# \#painless

**URL:** https://discuss.elastic.co/tag/painless/19.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Truncate a Mustache variable in an Alerting rule action (e.g. limit a long text field to N words)?](https://discuss.elastic.co/t/truncate-a-mustache-variable-in-an-alerting-rule-action-e-g-limit-a-long-text-field-to-n-words/389290)

<div class="topic-metadata">

**Author:** [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Replies:** 2\
**Last updated:** [August 13, 2026, 5:23am UTC](https://discuss.elastic.co/t/truncate-a-mustache-variable-in-an-alerting-rule-action-e-g-limit-a-long-text-field-to-n-words/389290 "2026-08-13T05:23:43Z")

</div>

Hello Team, Kibana version: 9.x We have a rule (Elasticsearch query rule type) that runs every few minutes against an index of banking transaction logs. When it matches, the action is an Index connector that writes a s…

---

## [How to break down (terms aggregation) in Kibana Lens by a sub-key of a flattened field (other than a runtime field)](https://discuss.elastic.co/t/how-to-break-down-terms-aggregation-in-kibana-lens-by-a-sub-key-of-a-flattened-field-other-than-a-runtime-field/388352)

<div class="topic-metadata">

**Author:** [@shojiiii](https://discuss.elastic.co/u/shojiiii)\
**Replies:** 0\
**Last updated:** [July 15, 2026, 4:43am UTC](https://discuss.elastic.co/t/how-to-break-down-terms-aggregation-in-kibana-lens-by-a-sub-key-of-a-flattened-field-other-than-a-runtime-field/388352 "2026-07-15T04:43:38Z")

</div>

Environment Elasticsearch / Kibana: 8.14.0 ~several million to ~10 million documents per index (daily indices) What I want to do In Kibana Lens, I want to break down (Top values / terms aggregation) by the value of a…

---

## [Elastic - MISP Integration shows total Indicators ( fortigate logs)](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132)

<div class="topic-metadata">

**Author:** [@4l13v](https://discuss.elastic.co/u/4l13v)\
**Replies:** 5\
**Last updated:** [February 24, 2026, 11:07am UTC](https://discuss.elastic.co/t/elastic-misp-integration-shows-total-indicators-fortigate-logs/385132 "2026-02-24T11:07:56Z")

</div>

Hello community. I am having big issue right now. I have Integrated Fortigate and Elastic. Then attempted to integrate MISP to Elastic. Integration was well till \[Logs MISP\] Dashboard was thinking Total Indicators coun…

---

## [Watcher chain results not in the ctx.payload for a condition](https://discuss.elastic.co/t/watcher-chain-results-not-in-the-ctx-payload-for-a-condition/384574)

<div class="topic-metadata">

**Author:** [@Joey\_Visbeen](https://discuss.elastic.co/u/Joey_Visbeen)\
**Replies:** 2\
**Last updated:** [January 19, 2026, 9:50am UTC](https://discuss.elastic.co/t/watcher-chain-results-not-in-the-ctx-payload-for-a-condition/384574 "2026-01-19T09:50:01Z")

</div>

Lately I ran into an issue I am trying to make a watcher. The main purpose is to see if the elastic agents we are running are still producing logs. The agents run on different hosts, therefore the query on the host names…

---

## [Error: rejected execution of coordinating operation \[coordinating\_and\_primary\_bytes=0, replica\_bytes=0, all\_bytes=0, coordinating\_operation\_bytes=130953165, max\_coordinating\_bytes=107374182\]"](https://discuss.elastic.co/t/error-rejected-execution-of-coordinating-operation-coordinating-and-primary-bytes-0-replica-bytes-0-all-bytes-0-coordinating-operation-bytes-130953165-max-coordinating-bytes-107374182/382813)

<div class="topic-metadata">

**Author:** [@Peng\_Dong](https://discuss.elastic.co/u/Peng_Dong)\
**Replies:** 0\
**Last updated:** [October 18, 2025, 9:14pm UTC](https://discuss.elastic.co/t/error-rejected-execution-of-coordinating-operation-coordinating-and-primary-bytes-0-replica-bytes-0-all-bytes-0-coordinating-operation-bytes-130953165-max-coordinating-bytes-107374182/382813 "2025-10-18T21:14:00Z")

