# Using script params - elasticsearch output plugin

**URL:** <https://discuss.elastic.co/t/using-script-params-elasticsearch-output-plugin/71693>\
**Category:** Logstash\
**Created:** [January 16, 2017, 8:31am UTC](https://discuss.elastic.co/t/using-script-params-elasticsearch-output-plugin/71693 "2017-01-16T08:31:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [January 16, 2017, 8:31am UTC](https://discuss.elastic.co/t/using-script-params-elasticsearch-output-plugin/71693/1 "2017-01-16T08:31:19Z")

</div>

Hello,

I was trying to use [script params in scripted updates](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-update.html#_scripted_updates) in the elasticsearch output plugin of logstash but I was unsure of how to do it. Currently, we two types of scripted updates:

```
                                script_lang => "painless"
			        script_type => "inline"                                
                                script => '
					ctx._source.name_servers = "%{name_servers}";
					ctx._source.past_name_servers.add("%{past_name_servers}");
				'

```

Where my event has fields "name\_servers" and "past\_name\_servers", it's a flat event object as the content is not nested. Is there a way for me to use script params within logstash?

Thanks in advance!

\*Currently using logstash 5.1.2 and elasticsearch 5.0.1

---

<div class="post-metadata">

**Author:** ![sebz](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@sebz](https://discuss.elastic.co/u/sebz)\
**Post date:** [January 18, 2017, 4:49pm UTC](https://discuss.elastic.co/t/using-script-params-elasticsearch-output-plugin/71693/2 "2017-01-18T16:49:50Z")

</div>

Hi,

You can try following to get logstash event from script. (I do this in file script, but I suppose it works the same way for inline)

params.event.get("name\_servers")

---

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [January 25, 2017, 6:58am UTC](https://discuss.elastic.co/t/using-script-params-elasticsearch-output-plugin/71693/3 "2017-01-25T06:58:38Z")

</div>

Hey,

I wanted to report back and tell you that this did the trick.

Thank you so much!

---

<div class="post-metadata">

**Author:** ![Michael\_Oullion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_oullion/32/46106_2.png) [@Michael\_Oullion](https://discuss.elastic.co/u/Michael_Oullion)\
**Post date:** [January 25, 2017, 10:06am UTC](https://discuss.elastic.co/t/using-script-params-elasticsearch-output-plugin/71693/4 "2017-01-25T10:06:56Z")

</div>

Hello,  
can you put your logstash output config and your script file ?  
It can be very useful.

Regards,

---

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [January 25, 2017, 5:18pm UTC](https://discuss.elastic.co/t/using-script-params-elasticsearch-output-plugin/71693/5 "2017-01-25T17:18:12Z")

</div>

Hello,

I don't have a script file, I use inline. However, using params brought down the number of compilations tremendously as per [the stats api](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-nodes-stats.html).

Output config (with some information populated by an Ansible playbook):

```
output{
		elasticsearch {
			hosts => [{% for host in groups['es_data_nodes'] %}"{{ host }}"{% if not loop.last %},{% endif %}{% endfor %}]
			index => "{{ dest_index}}"
			manage_template => false
			flush_size => {{ batch_size }}
			routing => "%{domain_name}"
			action => "update"
			document_id => "%{domain_name}"
			script_lang => "painless"
			script_type => "inline"
			script => '
				ctx._source.is_registered = params.event.get("is_registered");
				ctx._source.last_deregistered = params.event.get("last_deregistered");
				ctx._source.deregistered_history.add(params.event.get("deregistered_history"));
			'
		}
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2017, 5:18pm UTC](https://discuss.elastic.co/t/using-script-params-elasticsearch-output-plugin/71693/6 "2017-02-22T17:18:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
