# A few questions around the can\_match feature

**URL:** <https://discuss.elastic.co/t/a-few-questions-around-the-can-match-feature/297713>\
**Category:** Elasticsearch\
**Created:** [February 21, 2022, 5:51am UTC](https://discuss.elastic.co/t/a-few-questions-around-the-can-match-feature/297713 "2022-02-21T05:51:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bryan\_Hamilton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_hamilton/32/82111_2.png) [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Post date:** [February 21, 2022, 5:51am UTC](https://discuss.elastic.co/t/a-few-questions-around-the-can-match-feature/297713/1 "2022-02-21T05:51:10Z")

</div>

Hi, @jpountz and @ruflin. I working on a migration path to migrate our on-prem environment from xxxbeat-\* type indices to datastreams based on the elastic Agent. This will require updating/recreating all sorts of objects in Kibana (visualizations, saved searches, Security rules with EQL queries, ....) as well as queries in python scripts. I this stage I am still experimenting in a lab environment and am trying to understand all about the new indexing strategy in order to come up with the most appropriate migration strategy. I have watched a few a few youtube videos from the Elastic community about the new indexing strategy including [Deep dive into the new Elastic Indexing Strategy - YouTube](https://www.youtube.com/watch?v=ls1O-gB-Voo&t=1457s&ab_channel=OfficialElasticCommunity) and have a basic understaning of how it works.

For Optimization, we would like to take advantage of `constant_keyword` and the `can_match` feature as much as possible. For the sake of this conversation, let's assume I am working with the base index patern of `logs-*` and am trying work with the dataset `system.security`.

From this privious topic, [How does can\_match functionality work](https://discuss.elastic.co/t/how-does-can-match-functionality-work/288164), I understand that for visualization, to use the can\_match feature, I will have to include something like `data_stream.dataset: "system.security"` in the visualization filter. But I have a few more questions to make sure I fully understand the concept and how to take advantage of it.

1. Does the can\_match feature only work when the a condition like `data_stream.dataset: "system.security"` is specified as a **filter**? or does it also work when specified in a **query/query\_string**?  
ex: kibana discover search `'data_stream.dataset: "system.security" and winlog.event_id: "4624"'` with nothing in the discover filter.
2. How would I take advantage of this in an **EQL query**? something like `any where (data_stream.dataset: "system.security" and winlog.event_id: "4624")`?
3. My 3rd question has to do with python queries but I think the answer to question 1 might answer it.

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [February 22, 2022, 12:51pm UTC](https://discuss.elastic.co/t/a-few-questions-around-the-can-match-feature/297713/2 "2022-02-22T12:51:39Z")

</div>

1. If you pass `datastream.dataset:"system.security"` in a `query_string`, Elasticsearch won't be able to skip a shard using the `can_match` phase, but shard requests will still be pretty cheap as Elasticsearch will easily notice that the query cannot possibly match any docs once the query string gets parsed (assuming that the shard has a different value for `datastream.dataset`).
2. EQL uses the query DSL and the `_search` API under the hood, so this will work transparently.

---

<div class="post-metadata">

**Author:** ![Bryan\_Hamilton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_hamilton/32/82111_2.png) [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Post date:** [March 17, 2022, 2:13pm UTC](https://discuss.elastic.co/t/a-few-questions-around-the-can-match-feature/297713/3 "2022-03-17T14:13:32Z")

</div>

Hi @jpountz sorry for the late reply. I have been off work training for a cert. Thanks for your reply.

For Kibana KQL, which would be more optimised for datastreams?  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/7/071b10b888ddc072ebeb5bdd078a4a28a9384083.png)  
or  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/0/e0bda96df06ff7f37aa32ad0630f8ca624f43f65.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2022, 2:14pm UTC](https://discuss.elastic.co/t/a-few-questions-around-the-can-match-feature/297713/4 "2022-04-14T14:14:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