</div>

Hi, was trying to re-index in elastic. Using the command below: POST \_reindex?wait\_for\_completion=false&requests\_per\_second=50 { "source": { "index": "prod-application-2025", "size": 200 }, "dest": { …

---

## [javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/381314)

<div class="topic-metadata">

**Author:** [@gadde36256](https://discuss.elastic.co/u/gadde36256)\
**Replies:** 1\
**Last updated:** [September 29, 2025, 12:19pm UTC](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/381314 "2025-09-29T12:19:53Z")

</div>

I was trying to access Cassandra data as input jdbc using ing-bank driver with mtls certs, I was always getting bad certificate error with below error on latest version of logstash 9.1.2. Same certs are working with pyt…

---

## [Elasticsearch enrich policy not reflecting updated source after \_execute (v9.1.3)](https://discuss.elastic.co/t/elasticsearch-enrich-policy-not-reflecting-updated-source-after-execute-v9-1-3/382141)

<div class="topic-metadata">

**Author:** [@Daniel\_Santos1](https://discuss.elastic.co/u/Daniel_Santos1)\
**Replies:** 2\
**Last updated:** [September 23, 2025, 12:01am UTC](https://discuss.elastic.co/t/elasticsearch-enrich-policy-not-reflecting-updated-source-after-execute-v9-1-3/382141 "2025-09-23T00:01:25Z")

</div>

Hi, I’m running into an issue with enrich policies in Elasticsearch v9.1.3. When I update the source index used by an enrich policy and then re-execute the policy, the enrich simulation still returns stale data. The upd…

---

## [How to pass the dynamic date in the body section of http input in the Watcher config](https://discuss.elastic.co/t/how-to-pass-the-dynamic-date-in-the-body-section-of-http-input-in-the-watcher-config/382024)

<div class="topic-metadata">

**Author:** [@Ria\_Shah](https://discuss.elastic.co/u/Ria_Shah)\
**Replies:** 1\
**Last updated:** [September 18, 2025, 11:08am UTC](https://discuss.elastic.co/t/how-to-pass-the-dynamic-date-in-the-body-section-of-http-input-in-the-watcher-config/382024 "2025-09-18T11:08:18Z")

</div>

The below is my watcher config and I want to pass the dynamic date in the body part so that it can take the current date in MM-dd-yyyy format to call the REST aPI endpoint: { "trigger": { "schedule": { "inte…

---

## [Results search use script query not true?](https://discuss.elastic.co/t/results-search-use-script-query-not-true/381561)

<div class="topic-metadata">

**Author:** [@lehoangHUST](https://discuss.elastic.co/u/lehoangHUST)\
**Replies:** 1\
**Last updated:** [September 8, 2025, 6:37am UTC](https://discuss.elastic.co/t/results-search-use-script-query-not-true/381561 "2025-09-08T06:37:00Z")

</div>

I have a problem that requires finding the value corresponding to the label. I have a query with the following script: GET hawkcam\_object\_v3\_test/\_search { "query": { "bool": { "filter": \[ { …

---

## [Elastic Watcher migration to Rules Issue's](https://discuss.elastic.co/t/elastic-watcher-migration-to-rules-issues/381617)

<div class="topic-metadata">

**Author:** [@Sarada](https://discuss.elastic.co/u/Sarada)\
**Replies:** 1\
**Last updated:** [September 5, 2025, 5:41am UTC](https://discuss.elastic.co/t/elastic-watcher-migration-to-rules-issues/381617 "2025-09-05T05:41:53Z")

</div>

Hi All, I migrating watchers to Rules, I do have a watcher that compares previous value from last entry and alerts if not same. This works perfectly in watcher as we wrote aggs and painless script but as we are migratin…

---

## [PostgreSQL Functionality Equivalent to Elasticsearch Painless Scripts](https://discuss.elastic.co/t/postgresql-functionality-equivalent-to-elasticsearch-painless-scripts/381559)

<div class="topic-metadata">

**Author:** [@samrinkomai](https://discuss.elastic.co/u/samrinkomai)\
**Replies:** 3\
**Last updated:** [September 3, 2025, 1:21pm UTC](https://discuss.elastic.co/t/postgresql-functionality-equivalent-to-elasticsearch-painless-scripts/381559 "2025-09-03T13:21:28Z")

