# Divide query in separate new lines

**URL:** <https://discuss.elastic.co/t/divide-query-in-separate-new-lines/317389>\
**Category:** Elasticsearch\
**Created:** [October 25, 2022, 9:42am UTC](https://discuss.elastic.co/t/divide-query-in-separate-new-lines/317389 "2022-10-25T09:42:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![oalimerko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oalimerko/32/112489_2.png) [@oalimerko](https://discuss.elastic.co/u/oalimerko)\
**Post date:** [October 25, 2022, 9:42am UTC](https://discuss.elastic.co/t/divide-query-in-separate-new-lines/317389/1 "2022-10-25T09:42:07Z")

</div>

Hello team,

this is my new post here,i am looking forward share my experience and knowledge with community.  
I'm using elasticsearch and kibana for logs monitoring and also for this purpose i use the [ES-Exporter](https://github.com/braedon/prometheus-es-exporter) for catching the exceptions in logs .  
I have query like this

```auto
  GET _search 
{
  "query": {
    "query_string": {
      "query": "message:\"com.microsoft.sqlserver.jdbc.SQLServerException\" AND @timestamp:(>=now-1h AND <now)"
    }
  },
  "aggs": {
    "application": {
      "terms": {
        "field": "kubernetes.labels.app.keyword"
        }
      }
    }
  }

```

Can i somehow define some conditions in separate new lines using boolean opertator like below:

```auto
  GET _search 
{
  "query": {
    "query_string": {
      "query": "message:\"com.microsoft.sqlserver.jdbc.SQLServerException\" 
                       AND level: DEBUG
                       AND threadname: xyz                       
                       AND @timestamp:(>=now-1h AND <now)"
    }
  },
  "aggs": {
    "application": {
      "terms": {
        "field": "kubernetes.labels.app.keyword"
        }
      }
    }
  }

```

This would make the query more readable.I tried using `\n` but without success

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [October 25, 2022, 4:31pm UTC](https://discuss.elastic.co/t/divide-query-in-separate-new-lines/317389/2 "2022-10-25T16:31:22Z")

</div>

Can you try wrapping the query in triple quotes, [similar to this example](https://discuss.elastic.co/t/how-to-put-multiple-lines-in-kibana-sql-search/241708).

```auto
GET _search 
{
  "query": {
    "query_string": {
      "query": """message:\"com.microsoft.sqlserver.jdbc.SQLServerException\" 
                       AND level: DEBUG
                       AND threadname: xyz                       
                       AND @timestamp:(>=now-1h AND <now)"""
    }
  },
  "aggs": {
    "application": {
      "terms": {
        "field": "kubernetes.labels.app.keyword"
        }
      }
    }
  }

```

---

<div class="post-metadata">

**Author:** ![oalimerko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oalimerko/32/112489_2.png) [@oalimerko](https://discuss.elastic.co/u/oalimerko)\
**Post date:** [October 25, 2022, 9:50pm UTC](https://discuss.elastic.co/t/divide-query-in-separate-new-lines/317389/3 "2022-10-25T21:50:44Z")

</div>

ok this seems to be the solution.Thnx for that.  
This query works:

```auto
  GET _search 
{
  "query": {
    "query_string": {
      "query": """message: "com.microsoft.sqlserver.jdbc.SQLServerException" 
                  AND NOT message: "Condition 1" 
                  AND NOT message: "Condition 2"            
                  AND @timestamp:(>=now-90d AND <now)"""
    }
  },
  "aggs": {
    "application": {
      "terms": {
        "field": "kubernetes.labels.app.keyword"
        }
      }
    }
  }

```

Could you pls explain what kind of role does `\"` play?

```auto

  GET _search 
{
  "query": {
    "query_string": {
      "query": """message:\"com.microsoft.sqlserver.jdbc.SQLServerException\" 
                  AND NOT message:\" Condition 1\"
                  AND NOT message:\"Condition 2\"        
                  AND @timestamp:(>=now-90d AND <now)"""
    }
  },
  "aggs": {
    "application": {
      "terms": {
        "field": "kubernetes.labels.app.keyword"
        }
      }
    }
  }

```

So where is the difference between above queries?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [October 26, 2022, 8:39am UTC](https://discuss.elastic.co/t/divide-query-in-separate-new-lines/317389/4 "2022-10-26T08:39:30Z")

</div>

The slash operator ("") is used to escape special characters in strings, such as double quotes ("content"). Arguably when using the triple double quotes ("""content""") escaping the single double quotes is not required. Which is why the first one without works. Hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2022, 8:39am UTC](https://discuss.elastic.co/t/divide-query-in-separate-new-lines/317389/5 "2022-11-23T08:39:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
