# URL field formatter - get values of other fields

**URL:** <https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029>\
**Category:** Kibana\
**Created:** [April 30, 2018, 1:43pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029 "2018-04-30T13:43:29Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![nkaenzig](https://avatars.discourse-cdn.com/v4/letter/n/97f17d/32.png) [@nkaenzig](https://discuss.elastic.co/u/nkaenzig)\
**Post date:** [April 30, 2018, 1:43pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/1 "2018-04-30T13:43:29Z")

</div>

Dear Community,

In Kibana there is the option of formatting the fields of an index as a URL (Link).  
What I want to do with this is to trigger a query when clicking on the \_id field of a document, but then issue a query on the same or another index using other fields than \_id as filter arguments.

I know that using {{value}} you can reference the value of the field you are formatting (e.g. \_id=3) and you can then use this value to issue a query when clicking on the link:  
For example:

> &\_a=(columns:!(\_source),index:'packets-\*',query:(query\_string:(query:'"{{value}}"')))

My question is: can you also reference other fields of the same document and use them for a new query?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [April 30, 2018, 4:53pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/2 "2018-04-30T16:53:04Z")

</div>

Field formatters can only access their own field. However, you could create a [scripted field](https://www.elastic.co/guide/en/kibana/6.2/scripted-fields.html) that builds the URL and then just use the formatter to display it as a hyperlink.

---

<div class="post-metadata">

**Author:** ![nkaenzig](https://avatars.discourse-cdn.com/v4/letter/n/97f17d/32.png) [@nkaenzig](https://discuss.elastic.co/u/nkaenzig)\
**Post date:** [April 30, 2018, 6:36pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/3 "2018-04-30T18:36:49Z")

</div>

Yes, this is what I was looking for. Thanks a lot!

---

<div class="post-metadata">

**Author:** ![nkaenzig](https://avatars.discourse-cdn.com/v4/letter/n/97f17d/32.png) [@nkaenzig](https://discuss.elastic.co/u/nkaenzig)\
**Post date:** [May 1, 2018, 4:04pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/4 "2018-05-01T16:04:11Z")

</div>

I've made now quite some progress using scripted fields. However, one thing I could not achieve yet is to set a new time range when clicking on that link.  
In painless I can access the timestamp of my documents using doc['timestamp'].value.  
The time range should be set as follows:  
start time: doc['timestamp'].value  
end time: doc['timestamp'].value+doc['duration'].value]  
...where the 'duration' is of type float and the unit is seconds.

An example of the the timestamp and duration formats:

2017-04-26T00:24:10.957Z (=doc['timestamp'].value)  
0.146696999669075 (=doc['duration'].value)

Using the following link, I am able to set the starttime of the time range. But I could not code the endtime to be doc['timestamp'].value+doc['duration'].value.

`'/app/kibana#/dashboard/e0204410-4d55-11e8-8265-513fea73f2bd?' + '_g=' + '(refreshInterval:(display:Off,pause:!f,value:0)' + ',time:(from:' + '\'' + doc['timestamp'].value + '\'' + ',mode:absolute,to:\'2017-04-27T22:00:00.000Z\'))'`

According to the Kibana documentation, Kibana supports datemath, so I tried something like:

`doc['timestamp'].value + '+' + doc['duration'].value + 's'`

But this gives me a URL parsing error.  
How can I achieve this?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 2, 2018, 7:25pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/5 "2018-05-02T19:25:42Z")

</div>

[Painless](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-getting-started.html) exposes the [Java date time APIs](https://docs.oracle.com/javase/8/docs/api/java/time/package-summary.html), you'll need to use these to do the date math.

---

<div class="post-metadata">

**Author:** ![nkaenzig](https://avatars.discourse-cdn.com/v4/letter/n/97f17d/32.png) [@nkaenzig](https://discuss.elastic.co/u/nkaenzig)\
**Post date:** [May 3, 2018, 11:42am UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/6 "2018-05-03T11:42:59Z")

</div>

Thank you for this hint.  
I now gave this a try and found out that my doc['timestamp'].value belongs to the java class "org.joda.time.MutableDateTime".  
So I looked up the corresponding reference: [MutableDateTime (Joda time 2.2 API)](http://joda-time.sourceforge.net/apidocs/org/joda/time/MutableDateTime.html)

... and found that this class comes with methods to add or subtract timevalues.  
However running e.g

> doc['timestamp'].value.addHours(-1)

...gives me the compile error:

> {"type":"script\_exception","reason":"runtime error","script\_stack":["doc['timestamp'].value.addHours(-1);"," ^---- HERE"],"script":"doc['timestamp'].value.addHours(-1);","lang":"painless","caused\_by":{"type":"illegal\_argument\_exception","reason":"Unable to find dynamic method [addHours] with [1] arguments for class [org.joda.time.MutableDateTime]."}}}]},"status":500}

So painless doesn't seem to find this function. Am I doing something wrong? How can I get access to these functions?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 8, 2018, 3:43pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/7 "2018-05-08T15:43:41Z")

</div>

What version of Kibana and ES are you running?

---

<div class="post-metadata">

**Author:** ![nkaenzig](https://avatars.discourse-cdn.com/v4/letter/n/97f17d/32.png) [@nkaenzig](https://discuss.elastic.co/u/nkaenzig)\
**Post date:** [May 10, 2018, 7:15pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/8 "2018-05-10T19:15:54Z")

</div>

I'm running ES 6.2 and Kibana 6.2

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 14, 2018, 4:18pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/9 "2018-05-14T16:18:41Z")

</div>

Hmmm seems like something changed, I swear Painless didn't used to expose Dates as Joda objects. The ES team is [definitely planning on getting rid of Joda](https://github.com/elastic/elasticsearch/issues/27330) so I'd recommend transforming the Joda object into a Java ZonedDateTime and use that. Give this script a try:

```auto
ZonedDateTime.ofInstant(Instant.ofEpochMilli(doc['@timestamp'].value.getMillis()), ZoneId.of('Z')).minusHours(1);

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2018, 4:33pm UTC](https://discuss.elastic.co/t/url-field-formatter-get-values-of-other-fields/130029/10 "2018-06-11T16:33:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