</div>

In elasticsearch I often use painless script inside searches to calculate values dynamically ay query time, for example by manipulating a timestamp field or deriving custom numeric values. Now I am working on a project w…

---

## [Using dense\_vector with script params](https://discuss.elastic.co/t/using-dense-vector-with-script-params/380908)

<div class="topic-metadata">

**Author:** [@joellupfer](https://discuss.elastic.co/u/joellupfer)\
**Replies:** 1\
**Last updated:** [August 8, 2025, 3:07pm UTC](https://discuss.elastic.co/t/using-dense-vector-with-script-params/380908 "2025-08-08T15:07:46Z")

</div>

Hello! I am currently developing a script that utilizes text embedding vectors. The relevant portion of the mapping is shown below (please disregard the remaining parts, as this is intended solely for testing purposes). …

---

## [Runtime field script error: Cannot cast from \[java.lang.String\] to \[void\] in Kibana 8.17](https://discuss.elastic.co/t/runtime-field-script-error-cannot-cast-from-java-lang-string-to-void-in-kibana-8-17/380517)

<div class="topic-metadata">

**Author:** [@Hendrawns](https://discuss.elastic.co/u/Hendrawns)\
**Replies:** 2\
**Last updated:** [July 30, 2025, 2:10am UTC](https://discuss.elastic.co/t/runtime-field-script-error-cannot-cast-from-java-lang-string-to-void-in-kibana-8-17/380517 "2025-07-30T02:10:15Z")

</div>

Hi everyone, I'm working with Kibana 8.17 and trying to create a runtime field using a Painless script to tag http.request.referrer into sectors based on domains. I followed the docs here: Goal: Create a runtime field…

---

## [Cannot cast from \[java.lang.String\] to \[char\] error](https://discuss.elastic.co/t/cannot-cast-from-java-lang-string-to-char-error/380243)

<div class="topic-metadata">

**Author:** [@Simriti\_Bundhoo](https://discuss.elastic.co/u/Simriti_Bundhoo)\
**Replies:** 4\
**Last updated:** [July 21, 2025, 7:11am UTC](https://discuss.elastic.co/t/cannot-cast-from-java-lang-string-to-char-error/380243 "2025-07-21T07:11:14Z")

</div>

Hello, I am currently learning painless and one of the exercises is to associate letter grades to a range of numbers. I have been stuck on a specific error which is: { "error": { "root\_cause": \[ { "t…

---

## [Ingest pipeline is not working for given document](https://discuss.elastic.co/t/ingest-pipeline-is-not-working-for-given-document/379099)

<div class="topic-metadata">

**Author:** [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)\
**Replies:** 6\
**Last updated:** [June 11, 2025, 5:02pm UTC](https://discuss.elastic.co/t/ingest-pipeline-is-not-working-for-given-document/379099 "2025-06-11T17:02:45Z")

</div>

i have below record which i want to process. \[ { "\_id": "GFk-X5cBY6REVzo7i86y", "\_index": "processor\_test", "\_source": { "event.original":"172.16.102.98 - - \[11/Jun/2025:19:05:43 +0530\] \\"POST /api/…

---

## [How to show fild's contain throught connector log](https://discuss.elastic.co/t/how-to-show-filds-contain-throught-connector-log/379125)

<div class="topic-metadata">

**Author:** [@Dariia\_Hrebenichenko](https://discuss.elastic.co/u/Dariia_Hrebenichenko)\
**Replies:** 2\
**Last updated:** [June 12, 2025, 1:27pm UTC](https://discuss.elastic.co/t/how-to-show-filds-contain-throught-connector-log/379125 "2025-06-12T13:27:50Z")

</div>

Hello there! I'm working on an alerting system. I use Kibana connector log and Logstash to sand emails. For now I have rule to show just a count of files, but I would like to see the contain of field. For example, I …

---

## [Fetch top k frequent fields](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928)

<div class="topic-metadata">

**Author:** [@Parthpuri\_Goswami](https://discuss.elastic.co/u/Parthpuri_Goswami)\
**Replies:** 3\
**Last updated:** [June 6, 2025, 7:53am UTC](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928 "2025-06-06T07:53:57Z")

