# Using painless script split(string) don't work

**URL:** <https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215>\
**Category:** Kibana\
**Created:** [June 21, 2017, 7:47am UTC](https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215 "2017-06-21T07:47:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![fatyaha](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@fatyaha](https://discuss.elastic.co/u/fatyaha)\
**Post date:** [June 21, 2017, 7:47am UTC](https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215/1 "2017-06-21T07:47:30Z")

</div>

I use kibana script filed to split domain. The result is not good.  
My code is  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/2/023924e0e04dbd72f78d2d0976665c22e81a4956.png)  
The result follow:  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e7674e01b138faa41b45da3f0dd0f329e576329d.png)

* * *

However, the code can run in restful format normaly.  
like this  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c6786f10ddf835043b1033d682571df73ba23137.png)  
result:  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/4/045682196883cf556939601240cebddc7b6a28d3.png)

* * *

So what is the reason, if possible, please instuct me.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [June 21, 2017, 11:59pm UTC](https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215/2 "2017-06-21T23:59:44Z")

</div>

Scripted fields are great for experimenting with the data to see if you can pull out additional useful information, but if that information absolutely is useful to you, the real way to solve this problem is at ingestion time. Doing this in Logstash, for example, would be way more efficient.

It is not really clear what your expecting. Based on trying to understand the script, do you want the `domain_l2` scripted field in the table to show:

```nohighlight
+---------+-------------+
| Date | mmbiz |
+-----------------------+
| Date | mmbiz |
+-----------------------+
| Date | localhost |
+-----------------------+
| Date | localhost |
+-----------------------+
| Date | pingjs |
+-----------------------+
| Date | pingjs |
+---------+-------------+

```

?

If so, wouldn't a simple regex work better?

---

<div class="post-metadata">

**Author:** ![fatyaha](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@fatyaha](https://discuss.elastic.co/u/fatyaha)\
**Post date:** [June 25, 2017, 11:57am UTC](https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215/3 "2017-06-25T11:57:38Z")

</div>

My problem is to take out the second level domain.  
For example:  
I want to split the [pingjs.qq.com](http://pingjs.qq.com) into the list of [pingjs, qq, com]. Then take the "qq" (the second level domain).  
I tried using this code:  
[https://discuss.elastic.co/uploads/short-url/jFnTVu7yzvPaaxikRsWcthfOPY.png](https://discuss.elastic.co/uploads/short-url/jFnTVu7yzvPaaxikRsWcthfOPY.png)  
but the "String level = /\./.split([pingjs.qq.com](http://pingjs.qq.com))" return the same string, without spliting the original string.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [June 26, 2017, 4:43pm UTC](https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215/4 "2017-06-26T16:43:10Z")

</div>

I got curious how to do this, so I downloaded the Groovy SDK (since Painless is very similar to Groovy) and played around with some test code in Groovy Console:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/9/d/9dfb02f8bc7f4a3916a7872809dbdb2256668d6d.png)

Maybe this will work for you:

```auto
def dom = doc['domain'].value;
String[] level = dom.split(/\./); // split the string per regex
List ss = Arrays.asList(level);
String l2 = ss[1]; // 1-th index is the "second" level
return l2;

```

---

<div class="post-metadata">

**Author:** ![fatyaha](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@fatyaha](https://discuss.elastic.co/u/fatyaha)\
**Post date:** [June 27, 2017, 3:22am UTC](https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215/5 "2017-06-27T03:22:22Z")

</div>

We have similar working code on groovy. However, we need a working painless code. please help us figure out the solution.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [June 27, 2017, 4:01pm UTC](https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215/6 "2017-06-27T16:01:13Z")

</div>

Painless is based on Groovy. I found bugs in your original code where the split wasn't being applied on the string correctly, and you were taking the wrong index from the array of split values. Are you saying the solution I suggested isn't working in your scripted field?

---

<div class="post-metadata">

**Author:** ![fatyaha](https://avatars.discourse-cdn.com/v4/letter/f/d2c977/32.png) [@fatyaha](https://discuss.elastic.co/u/fatyaha)\
**Post date:** [July 6, 2017, 5:15am UTC](https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215/7 "2017-07-06T05:15:25Z")

</div>

You code of "String[] level = dom.split(/./);"  
There is '.' in this line of your code, but Painless script needs '\.';  
I have tried it server times.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2017, 5:15am UTC](https://discuss.elastic.co/t/using-painless-script-split-string-dont-work/90215/8 "2017-08-03T05:15:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
