# Update Api script and Scripting in Elastic search

**URL:** <https://discuss.elastic.co/t/update-api-script-and-scripting-in-elastic-search/66959>\
**Category:** Elasticsearch\
**Created:** [November 23, 2016, 9:05am UTC](https://discuss.elastic.co/t/update-api-script-and-scripting-in-elastic-search/66959 "2016-11-23T09:05:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shubham\_Agrawal](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@Shubham\_Agrawal](https://discuss.elastic.co/u/Shubham_Agrawal)\
**Post date:** [November 23, 2016, 9:05am UTC](https://discuss.elastic.co/t/update-api-script-and-scripting-in-elastic-search/66959/1 "2016-11-23T09:05:01Z")

</div>

Hi,  
I am trying to use the update api of elasticsearch. In that i can use the script tag to update fields like counter.  
Now my concern is it is said that by default dynamic scripting is off and i dont want to get into any security issues, so can i still use the update api or do i need to turn on the dynamic scripting in it?

elastic search version : 2.3

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 23, 2016, 10:25am UTC](https://discuss.elastic.co/t/update-api-script-and-scripting-in-elastic-search/66959/2 "2016-11-23T10:25:31Z")

</div>

You can write a groovy script file and put it on your nodes as explained here: [https://www.elastic.co/guide/en/elasticsearch/reference/2.3/modules-scripting.html#modules-scripting](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/modules-scripting.html#modules-scripting)

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [November 23, 2016, 3:01pm UTC](https://discuss.elastic.co/t/update-api-script-and-scripting-in-elastic-search/66959/3 "2016-11-23T15:01:54Z")

</div>

And in 5.0 the default language for scripts (painless) is fully sandboxed and enabled by default.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2016, 3:02pm UTC](https://discuss.elastic.co/t/update-api-script-and-scripting-in-elastic-search/66959/4 "2016-12-21T15:02:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
