# Elasticsearch/Kibana query\_string with special characters

**URL:** <https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766>\
**Category:** Elasticsearch\
**Created:** [March 13, 2018, 3:47pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766 "2018-03-13T15:47:49Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rougui](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@Rougui](https://discuss.elastic.co/u/Rougui)\
**Post date:** [March 13, 2018, 3:47pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/1 "2018-03-13T15:47:49Z")

</div>

Hello,

i configured Elasticsearch cloud VM machine, i created index, simples types and mapping.

By using Kibana Dev-Tools console:

- I am able to build index data by using POST and PUT requests.
- Now i have to search text. I use query\_string for manage different jokers. But when i search word that contains special characters (eg: _@xxxx_, _!xxxx_, _xxxxé_, \*xxxx \*), even if word exists in BD, i get empty hits.

I have tried to configure index settings with "Analyzer" but i did not get any solution and i have more gray areas.

Can somebody help me about that?

Here are requests examples:

1- all posts

```
GET test-search/serch_text/_search
{
}

"hits": {
    "total": 11,
    "max_score": 1,
    "hits": [
      {
        "_index": "test-search",
        "_type": "serch_text",
        "_id": "ZXd1DGIBBx5VGSRKr7QL",
        "_score": 1,
        "_source": {
          "text": "@funy"
        }
      },
      {
        "_index": "test-search",
        "_type": "serch_text",
        "_id": "aXdUE2IBBx5VGSRKGbTZ",
        "_score": 1,
        "_source": {
          "text": "@fun "
        }
      },
      {
        "_index": "test-search",
        "_type": "serch_text",
        "_id": "Ynd1DGIBBx5VGSRKlrQs",
        "_score": 1,
        "_source": {
          "text": "you have a & fun"
        }
      },
      {
        "_index": "test-search",
        "_type": "serch_text",
        "_id": "Znd1DGIBBx5VGSRKxLQW",
        "_score": 1,
        "_source": {
          "text": "%fun "
        }
      },
      {
        "_index": "test-search",
        "_type": "serch_text",
        "_id": "bHdVE2IBBx5VGSRKlbSD",
        "_score": 1,
        "_source": {
          "text": "I have a fun!"
        }
      }

```

2- not work  
GET test-search/serch\_text/\_search  
{  
"query": {  
"query\_string": {  
"query": "_@fun_"  
}  
}  
}

```
{
  "took": 2,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": 0,
    "max_score": null,
    "hits": []
  }
}

```

3- not work

```
GET test-search/serch_text/_search
{
  "query": {
         "query_string": {
          "query": "*I have a fun*"
        }
  }
}

{
  "took": 2,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": 0,
    "max_score": null,
    "hits": []
  }
}

```

Thanks!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 13, 2018, 5:01pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/2 "2018-03-13T17:01:02Z")

</div>

Please don't post images of text as they are hardly readable and not searchable.

Instead paste the text and format it with `</>` icon. Check the preview window.

---

<div class="post-metadata">

**Author:** ![Rougui](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@Rougui](https://discuss.elastic.co/u/Rougui)\
**Post date:** [March 13, 2018, 6:10pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/3 "2018-03-13T18:10:10Z")

</div>

Ok dadoonet, i done it in \</\>.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 13, 2018, 6:38pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/4 "2018-03-13T18:38:14Z")

</div>

I can't reproduce.

```auto
DELETE test 
PUT test/doc/1
{
  "text": "@fun"
}
GET test/_search
{
  "query": {
    "query_string": {
      "query": "@fun"
    }
  }
}

```

It gives:

```auto
{
  "took": 65,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": 1,
    "max_score": 0.2876821,
    "hits": [
      {
        "_index": "test",
        "_type": "doc",
        "_id": "1",
        "_score": 0.2876821,
        "_source": {
          "text": "@fun"
        }
      }
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![Rougui](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@Rougui](https://discuss.elastic.co/u/Rougui)\
**Post date:** [March 13, 2018, 7:25pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/5 "2018-03-13T19:25:51Z")

</div>

Ok, weird.

I have created new index and 2 entries as you and it gives results as you.

Now please can you add this one:

```
PUT test/doc/3
{
  "text": "rougui@fun.com"
}

```

and test :  
1-

```
    GET test/_search
    {
      "query": {
        "query_string": {
          "query": "@fun"
        }
      }
    }

```

2- I have to support an wrong special character entering in the query

```
        GET test/_search
            {
              "query": {
                "query_string": {
                  "query": "*@fun!*"
                }
              }
            }

```

Normally these 2 GET request must give results.

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![Rougui](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@Rougui](https://discuss.elastic.co/u/Rougui)\
**Post date:** [March 13, 2018, 8:15pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/6 "2018-03-13T20:15:40Z")

</div>

other weird example:

i done successively these requests :

