# Unable to create scripted filed

**URL:** <https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101>\
**Category:** Kibana\
**Created:** [April 2, 2021, 11:47am UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101 "2021-04-02T11:47:05Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dinesh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dinesh_sharma/32/86511_2.png) [@Dinesh\_Sharma](https://discuss.elastic.co/u/Dinesh_Sharma)\
**Post date:** [April 2, 2021, 11:47am UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101/1 "2021-04-02T11:47:05Z")

</div>

Hi,

I was trying to create an scripted field. Where I was implementing the following logic which is return true if IP is equal to Pi\_IP.

## ''' if (doc['IP.kayword'].value == doc['Pi\_IP.keyword'].value) { retrun "true"; } else{ return "false"; } '''

Error message in preview

{  
"root\_cause": [  
{  
"type": "script\_exception",  
"reason": "compile error",  
"script\_stack": [  
"... '].value)\r\n{\r\n retrun "true";\r\n}\r\nelse{\r\n re ...",  
" ^---- HERE"  
],  
"script": "if (doc['IP.kayword'].value == doc['Pi\_IP.keyword'].value)\r\n{\r\n retrun "true";\r\n}\r\nelse{\r\n return "false";\r\n}",  
"lang": "painless",  
"position": {  
"offset": 74,  
"start": 49,  
"end": 99  
}  
}  
],  
"type": "search\_phase\_execution\_exception",  
"reason": "all shards failed",  
"phase": "query",  
"grouped": true,  
"failed\_shards": [  
{  
"shard": 0,  
"index": "compare\_pim\_index",  
"node": "cvHdUiDSQqGRGScirAwjwQ",  
"reason": {  
"type": "script\_exception",  
"reason": "compile error",  
"script\_stack": [  
"... '].value)\r\n{\r\n retrun "true";\r\n}\r\nelse{\r\n re ...",  
" ^---- HERE"  
],  
"script": "if (doc['IP.kayword'].value == doc['Pi\_IP.keyword'].value)\r\n{\r\n retrun "true";\r\n}\r\nelse{\r\n return "false";\r\n}",  
"lang": "painless",  
"position": {  
"offset": 74,  
"start": 49,  
"end": 99  
},  
"caused\_by": {  
"type": "illegal\_argument\_exception",  
"reason": "invalid sequence of tokens near ['"true"'].",  
"caused\_by": {  
"type": "no\_viable\_alt\_exception",  
"reason": null  
}  
}  
}  
}  
]  
}

* * *

Here are the drop down that I chose:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/2/c2a76b7a9153ee531e4fe2df03be091921418429.png)

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 2, 2021, 12:30pm UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101/2 "2021-04-02T12:30:54Z")

</div>

You have `retrun` vs `return` in line 3.

---

<div class="post-metadata">

**Author:** ![Dinesh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dinesh_sharma/32/86511_2.png) [@Dinesh\_Sharma](https://discuss.elastic.co/u/Dinesh_Sharma)\
**Post date:** [April 2, 2021, 1:25pm UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101/3 "2021-04-02T13:25:34Z")

</div>

Hi,

Now I am getting a new error.  
if (doc['IP'].value == doc['Pim\_IP'].value)  
{  
return "true";  
}  
else{  
return "false";  
}

