# Certain json messages not found in elastic

**URL:** <https://discuss.elastic.co/t/certain-json-messages-not-found-in-elastic/217681>\
**Category:** Kibana\
**Created:** [February 3, 2020, 7:23pm UTC](https://discuss.elastic.co/t/certain-json-messages-not-found-in-elastic/217681 "2020-02-03T19:23:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jdepp99](https://avatars.discourse-cdn.com/v4/letter/j/58956e/32.png) [@jdepp99](https://discuss.elastic.co/u/jdepp99)\
**Post date:** [February 3, 2020, 7:23pm UTC](https://discuss.elastic.co/t/certain-json-messages-not-found-in-elastic/217681/1 "2020-02-03T19:23:47Z")

</div>

I setup a dashboard in kibana and found the messages I was sending based on the 'type' field in the json that I specify. This is getting sent to a logstash index along millions of other types. I found certain msgTypes but not all and I know the json is being sent to elastic but tried every possible search to find it.  
Is there someway to confirm that this message is in elastic besides through kibana discover. Eg:

```
{"msgType":"comment",
  "articleId":"4749219208",
  "commentId":"6629988184640481077",
  "pubDate":"null",
  "receivedDate":"2020-02-03T19:20:30.900-05:00",
  "type":"production_comments_out"}

 {"msgType":"article",
 "articleId":"4750898288",
 "commentId":"null",
 "pubDate":"2020-02-03 19:09:51",
 "receivedDate":"null",
 "type":"production_comments_out"}

```

I only the one with msgType:comment.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 3, 2020, 8:21pm UTC](https://discuss.elastic.co/t/certain-json-messages-not-found-in-elastic/217681/2 "2020-02-03T20:21:21Z")

</div>

Hey @jdepp99, you can also use [Console](https://www.elastic.co/guide/en/kibana/current/console-kibana.html) to query Elasticsearch directly, skipping Kibana.

One thing which might be tripping you up is the difference between the [text](https://www.elastic.co/guide/en/elasticsearch/reference/current/text.html) and [keyword](https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html) field datatypes. The `text` fields go through [analysis](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis.html) which "tokenizes" the strings, and searches will be executed against the individual tokens themselves. Where-as `keyword` fields don't go through analysis, so you'll be searching against the raw unprocessed text itself.

---

<div class="post-metadata">

**Author:** ![jdepp99](https://avatars.discourse-cdn.com/v4/letter/j/58956e/32.png) [@jdepp99](https://discuss.elastic.co/u/jdepp99)\
**Post date:** [February 3, 2020, 8:56pm UTC](https://discuss.elastic.co/t/certain-json-messages-not-found-in-elastic/217681/3 "2020-02-03T20:56:37Z")

</div>

Thanks for responding. I will try the console. I did use both the text and keyword with no joy but lets see the console.

---

<div class="post-metadata">

**Author:** ![jdepp99](https://avatars.discourse-cdn.com/v4/letter/j/58956e/32.png) [@jdepp99](https://discuss.elastic.co/u/jdepp99)\
**Post date:** [February 4, 2020, 1:03pm UTC](https://discuss.elastic.co/t/certain-json-messages-not-found-in-elastic/217681/4 "2020-02-04T13:03:08Z")

</div>

Still no result with the console. Do I need to delete the index perhaps?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2020, 1:03pm UTC](https://discuss.elastic.co/t/certain-json-messages-not-found-in-elastic/217681/5 "2020-03-03T13:03:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
