# Busqueda con error en Discoverc

**URL:** <https://discuss.elastic.co/t/busqueda-con-error-en-discoverc/345314>\
**Category:** Kibana\
**Tags:** discover\
**Created:** [October 18, 2023, 4:42pm UTC](https://discuss.elastic.co/t/busqueda-con-error-en-discoverc/345314 "2023-10-18T16:42:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![volivares](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/volivares/32/121400_2.png) [@volivares](https://discuss.elastic.co/u/volivares)\
**Post date:** [October 18, 2023, 4:42pm UTC](https://discuss.elastic.co/t/busqueda-con-error-en-discoverc/345314/1 "2023-10-18T16:42:00Z")

</div>

Hola

Estoy queriendo realizar una búsqueda de una frase dentro de un conjunto de palabras en el "message" y me devuelve el siguiente error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f0ac8b2d82d1af2f39e54892f3bcf9ebabe9e8a.png)

Response:

```auto
{
  "took": 1963,
  "timed_out": false,
  "_shards": {
    "total": 26,
    "successful": 25,
    "skipped": 25,
    "failed": 1,
    "failures": [
      {
        "shard": 0,
        "index": ".ds-log-openshift-8.0.0-2023.10.18-001746",
        "node": "HDA8BQG7SM61JputeQBHTw",
        "reason": {
          "type": "index_out_of_bounds_exception",
          "reason": "index_out_of_bounds_exception: Index 15565 out of bounds for length 15442"
        }
      }
    ]
  },
  "hits": {
    "max_score": null,
    "hits": []
  }
}

```

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [October 18, 2023, 5:11pm UTC](https://discuss.elastic.co/t/busqueda-con-error-en-discoverc/345314/2 "2023-10-18T17:11:32Z")

</div>

Hello @volivares, welcome to the community!

If you remove the message field from the query, does it work? Is this field in all of your documents?

Could you please share the query (text, not an image) and provide a sample document?

---

<div class="post-metadata">

**Author:** ![volivares](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/volivares/32/121400_2.png) [@volivares](https://discuss.elastic.co/u/volivares)\
**Post date:** [October 18, 2023, 7:37pm UTC](https://discuss.elastic.co/t/busqueda-con-error-en-discoverc/345314/3 "2023-10-18T19:37:38Z")

</div>

hi

Share us the query KQL:

```auto

kubernetes.container_name:"unificacion" AND kubernetes.namespace_name:"unificacion-prod" and message: "request starting"

```

example :

```auto
{
  "_index": ".ds-log-openshift-8.0.0-2023.10.18-001747",
  "_id": "2h1FRIsBI0D8kBIGZbvG",
  "_version": 1,
  "_score": 0,
  "_source": {
    "@timestamp": "2023-10-18T19:31:05.318Z",
    "input": {
      "type": "syslog"
    },
    "openshift": {
      "sequence": 66666160,
      "cluster_id": "97261e16-3ece-42ee-8206-9b12063ef32b"
    },
    "log": {
      "source": {
        "address": "10.250.8.72:49350"
      }
    },
    "message": "[16:31:05 INF] Request starting HTTP/1.1 GET http://x/api/V1/unificacion/resultsGoogleRouteApi?q=GAONA%20%202916&f=UriSearch application/json ",
    "ecs": {
      "version": "8.0.0"
    },
    "event": {
      "severity": 7
    },
    "hostname": "x",
    "host": {
      "name": "filebeat-3-4p4mf"
    },
    "process": {
      "name": "ocpprod",
      "entity_id": "-"
    },
    "agent": {
      "ephemeral_id": "87bdf49d-e1d1-44d4-a709-b21a0910c633",
      "id": "041f669d-325c-4ede-9e46-fd2308a6cbea",
      "name": "filebeat-3-4p4mf",
      "type": "filebeat",
      "version": "8.0.0"
    },
    "kubernetes": {
      "namespace_name": "unificacion-prod",
      "pod_ip": "10.250.8.209",
      "host": "x",
      "container_name": "unificacion",
      "pod_name": "unificacion-29-xspz4",
      "pod_id": "986d49ee-5bdb-409e-a78b-845996157245",
      "flat_labels": [
        "app=unificacion",
        "deployment=unificacion-29",
        "deploymentconfig=unificacion",
        "log=clusterlogging",
        "source=cicd"
      ]
    }
  },
  "fields": {
    "kubernetes.pod_ip": [
      "10.250.8.209"
    ],
    "process.name.text": [
      "ocpprod"
    ],
    "process.entity_id": [
      "-"
    ],
    "agent.type": [
      "filebeat"
    ],
    "hostname": [
      "x"
    ],
    "agent.name": [
      "filebeat-3-4p4mf"
    ],
    "host.name": [
      "filebeat-3-4p4mf"
    ],
    "kubernetes.host": [
      "x"
    ],
    "kubernetes.flat_labels": [
      "app=unificacion",
      "deployment=unificacion-29",
      "deploymentconfig=unificacion",
      "log=clusterlogging",
      "source=cicd"
    ],
    "event.severity": [
      7
    ],
    "kubernetes.container_name": [
      "unificacion"
    ],
    "input.type": [
      "syslog"
    ],
    "agent.hostname": [
      "filebeat-3-4p4mf"
    ],
    "message": [
      "[16:31:05 INF] Request starting HTTP/1.1 GET http://x/api/V1/unificacion/resultsGoogleRouteApi?q=GAONA%20%202916&f=UriSearch application/json "
    ],
    "kubernetes.namespace_name": [
      "unificacion-prod"
    ],
    "process.name": [
      "x"
    ],
    "@timestamp": [
      "2023-10-18T19:31:05.318Z"
    ],
    "agent.id": [
      "041f669d-325c-4ede-9e46-fd2308a6cbea"
    ],
    "ecs.version": [
      "8.0.0"
    ],
    "kubernetes.pod_id": [
      "986d49ee-5bdb-409e-a78b-845996157245"
    ],
    "openshift.sequence": [
      66666160
    ],
    "log.source.address": [
      "x"
    ],
    "openshift.cluster_id": [
      "97261e16-3ece-42ee-8206-9b12063ef32b"
    ],
    "agent.ephemeral_id": [
      "87bdf49d-e1d1-44d4-a709-b21a0910c633"
    ],
    "agent.version": [
      "8.0.0"
    ],
    "kubernetes.pod_name": [
      "unificacion-29-xspz4"
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [October 18, 2023, 8:34pm UTC](https://discuss.elastic.co/t/busqueda-con-error-en-discoverc/345314/4 "2023-10-18T20:34:08Z")

</div>

Thanks for the info.

Apparently `kubernetes.container_name` and `kubernetes.namespace_name` are keywords and you are searching for the specific keyword and the message field is a text value and you want to search for a text that contains `“request starting”` as part of the message. Is that it?

Could you please try to do this with a `wildcard query`?

It will be:

`kubernetes.container_name:"unificacion" AND kubernetes.namespace_name:"unificacion-prod" and message: *starting*`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 15, 2023, 8:34pm UTC](https://discuss.elastic.co/t/busqueda-con-error-en-discoverc/345314/5 "2023-11-15T20:34:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