* * *

Error preview:  
{  
"root\_cause": [  
{  
"type": "script\_exception",  
"reason": "runtime error",  
"script\_stack": [  
"org.elasticsearch.index.mapper.TextFieldMapper$TextFieldType.fielddataBuilder(TextFieldMapper.java:767)",  
"org.elasticsearch.index.fielddata.IndexFieldDataService.getForField(IndexFieldDataService.java:109)",  
"org.elasticsearch.index.query.QueryShardContext.lambda$lookup$2(QueryShardContext.java:462)",  
"org.elasticsearch.search.lookup.SearchLookup.lambda$new$1(SearchLookup.java:57)",  
"org.elasticsearch.search.lookup.LeafDocLookup$1.run(LeafDocLookup.java:71)",  
"org.elasticsearch.search.lookup.LeafDocLookup$1.run(LeafDocLookup.java:68)",  
"java.base/java.security.AccessController.doPrivileged(AccessController.java:312)",  
"org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:68)",  
"org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:26)",  
"if (doc['IP'].value == doc['Pim\_IP'].value)\r\n{\r\n",  
" ^---- HERE"  
],  
"script": " if (doc['IP'].value == doc['Pim\_IP'].value) ...",  
"lang": "painless",  
"position": {  
"offset": 9,  
"start": 1,  
"end": 49  
}  
}  
],  
"type": "search\_phase\_execution\_exception",  
"reason": "all shards failed",  
"phase": "query",  
"grouped": true,  
"failed\_shards": [  
{  
"shard": 0,  
"index": "compare\_pim\_index",  
"node": "cvHdUiDSQqGRGScirAwjwQ",  
"reason": {  
"type": "script\_exception",  
"reason": "runtime error",  
"script\_stack": [  
"org.elasticsearch.index.mapper.TextFieldMapper$TextFieldType.fielddataBuilder(TextFieldMapper.java:767)",  
"org.elasticsearch.index.fielddata.IndexFieldDataService.getForField(IndexFieldDataService.java:109)",  
"org.elasticsearch.index.query.QueryShardContext.lambda$lookup$2(QueryShardContext.java:462)",  
"org.elasticsearch.search.lookup.SearchLookup.lambda$new$1(SearchLookup.java:57)",  
"org.elasticsearch.search.lookup.LeafDocLookup$1.run(LeafDocLookup.java:71)",  
"org.elasticsearch.search.lookup.LeafDocLookup$1.run(LeafDocLookup.java:68)",  
"java.base/java.security.AccessController.doPrivileged(AccessController.java:312)",  
"org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:68)",  
"org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:26)",  
"if (doc['IP'].value == doc['Pim\_IP'].value)\r\n{\r\n",  
" ^---- HERE"  
],  
"script": " if (doc['IP'].value == doc['Pim\_IP'].value) ...",  
"lang": "painless",  
"position": {  
"offset": 9,  
"start": 1,  
"end": 49  
},  
"caused\_by": {  
"type": "illegal\_argument\_exception",  
"reason": "Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [IP] in order to load field data by uninverting the inverted index. Note that this can use significant memory."  
}  
}  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 2, 2021, 1:29pm UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101/4 "2021-04-02T13:29:58Z")

</div>

> [@Dinesh\_Sharma](#):
>
> Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [IP] in order to load field data by uninverting the inverted index. Note that this can use significant memory

The error message you see explains it. What it means in other words is you can't do this on a `text` field and only `keyword`.

If those fields exist then the below should work

```auto
if (doc['IP.keyword'].value == doc['Pim_IP.keyword'].value) {
 return "true";
} else {
 return "false";
}

```

---

<div class="post-metadata">

**Author:** ![Dinesh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dinesh_sharma/32/86511_2.png) [@Dinesh\_Sharma](https://discuss.elastic.co/u/Dinesh_Sharma)\
**Post date:** [April 2, 2021, 1:48pm UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101/5 "2021-04-02T13:48:09Z")

</div>

Hi,

I use the above that you suggested but it gave error that the field not exist in some document. So I modified the code and it is as follows:

if ((doc['IP.keyword'].size() !=0) && (doc['Pim\_IP.keyword'].size() != 0))  
{  
if (doc['IP.keyword'].value == doc['Pim\_IP.keyword'].value)  
{ return "true"; }  
else  
{ return "false"; }  
}

After modification, scripted field is created but it is not working in discover when I choose it. PFA the screenshot.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/4564496ea215018e6613bb8f239a4137a5e2f2c8.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/6/e602083bb095247abd2615c1bda79e2144ab51c6.png)

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 2, 2021, 1:54pm UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101/6 "2021-04-02T13:54:57Z")

</div>

Are the ones showing `-` possibly records that don't have data? Add the `IP.keyword` and `Pim_IP.keyword` fields to your table in Discovery to easily check it.

If the condition in your first `if` statement doesn't match it won't return anything which I guess could be a `-`.

---

<div class="post-metadata">

**Author:** ![Dinesh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dinesh_sharma/32/86511_2.png) [@Dinesh\_Sharma](https://discuss.elastic.co/u/Dinesh_Sharma)\
**Post date:** [April 2, 2021, 2:07pm UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101/7 "2021-04-02T14:07:50Z")

</div>

Hi,

Got it. Thanks man.  
I have one more doubt suppose I have 500 documents and half of them contains "IP.keyword" and half contains "Pim\_IP".keyword. Now I want to apply scripted field to get all the document which will have Pim\_IP(from one docuement) == IP.keyword( from other document). How to achieve this as as far as I know scripted field can be operated only within the document. Please suggest.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 2, 2021, 2:12pm UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101/8 "2021-04-02T14:12:46Z")

</div>

Correct, you can't do that in a scripted field. You might be able to do this via a [transform](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform-overview.html). Basically create a new index based on your required conditions. I have not tested or tried this though.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2021, 2:12pm UTC](https://discuss.elastic.co/t/unable-to-create-scripted-filed/269101/9 "2021-04-30T14:12:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
