# Discover field names with spaces

**URL:** <https://discuss.elastic.co/t/discover-field-names-with-spaces/37467>\
**Category:** Kibana\
**Created:** [December 17, 2015, 12:25pm UTC](https://discuss.elastic.co/t/discover-field-names-with-spaces/37467 "2015-12-17T12:25:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![flow](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@flow](https://discuss.elastic.co/u/flow)\
**Post date:** [December 17, 2015, 12:25pm UTC](https://discuss.elastic.co/t/discover-field-names-with-spaces/37467/1 "2015-12-17T12:25:28Z")

</div>

I'd like to search only in a specific field, like `myfield:searchterm`. But in my case, the field name contains a space character `my field:searchterm`. This will search for my in the default field and for searchterm in the field field, which does not even exist. I tried enclosing the field name in double quotes but I get an error. I also found that Lucene syntax supportes escaping spaces with a backslash, but `my\ field:searchterm` doesn't work either.  
No need to tell me that spaces in field names are a bad idea in general and that this should be prevented, but still I have to deal with it. But how?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [December 17, 2015, 7:47pm UTC](https://discuss.elastic.co/t/discover-field-names-with-spaces/37467/2 "2015-12-17T19:47:19Z")

</div>

The backslash format is the right syntax, as you can see here:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/4493ef470688147f50c85b785dc67fe1381c5e19.png)

Perhaps it's a time field issue? Are you using time-based events for the index pattern, and are you looking in a time range that actually has data?

---

<div class="post-metadata">

**Author:** ![Ilija\_Vukotic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilija_vukotic/32/7705_2.png) [@Ilija\_Vukotic](https://discuss.elastic.co/u/Ilija_Vukotic)\
**Post date:** [February 10, 2016, 7:57am UTC](https://discuss.elastic.co/t/discover-field-names-with-spaces/37467/3 "2016-02-10T07:57:50Z")

</div>

I don't think this answer is correct. The only reason you see result here is because you left a space between ":" and \*  
While ES won't complain when you do "My\ field:\>10" it will never find any results.

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [February 11, 2016, 6:56pm UTC](https://discuss.elastic.co/t/discover-field-names-with-spaces/37467/4 "2016-02-11T18:56:28Z")

</div>

Hrm, perhaps you're right. While it's not really clear to me from [the query docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#query-string-syntax), all the examples there explicitly **do not** include a space after the `:`, so it's entirely possible that it matters.

Looking at the query being sent to ES, I see the following:

- With \ and no space - `{"query_string":{"query":"my\\ field:*" ...`
- With \ and space - `{"query_string":{"query":"my\\ field: *" ...`
- With space in field name - `{"query_string":{"query":"my field:*" ...`

So whatever you put in there seems to be sent unaltered to ES as a query\_string inside of a bool query. That doesn't really answer your question of which one is right though. Unfortunately, I don't actually know. I'll go find out and post back here though.

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [February 11, 2016, 7:19pm UTC](https://discuss.elastic.co/t/discover-field-names-with-spaces/37467/5 "2016-02-11T19:19:52Z")

</div>

I asked around, and most people didn't even think we supported spaces in field names. That's probably an indication that you shouldn't be doing that in the first place. FWIW, convention would seem to imply using \_ in your field names in place of a space.

That said, there seems to be 2 ways to query a field with a space in it. The first is to simply escape the space in the field name, such as `"query": "my\\ field:value"`. So, in Kibana, using a \ and no space before or after the : seems to be the way to do it. Given the original question, `my\ field:searchterm` should work.

The second uses the [default\_field parameter](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#query-dsl-query-string-query). Kibana simply passes whatever you put in that field into the "query" value when it's a string, but it will pass the entire contents into a bool query if you use valid JSON instead. So, I _think_ you can query that field with the following as well: `{ "query_string": { "default_field": "my field", "query": "searchterm" }}`, but I haven't tried that directly myself.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:02pm UTC](https://discuss.elastic.co/t/discover-field-names-with-spaces/37467/6 "2017-07-06T14:02:29Z")

</div>


