# Case sensitive search in Kibana

**URL:** <https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583>\
**Category:** Kibana\
**Created:** [August 22, 2018, 3:45pm UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583 "2018-08-22T15:45:28Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheCodingKnight](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@TheCodingKnight](https://discuss.elastic.co/u/TheCodingKnight)\
**Post date:** [August 22, 2018, 3:45pm UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/1 "2018-08-22T15:45:28Z")

</div>

I'm trying to do a case sensitive search in a Kibana watcher as below. However, this seems to pick up all messages with "error" as well. How best can this be handled?

```
    "body": {
      "query": {
        "bool": {
          "should": [
            {
              "match": {
                "message": "Exception Warn ERROR"
              }
            },
```

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [August 22, 2018, 6:24pm UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/2 "2018-08-22T18:24:12Z")

</div>

I assume that the message field has been mapped as type text. Without any further analyzers specified, the [standard analyser](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-standard-analyzer.html) will lowercase the field values during indexing. If you don't want that to happen you'll have to specify a custom analyser on the message field. See the [custom analyzer documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-custom-analyzer.html) for more details.

---

<div class="post-metadata">

**Author:** ![TheCodingKnight](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@TheCodingKnight](https://discuss.elastic.co/u/TheCodingKnight)\
**Post date:** [August 23, 2018, 9:10am UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/3 "2018-08-23T09:10:40Z")

</div>

Thank you so much. I'll give it a try now.

---

<div class="post-metadata">

**Author:** ![TheCodingKnight](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@TheCodingKnight](https://discuss.elastic.co/u/TheCodingKnight)\
**Post date:** [August 24, 2018, 12:58pm UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/4 "2018-08-24T12:58:46Z")

</div>

I started reading through the 'custom analyser documentation' from your post above. Rookie question - where exactly do I add the custom analyser? The closest thing seemed to be Management \> Elasticsearch \> Index Management \> "One of the Indeces" \> Edit Settings. However, not sure if that is correct thou'.

```
  "settings": {
"analysis": {
  "analyzer": {
    "rebuilt_standard": {
      "tokenizer": "standard",
      "filter": [
        "standard"      
      ]
    }
  }
}

```

}

---

<div class="post-metadata">

**Author:** ![TheCodingKnight](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@TheCodingKnight](https://discuss.elastic.co/u/TheCodingKnight)\
**Post date:** [August 25, 2018, 9:37am UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/5 "2018-08-25T09:37:13Z")

</div>

After a bit more playing around this is what I've got to.

Under Management \> Elasticsearch \> Index Management \> select the index \> Edit Settings and

1. Closed the index
2. Added the following 2 entries  
"index.analysis.analyzer.rebuilt\_standard.filter": ["standard"],  
"index.analysis.analyzer.rebuilt\_standard.tokenizer": "standard"
3. Opened the index
4. Various combinations of clear index cache, flush index, refresh index, & force merge index.

Now when I try to simulate the watch it still is doing case insensitive search. Any pointers on what I could be missing?

---

<div class="post-metadata">

**Author:** ![TheCodingKnight](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@TheCodingKnight](https://discuss.elastic.co/u/TheCodingKnight)\
**Post date:** [August 28, 2018, 12:04pm UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/6 "2018-08-28T12:04:33Z")

</div>

Hi @Bargs, @Magnus_Kessler, Elastic team,  
Could you help with this please?

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [August 28, 2018, 12:27pm UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/7 "2018-08-28T12:27:27Z")

</div>

Please don't use `@name` with forum members who haven't been part of a disussion thread, yet.

To answer your question about where the custom analyzer needs to be configured:

You install the analyzer in the settings of a given index. From the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-custom-analyzer.html):

```auto
PUT my_index
{
  "settings": {
    "analysis": {
      "analyzer": {
        "my_custom_analyzer": {
          "type": "custom",
          "tokenizer": "standard",
          "char_filter": [
            "html_strip"
          ],
          "filter": [
            "lowercase",
            "asciifolding"
          ]
        }
      }
    }
  }
}

```

Then, for each field that should be analyzed with the custom analyzer, you also have to configure the analyzer in the [mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/analyzer.html):

```auto
PUT /my_index
{
  "mappings": {
    "_doc": {
      "properties": {
        "message": { 
          "type": "text",
          "analyzer": "my_custom_analyzer"
        }
      }
    }
  }
}

```

Make sure to replace the document type `_doc` above with the document type you actually use.

---

<div class="post-metadata">

**Author:** ![TheCodingKnight](https://avatars.discourse-cdn.com/v4/letter/t/35a633/32.png) [@TheCodingKnight](https://discuss.elastic.co/u/TheCodingKnight)\
**Post date:** [August 28, 2018, 12:37pm UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/8 "2018-08-28T12:37:17Z")

</div>

Thanks. Will give it a try now. Will this work against the existing entries as well or only against those that will be created after the custom analyzer was created?

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [August 28, 2018, 1:04pm UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/9 "2018-08-28T13:04:08Z")

</div>

If you want to change the mappings for existing fields, you will have to reindex your data. I suggest you create a new index with your custom analyzer and configure the mapping to use this analyzer as shown. Then you can start indexing new data into this index, or use the [Reindex API](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html) to reindex existing data. You may want to look into creating an [alias](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-aliases.html), so that your client can transparently use the new index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2018, 1:04pm UTC](https://discuss.elastic.co/t/case-sensitive-search-in-kibana/145583/10 "2018-09-25T13:04:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
