# Update a variable in a scripted field definition

**URL:** <https://discuss.elastic.co/t/update-a-variable-in-a-scripted-field-definition/301350>\
**Category:** Kibana\
**Created:** [April 1, 2022, 4:01pm UTC](https://discuss.elastic.co/t/update-a-variable-in-a-scripted-field-definition/301350 "2022-04-01T16:01:09Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![uncleAlbert](https://avatars.discourse-cdn.com/v4/letter/u/87869e/32.png) [@uncleAlbert](https://discuss.elastic.co/u/uncleAlbert)\
**Post date:** [April 1, 2022, 4:01pm UTC](https://discuss.elastic.co/t/update-a-variable-in-a-scripted-field-definition/301350/1 "2022-04-01T16:01:10Z")

</div>

Is there a way to update a variable within a scripted field in Kibana? Say I had the following scripted field.

```auto
MAP car ["bob":"toyota"];
if (car.containsKey(doc["owner"].value)){
    return car.get(doc["owner"].value);
}

```

Is it possible through the Kibana API to update the above variable "car" to new mapping?

---

<div class="post-metadata">

**Author:** ![msanz-acclaro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/msanz-acclaro/32/103661_2.png) [@msanz-acclaro](https://discuss.elastic.co/u/msanz-acclaro)\
**Post date:** [April 4, 2022, 7:25am UTC](https://discuss.elastic.co/t/update-a-variable-in-a-scripted-field-definition/301350/2 "2022-04-04T07:25:30Z")

</div>

yes it is, please see example bellow

for "runtime field" `BrandOwner`

```java
Map car = new HashMap(); 
car.put("bob","toyota");
car.put("jane","honda");
if (doc['owner'].size() == 0) {
	emit ("N/A");
} else {
	def keyMap = doc['owner'].value;
	if (car.containsKey(keyMap)){
		emit (car[keyMap]);
	} else {
		emit ("N/A");
	}		
}

```

when `owner = jane`, the field will return `honda`  
when `owner = bob`, the field will return `toyota`  
when `onwer = other`, the field will return `N/A`  
if `owner` does not have value, the field will return `N/A`

I update my maps from time to time, and I have not experienced any issues.

---

<div class="post-metadata">

**Author:** ![uncleAlbert](https://avatars.discourse-cdn.com/v4/letter/u/87869e/32.png) [@uncleAlbert](https://discuss.elastic.co/u/uncleAlbert)\
**Post date:** [April 4, 2022, 4:15pm UTC](https://discuss.elastic.co/t/update-a-variable-in-a-scripted-field-definition/301350/3 "2022-04-04T16:15:22Z")

</div>

Thank you. Is there a programmatic way to update the variable `car` in the above example?

I see you could update the entire field via the Kibana API like with something like: (using BrandOwnder field)

`POST <kibana host>:<port>/api/index_patterns/index_pattern/<index_pattern_id>/runtime_field/BrandOwner`

Is there a good example of using the API to update the a variable within a field? In this example I would like to change the mapping of `car` to say `MAP car ["bob":"ford","jane","lexus"];` but keep the rest of the logic, via the API.

---

<div class="post-metadata">

**Author:** ![msanz-acclaro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/msanz-acclaro/32/103661_2.png) [@msanz-acclaro](https://discuss.elastic.co/u/msanz-acclaro)\
**Post date:** [April 4, 2022, 4:36pm UTC](https://discuss.elastic.co/t/update-a-variable-in-a-scripted-field-definition/301350/4 "2022-04-04T16:36:27Z")

</div>

@uncleAlbert I just edit the runtime field in the UI every time I need to update it (essentially I add more puts). I guess you can do the same thing through the API, you POST the updated code version (all lines, not just some of them), as you mentioned 🙂

> **[Update runtime field API | Kibana Guide \[8.1\] | Elastic](https://www.elastic.co/guide/en/kibana/current/index-patterns-runtime-field-api-update.html)**
>
> Conceptual and step-by-step procedures for using runtime fields, scripted fields, and field formatters.

---

<div class="post-metadata">

**Author:** ![uncleAlbert](https://avatars.discourse-cdn.com/v4/letter/u/87869e/32.png) [@uncleAlbert](https://discuss.elastic.co/u/uncleAlbert)\
**Post date:** [April 4, 2022, 7:01pm UTC](https://discuss.elastic.co/t/update-a-variable-in-a-scripted-field-definition/301350/5 "2022-04-04T19:01:20Z")

</div>

I see. I would like a way automate the process, so the API seems to be my best bet.

From my understanding there is no way to update variables within a runtime field or scripted field via the API. You must overwrite the entire field with the new additions.

---

<div class="post-metadata">

**Author:** ![msanz-acclaro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/msanz-acclaro/32/103661_2.png) [@msanz-acclaro](https://discuss.elastic.co/u/msanz-acclaro)\
**Post date:** [April 5, 2022, 10:57am UTC](https://discuss.elastic.co/t/update-a-variable-in-a-scripted-field-definition/301350/6 "2022-04-05T10:57:10Z")

</div>

from top of my head, and getting into a house that I have not been invited to...

I would maybe version the runtime variable code in github or similar, as a file; then a pipeline should trigger a Kibana API rewrite of the whole runtime field taking the code from the file whenever the file is updated, as last step (I would lint and make some basic checks before).

You could also create another automated event on the other side, to update your script inserting a new line and committing it to the repo, whenever an event triggers the need of a new "put" line.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2022, 10:57am UTC](https://discuss.elastic.co/t/update-a-variable-in-a-scripted-field-definition/301350/7 "2022-05-03T10:57:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
