# "Add filter", "contains"-operator?

**URL:** <https://discuss.elastic.co/t/add-filter-contains-operator/105754>\
**Category:** Kibana\
**Created:** [October 30, 2017, 11:28am UTC](https://discuss.elastic.co/t/add-filter-contains-operator/105754 "2017-10-30T11:28:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![CarlKnutsen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlknutsen/32/22752_2.png) [@CarlKnutsen](https://discuss.elastic.co/u/CarlKnutsen)\
**Post date:** [October 30, 2017, 11:28am UTC](https://discuss.elastic.co/t/add-filter-contains-operator/105754/1 "2017-10-30T11:28:56Z")

</div>

Hi there,

I am wondering why there doesn't exist a "contains" operator in the "Add filter"-window. I'd like to do something like this:

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a7541add4a2c59fdf283af4aff12550f1185d263.png)

When I select "is" I am getting no result. But when I enter "message:\*test\*" in the search bar I do.

Of course you can always do:

![image](https://us1.discourse-cdn.com/elastic/original/3X/6/c/6c4012ad7031f16db2d6c83ca167cc78bdb472a4.png)

But that is rather complicated just to add a filter for some users... Is there a reason that there is no operator in the UI doing that?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 30, 2017, 12:44pm UTC](https://discuss.elastic.co/t/add-filter-contains-operator/105754/2 "2017-10-30T12:44:20Z")

</div>

Leading wildcard queries are very inefficient and should be avoided. I would therefore recommend extracting the information at index time so you can use an operator that scales and performs better.

---

<div class="post-metadata">

**Author:** ![CarlKnutsen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlknutsen/32/22752_2.png) [@CarlKnutsen](https://discuss.elastic.co/u/CarlKnutsen)\
**Post date:** [October 30, 2017, 1:14pm UTC](https://discuss.elastic.co/t/add-filter-contains-operator/105754/3 "2017-10-30T13:14:29Z")

</div>

Yeah, that is right of course. But why can you enter "\*test\*" in the search bar, but cannot set a field filter "message:\*test\*"? I think the latter isn't as costly as the first...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2017, 1:14pm UTC](https://discuss.elastic.co/t/add-filter-contains-operator/105754/4 "2017-11-27T13:14:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
