05Z")

</div>

I have an index with 130 fields. One field I would like to change ranges over longs: 0, 1, 2.

In order to do this, I added a runtime field with the following description:

```auto
def names = ['0': 'Other', '1':'Friendly', '2': 'Opposing'];

emit(doc['attributes.forceId'].size() > 0 ? names[doc['attributes.forceId'].value.toString()] : null);

```

But I now the index is full of empty fields, with the correct time range, whereas before these fields were full. attributes.forceId has some null data but is filled with 0,1, and 2's. Not sure why the data isn't showing up after adding the runtime field described above.

Error is:

```auto
"Cannot invoke \"String.length()\" because \"v\" is null"

```

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [July 19, 2023, 11:17am UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708/2 "2023-07-19T11:17:15Z")

</div>

A runtime field mapped as a keyword cannot emit a null value.

You need to return a string value instead of `null` in your ternary operator.

My test:

```auto
# Cleanup
DELETE discuss-338708

# Create an index
PUT discus-338708
{
  "mappings": {
    "properties": {
      "ts": {"type": "date"},
      "forceId": { "type": "keyword"}
    }
  }
}

# Add some data
POST discuss-338708/_bulk
{ "index": {}}
{ "ts": "2023-07-19T12:42:55+0200", "forceId": 0}
{ "index": {}}
{ "ts": "2023-07-19T12:22:55+0200", "forceId": 0}
{ "index": {}}
{ "ts": "2023-07-19T12:12:55+0200", "forceId": 1}
{ "index": {}}
{ "ts": "2023-07-19T12:02:55+0200", "forceId": 1}
{ "index": {}}
{ "ts": "2023-07-19T11:52:55+0200", "forceId": 2}
{ "index": {}}
{ "ts": "2023-07-19T11:42:55+0200", "forceId": 2}
{ "index": {}}
{ "ts": "2023-07-19T11:32:55+0200"}
{ "index": {}}
{ "ts": "2023-07-19T11:22:55+0200"}

# Search with a runtime field
GET discuss-338708/_search
{
  "_source": false, 
  "fields": [
    "ts","forceId","mapped"
  ], 
  "runtime_mappings": {
    "mapped": {
      "type": "keyword",
      "script": {
        "source": """
def names = ['0': 'Other', '1':'Friendly', '2': 'Opposing'];
emit(doc['forceId'].size() > 0 ? names[doc['forceId'].value.toString()] : "N/A");
        """
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![michael\_c\_michael](https://avatars.discourse-cdn.com/v4/letter/m/ecccb3/32.png) [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Post date:** [July 30, 2023, 5:03pm UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708/4 "2023-07-30T17:03:56Z")

</div>

I am still getting the error 'cannot invoke string.length() because "v" is null'. I do not understand why, as I am outputting a string in my ternary operator.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [July 31, 2023, 9:54am UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708/5 "2023-07-31T09:54:57Z")

</div>

Can you share a reproducible test as I did to check your script and mappings?

---

<div class="post-metadata">

**Author:** ![michael\_c\_michael](https://avatars.discourse-cdn.com/v4/letter/m/ecccb3/32.png) [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Post date:** [August 1, 2023, 4:15pm UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708/6 "2023-08-01T16:15:36Z")

</div>

Hi Jsanz, I'm sorry but I don't really understand where you run the code you showed above. I'm using Kibana. The data I'm being sent is logs generated by other containers that eventually makes its way to Kibana, so I don't understand how to reproduce your test.

Is there a different engine, like at the command line with a logstash build, where you're executing the above?

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [August 1, 2023, 4:46pm UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708/7 "2023-08-01T16:46:14Z")

</div>

Sorry, I was not explicit about that. The code shared above is expected to be run from the [Kibana Console](https://www.elastic.co/guide/en/kibana/current/console-kibana.html) in the `Dev Tools` section of the `Management` block in the Kibana sidebar. That application is independent of Logstash.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f979fc3dc87044d1f8a4316458f8cdcb32a19f71.png)

The code I shared creates an index, then insert some documents using the [Bulk API](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-bulk.html), to finally execute the runtime field directly on a [search request](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime-search-request.html).

That script, of course, can later be added in the index mapping, or added to the [Kibana Data View](https://www.elastic.co/guide/en/kibana/current/managing-data-views.html#create-runtime-fields), depending on your needs.

---

<div class="post-metadata">

**Author:** ![michael\_c\_michael](https://avatars.discourse-cdn.com/v4/letter/m/ecccb3/32.png) [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Post date:** [August 2, 2023, 1:35pm UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708/8 "2023-08-02T13:35:52Z")

</div>

> [@jsanz](#):
>
> ```auto
> # Cleanup
> DELETE discuss-338708
> 
> # Create an index
> PUT discus-338708
> {
> "mappings": {
> "properties": {
> "ts": {"type": "date"},
> "forceId": { "type": "keyword"}
> }
> }
> }
> 
> # Add some data
> POST discuss-338708/_bulk
> { "index": {}}
> { "ts": "2023-07-19T12:42:55+0200", "forceId": 0}
> { "index": {}}
> { "ts": "2023-07-19T12:22:55+0200", "forceId": 0}
> { "index": {}}
> { "ts": "2023-07-19T12:12:55+0200", "forceId": 1}
> { "index": {}}
> { "ts": "2023-07-19T12:02:55+0200", "forceId": 1}
> { "index": {}}
> { "ts": "2023-07-19T11:52:55+0200", "forceId": 2}
> { "index": {}}
> { "ts": "2023-07-19T11:42:55+0200", "forceId": 2}
> { "index": {}}
> { "ts": "2023-07-19T11:32:55+0200"}
> { "index": {}}
> { "ts": "2023-07-19T11:22:55+0200"}
> 
> # Search with a runtime field
> GET discuss-338708/_search
> {
> "_source": false, 
> "fields": [
> "ts","forceId","mapped"
> ], 
> "runtime_mappings": {
> "mapped": {
> "type": "keyword",
> "script": {
> "source": """
> def names = ['0': 'Other', '1':'Friendly', '2': 'Opposing'];
> emit(doc['forceId'].size() > 0 ? names[doc['forceId'].value.toString()] : "N/A");
> """
> }
> }
> }
> }
> 
> ```

Hey, I'm actually not sure of the problem, as from what I can see in discover, all of the forceID's are 0's, 1's, or 2's; but I'm solving this problem by translating the forceID in a logger that preprocesses the data being sent to kibana.

Thanks for your help though! I'm sure I'll have more questions soon enough.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2023, 1:36pm UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708/9 "2023-08-30T13:36:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