</div>

Hi all, I want to fetch the top k fields that are most frequent in the last 5 minutes of documents or in whole index. I have tried some queries, as shown below, to get the desired output, but it's taking a long time. I …

---

## [Vector functions in script fields context](https://discuss.elastic.co/t/vector-functions-in-script-fields-context/378254)

<div class="topic-metadata">

**Author:** [@ksalomatin](https://discuss.elastic.co/u/ksalomatin)\
**Replies:** 0\
**Last updated:** [May 17, 2025, 12:02am UTC](https://discuss.elastic.co/t/vector-functions-in-script-fields-context/378254 "2025-05-17T00:02:18Z")

</div>

Hi! I need to compute two vector similarities during search and return them as fields. Both fields are needed for downstream processing, so I cannot use scoring context that only returns a single combined score. This ol…

---

## [Can't access keySet of document on scripted query](https://discuss.elastic.co/t/cant-access-keyset-of-document-on-scripted-query/378097)

<div class="topic-metadata">

**Author:** [@laxopix](https://discuss.elastic.co/u/laxopix)\
**Replies:** 0\
**Last updated:** [May 13, 2025, 6:29pm UTC](https://discuss.elastic.co/t/cant-access-keyset-of-document-on-scripted-query/378097 "2025-05-13T18:29:11Z")

</div>

I was trying to get all the document keys through the keySet() method in a scripted painless query { …

---

## [Transform script fails to index into destination data stream](https://discuss.elastic.co/t/transform-script-fails-to-index-into-destination-data-stream/378012)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [May 11, 2025, 11:52am UTC](https://discuss.elastic.co/t/transform-script-fails-to-index-into-destination-data-stream/378012 "2025-05-11T11:52:02Z")

</div>

I'm on v.8.18 and trying to make my first transform script which should correlate a start and end event from a source index and then calculate the process time in ms as the time difference between start and end events an…

---

## [Nested fields Issues - Remove / rename](https://discuss.elastic.co/t/nested-fields-issues-remove-rename/377447)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 3\
**Last updated:** [April 24, 2025, 1:09pm UTC](https://discuss.elastic.co/t/nested-fields-issues-remove-rename/377447 "2025-04-24T13:09:55Z")

</div>

Hi, Can someone help me on the below issue. I have a nested object where i am unable to rename or remove such fields. Below is the format of such field. test.test1.test2.test3.test4.test5 It has 4 objects and 1 field…

---

## [Elasticsearch server is not starting](https://discuss.elastic.co/t/elasticsearch-server-is-not-starting/377051)

<div class="topic-metadata">

**Author:** [@mithun321](https://discuss.elastic.co/u/mithun321)\
**Replies:** 5\
**Last updated:** [April 12, 2025, 12:22pm UTC](https://discuss.elastic.co/t/elasticsearch-server-is-not-starting/377051 "2025-04-12T12:22:32Z")

</div>

I'm getting this error I'm starting Elasticsearch server Job for elasticsearch.service failed because the control process exited with error code. See "systemctl status elasticsearch.service" and "journalctl -xeu elasti…

---

## [Creating a New Keyword Field at Runtime from Two Existing Fields](https://discuss.elastic.co/t/creating-a-new-keyword-field-at-runtime-from-two-existing-fields/376193)

<div class="topic-metadata">

**Author:** [@Shubham\_Pant](https://discuss.elastic.co/u/Shubham_Pant)\
**Replies:** 3\
**Last updated:** [April 4, 2025, 4:39pm UTC](https://discuss.elastic.co/t/creating-a-new-keyword-field-at-runtime-from-two-existing-fields/376193 "2025-04-04T16:39:03Z")

</div>

I need to create a new field dynamically at runtime using two existing fields, and the new field should be of type "keyword". I attempted this using Painless scripting, but it's not working and throws a type casting err…

---

## [Indexing rate for data streams](https://discuss.elastic.co/t/indexing-rate-for-data-streams/376566)

<div class="topic-metadata">

**Author:** [@Dr00py](https://discuss.elastic.co/u/Dr00py)\
**Replies:** 3\
**Last updated:** [April 2, 2025, 4:50pm UTC](https://discuss.elastic.co/t/indexing-rate-for-data-streams/376566 "2025-04-02T16:50:17Z")

