Andrew Mercer
on this page

Scripted fields are deprecated in favour of runtime fields, which are defined in the mapping or data view, run in Elasticsearch, and work in ES|QL and Lens. Before an upgrade or migration, find out where scripted fields are still in use.

Data views are stored as index-pattern saved objects. Their scripted fields are kept in attributes.fields, which is a JSON string, hence the fromjson.

#!/usr/bin/env bash
set -euo pipefail
: "${KIBANA_URL:?set KIBANA_URL}"
: "${ES_API_KEY:?set ES_API_KEY}"

curl -sS --fail \
  "$KIBANA_URL/api/saved_objects/_find?type=index-pattern&per_page=10000" \
  -H "Authorization: ApiKey $ES_API_KEY" \
  -H 'kbn-xsrf: true' |
jq -r '
  .saved_objects[]
  | select(.attributes.fields != null)
  | . as $dv
  | (.attributes.fields | fromjson? // [])
  | map(select(.scripted == true))
  | .[]
  | "data_view=\($dv.attributes.title)\tfield=\(.name)\tscript=\(.script)"
'

No output means no scripted fields in that space. Run it once per space ($KIBANA_URL/s/<space_id>/api/...).

Migrating a scripted field

In Stack Management → Data views → [ view ], add a runtime field with the same name and an equivalent Painless script that uses emit(...) instead of return .... Then delete the scripted field. Test the visualizations that use it before deleting.