# Can't exact match the keyword which ends with equal mark

**URL:** <https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336>\
**Category:** Kibana\
**Created:** [April 14, 2016, 3:02am UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336 "2016-04-14T03:02:13Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![aqiao](https://avatars.discourse-cdn.com/v4/letter/a/e274bd/32.png) [@aqiao](https://discuss.elastic.co/u/aqiao)\
**Post date:** [April 14, 2016, 3:02am UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/1 "2016-04-14T03:02:13Z")

</div>

i want to get all the events which Item equal EUR=,in Kibana 4.4.1 search box,i input the filter like this Item:"ERU=",however i get the following  
EUR=  
EUR=Q  
EUR=P  
I mean i just want to get EUR= events, i check the HTML source code in chrome and find some interesting code:

`<td class="discover-table-datafield"><mark>EUR</mark>=</td>`

but when i type Item:"PQR=", it works fine,below is the html source code

`<td class="discover-table-datafield">PQR=</td>`

So "EUR" is key word in Kibana ?, or if i make some mistakes

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 15, 2016, 6:27pm UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/2 "2016-04-15T18:27:52Z")

</div>

I think your post got mangled somehow, specifically the `=` bits after "interesting code:" and "other fields are:". Can you edit your post so it displays what you were trying to show?

---

<div class="post-metadata">

**Author:** ![aqiao](https://avatars.discourse-cdn.com/v4/letter/a/e274bd/32.png) [@aqiao](https://discuss.elastic.co/u/aqiao)\
**Post date:** [April 20, 2016, 9:38am UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/3 "2016-04-20T09:38:31Z")

</div>

Hi shaunak, sorry for late! i modified the post and hope your reply . Thanks

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 20, 2016, 1:11pm UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/4 "2016-04-20T13:11:00Z")

</div>

Hmm... that's interesting. Can you post the mapping of your Elasticsearch index here, please? You can view the mapping by calling the `GET {index-name}/_mapping` REST API.

---

<div class="post-metadata">

**Author:** ![aqiao](https://avatars.discourse-cdn.com/v4/letter/a/e274bd/32.png) [@aqiao](https://discuss.elastic.co/u/aqiao)\
**Post date:** [April 21, 2016, 6:50am UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/5 "2016-04-21T06:50:03Z")

</div>

```
 "tolreport-2016.04.20" : {
        "mappings" : {
          "tolcheck" : {
            "properties" : {
              "@timestamp" : {
                "type" : "date",
                "format" : "strict_date_optional_time||epoch_millis"
              },
              "@version" : {
                "type" : "string"
              },
              "Contributer" : {
                "type" : "string"
              },
              "Description" : {
                "type" : "string"
              },
              "Detail" : {
                "type" : "string"
              },
              "EventTime" : {
                "type" : "date",
                "format" : "strict_date_optional_time||epoch_millis"
              },
              "Item" : {
                "type" : "string"
              },
              "Type" : {
                "type" : "string"
              },
              "beat" : {
                "properties" : {
                  "hostname" : {
                    "type" : "string"
                  },
                  "name" : {
                    "type" : "string"
                  }
                }
              },
              "count" : {
                "type" : "long"
              },
              "host" : {
                "type" : "string"
              },
              "input_type" : {
                "type" : "string"
              },
              "message" : {
                "type" : "string"
              },
              "offset" : {
                "type" : "long"
              },
              "source" : {
                "type" : "string"
              },
              "tags" : {
                "type" : "string"
              },
              "type" : {
                "type" : "string"
              }
            }
          }
        }
      }
    }

```

Above is the mapping, and thanks shaunak

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 21, 2016, 4:15pm UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/6 "2016-04-21T16:15:03Z")

</div>

Thanks. Can you try calling the [analyze API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-analyze.html) with the text you are searching for, like this:

```
curl -XGET 'http://localhost:9200/tolreport-2016.04.20/_analyze' -d '
{
  "field" : "Item",
  "text" : "EUR="
}'

```

and also:

```
curl -XGET 'http://localhost:9200/tolreport-2016.04.20/_analyze' -d '
{
  "field" : "Item",
  "text" : "PQR="
}'
```

---

<div class="post-metadata">

**Author:** ![aqiao](https://avatars.discourse-cdn.com/v4/letter/a/e274bd/32.png) [@aqiao](https://discuss.elastic.co/u/aqiao)\
**Post date:** [April 22, 2016, 8:56am UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/7 "2016-04-22T08:56:28Z")

</div>

For first get request (EUR=):

`{"tokens":[{"token":"eur","start_offset":0,"end_offset":3,"type":"<ALPHANUM>","position":0}]}`

For second get request (XAUALL= ,there is no PQR= in current es, so i use XAUALL= instead):

`{"tokens":[{"token":"xauall","start_offset":0,"end_offset":6,"type":"<ALPHANUM>","position":0}]}`

---

<div class="post-metadata">

**Author:** ![aqiao](https://avatars.discourse-cdn.com/v4/letter/a/e274bd/32.png) [@aqiao](https://discuss.elastic.co/u/aqiao)\
**Post date:** [April 22, 2016, 9:09am UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/8 "2016-04-22T09:09:24Z")

</div>

Hi, after try some times, i find the only differences between "EUR=" and "XAUALL=" is there have some similar events to "EUR=" like "EUR=M" ,"EUR=W" and so on, but "XAUALL=" isn't.  
I mean there is no events like "XAUALL=M" or " "XAUALL=W".  
So this is Lucene bug?

Thanks!

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 27, 2016, 1:58pm UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/9 "2016-04-27T13:58:24Z")

</div>

HI @aqiao,

This is not a bug but working as expected 🙂. Let me attempt to explain.

As indicated in your mapping, the "Item" field does not specify an analyzer to use. This means Elasticsearch (really Lucene) will use the default, which is the [standard analyzer](https://www.elastic.co/guide/en/elasticsearch/guide/current/standard-analyzer.html). This analyzer, amongst other things, tokenizes the input string on the `=` sign. So the string `EUR=` is analyzed into one token, `eur`, while the string `EUR=W` is analyzed into two tokens, `eur` and `w`. These analyzed tokens are stored in Lucene's inverted index, which is used at search time.

At search time, the string you want to search on goes through the same analysis process. So searching for the string `EUR=W` causes Lucene to search in the inverted index for `eur` or `w`. That's why you are seeing results with `EUR=`, `EUR=W`, `EUR=Q`, etc.

If you are looking to perform exact matches, you should index the "Item" field as `index: not_analyzed` in your mapping. I would recommend reading this section of the Elasticsearch Definitive Guide: [https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping-analysis.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping-analysis.html)

---

<div class="post-metadata">

**Author:** ![aqiao](https://avatars.discourse-cdn.com/v4/letter/a/e274bd/32.png) [@aqiao](https://discuss.elastic.co/u/aqiao)\
**Post date:** [May 3, 2016, 7:28am UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/10 "2016-05-03T07:28:36Z")

</div>

Thanks @shaunak,i'll try that

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:54pm UTC](https://discuss.elastic.co/t/cant-exact-match-the-keyword-which-ends-with-equal-mark/47336/11 "2017-07-06T13:54:32Z")

</div>