</div>

I want to calculate the indexing speed of documents in primary shards in my data streams. When monitoring is enabled, I can see the index rate for each index. But I can't do this for any data stream from my clusters. I …

---

## [Kibana Shows Black Screen After Login Need Help](https://discuss.elastic.co/t/kibana-shows-black-screen-after-login-need-help/375155)

<div class="topic-metadata">

**Author:** [@xirawa](https://discuss.elastic.co/u/xirawa)\
**Replies:** 3\
**Last updated:** [March 2, 2025, 4:26am UTC](https://discuss.elastic.co/t/kibana-shows-black-screen-after-login-need-help/375155 "2025-03-02T04:26:47Z")

</div>

Hi Everyone, I recently upgraded my Elastic Stack version X.X and now when I try to access Kibana, all I see is a black screen after logging in. The browser loads the Kibana interface, but no content appears. Elasticse…

---

## [ECK 8.17.3 "memory locking requested for elasticsearch process but memory is not locked"](https://discuss.elastic.co/t/eck-8-17-3-memory-locking-requested-for-elasticsearch-process-but-memory-is-not-locked/376302)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 2\
**Last updated:** [March 24, 2025, 8:06am UTC](https://discuss.elastic.co/t/eck-8-17-3-memory-locking-requested-for-elasticsearch-process-but-memory-is-not-locked/376302 "2025-03-24T08:06:29Z")

</div>

I have the following config: config: # most Elasticsearch configuration parameters are possible to set, e.g: node.attr.attr\_name: attr\_value #node.roles: \["master", "data", "ingest", "ml"\] …

---

## [False alert for watcher](https://discuss.elastic.co/t/false-alert-for-watcher/376115)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 0\
**Last updated:** [March 19, 2025, 10:40am UTC](https://discuss.elastic.co/t/false-alert-for-watcher/376115 "2025-03-19T10:40:42Z")

</div>

We have a watcher to check a java process for an application on two servers. But issue is that the application team use to get false alerts from ELK even the processes are up . { "trigger": { "schedule": { "…

---

## [Watcher for monitor a process does not work](https://discuss.elastic.co/t/watcher-for-monitor-a-process-does-not-work/376064)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 1\
**Last updated:** [March 18, 2025, 1:35pm UTC](https://discuss.elastic.co/t/watcher-for-monitor-a-process-does-not-work/376064 "2025-03-18T13:35:39Z")

</div>

We have created a watcher to monitor a process in a linux server but it does not fired and only taking the sleeping state of the process . { "trigger": { "schedule": { "interval": "5m" } }, "input": …

---

## [Wrong returned Values on simple SUM-Aggregation and scale up/down](https://discuss.elastic.co/t/wrong-returned-values-on-simple-sum-aggregation-and-scale-up-down/375960)

<div class="topic-metadata">

**Author:** [@Manoj\_Upadhyay](https://discuss.elastic.co/u/Manoj_Upadhyay)\
**Replies:** 4\
**Last updated:** [March 17, 2025, 4:12pm UTC](https://discuss.elastic.co/t/wrong-returned-values-on-simple-sum-aggregation-and-scale-up-down/375960 "2025-03-17T16:12:58Z")

</div>

Trying to sum/stats of transaction amounts for given search criteria but sum/stats amount is getting rounded up/down in place of returning decimal 2 positions. Below is one transaction data. The transactionAmount field i…

---

## [Kibana APM does not show data even though there is APM data](https://discuss.elastic.co/t/kibana-apm-does-not-show-data-even-though-there-is-apm-data/375750)

<div class="topic-metadata">

**Author:** [@rodolk](https://discuss.elastic.co/u/rodolk)\
**Replies:** 17\
**Last updated:** [March 12, 2025, 10:26pm UTC](https://discuss.elastic.co/t/kibana-apm-does-not-show-data-even-though-there-is-apm-data/375750 "2025-03-12T22:26:37Z")

</div>

Kibana i snot showing data when I go to Observability-\>APM-\>Services It doesn't show data neither in services, nor traces, nor dependencies Kibana version: 8.15.3 Elasticsearch version: 8.15.3 APM Server version: 8.1…

[Next page](https://discuss.elastic.co/tag/painless/19.md?match_all_tags=true&page=1&tags%5B%5D=painless)