```
DELETE test

PUT test
{
}

POST test/_mapping/search
{
  "properties" : {
      "text" : {
        "type" : "text"
      }
    }
}

POST test/search/
{
  "text": "@fun"
}

POST test/search
{
  "text": "i have a & fun"
}

GET test/search/_search

GET test/search/_search
{
  "query": {
    "query_string": {
      "query": "@fun"
    }
  }
}

```

it gives :

```
{
  "took": 0,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": 2,
    "max_score": 1,
    "hits": [
      {
        "_index": "test",
        "_type": "search",
        "_id": "c3f6IGIBBx5VGSRKoLR6",
        "_score": 1,
        "_source": {
          "text": "@fun"
        }
      },
      {
        "_index": "test",
        "_type": "search",
        "_id": "dXf8IGIBBx5VGSRK-LSh",
        "_score": 1,
        "_source": {
          "text": "i have a & fun"
        }
      }
    ]
  }
}

```

Normally it must gives :

```
{
  "took": 0,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": 2,
    "max_score": 1,
    "hits": [
      {
        "_index": "test",
        "_type": "search",
        "_id": "c3f6IGIBBx5VGSRKoLR6",
        "_score": 1,
        "_source": {
          "text": "@fun"
        }
      }
    ]
  }
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 13, 2018, 8:28pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/7 "2018-03-13T20:28:53Z")

</div>

Have a look at analyze API to understand what is happening.

---

<div class="post-metadata">

**Author:** ![Rougui](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@Rougui](https://discuss.elastic.co/u/Rougui)\
**Post date:** [March 13, 2018, 8:39pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/8 "2018-03-13T20:39:32Z")

</div>

```
GET test/_analyze
{
  "text" : "@fun"
}

```

it gives:

```
{
  "tokens": [
    {
      "token": "fun",
      "start_offset": 1,
      "end_offset": 4,
      "type": "<ALPHANUM>",
      "position": 0
    }
  ]
}

```

it look likes it ignore @ character by tokenizing.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 13, 2018, 9:05pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/9 "2018-03-13T21:05:40Z")

</div>

Yes. That's expected.

---

<div class="post-metadata">

**Author:** ![Rougui](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@Rougui](https://discuss.elastic.co/u/Rougui)\
**Post date:** [March 14, 2018, 12:05pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/10 "2018-03-14T12:05:24Z")

</div>

Hello,

But it is not expected behavior that i want. Below i give 2 examples that i have to manage.

eg:  
1- when user enter **@gmail** in searchview, it must gives all emails that contains **@gmail**  
2 - when user enter **fun&** in searchview, it must gives all entries that contains **fun**

But at this time it does not find words contains special characters.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 14, 2018, 1:40pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/11 "2018-03-14T13:40:07Z")

</div>

You need to find the right analyzer which matches your use case. Have a look at [https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-analyzers.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-analyzers.html)

May be this tokenizer could help you: [https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-uaxurlemail-tokenizer.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-uaxurlemail-tokenizer.html)

---

<div class="post-metadata">

**Author:** ![Rougui](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@Rougui](https://discuss.elastic.co/u/Rougui)\
**Post date:** [March 15, 2018, 8:04pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/12 "2018-03-15T20:04:33Z")

</div>

Ok thanks.

I defined custom analyzer.

```
"analysis": {
      "analyzer": {
        "my_analyzer" : {
          "type" : "custom",
          "tokenizer": "standard",
          "filter" : [
            "email",
            "lowercase",
            "asciifolding"
            ],
          "char_filter" : [
            "specialCharactersFilter"
            ]
        }
      },
      
      "tokenizer": {
        "my_tokenizer": {
          "type": "uax_url_email"
        }
      },
      
      "filter" : {
        "email" : {
          "type" : "pattern_capture",
          "preserve_original" : true,
          "patterns" : ["(\\p{L}+)", "(\\d+)"]
        }
      },
      
      "char_filter": {
        "specialCharactersFilter": {
        "pattern": "[^a-zA-Z0-9À-ÖØ-öø-ÿ]+",
          "type": "pattern_replace",
          "replacement": ""
        }
      }
      
   }

```

with this one, its search pretty better.

I have again issue with @. I continue improve its.

If you have any idea, share me it.

Thanks

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 15, 2018, 8:18pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/13 "2018-03-15T20:18:01Z")

</div>

You can also define multiple analyzers and use multifields to index the same content with different analyzers.

---

<div class="post-metadata">

**Author:** ![Rougui](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@Rougui](https://discuss.elastic.co/u/Rougui)\
**Post date:** [March 16, 2018, 1:27pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/14 "2018-03-16T13:27:37Z")

</div>

Ok thanks !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2018, 1:27pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-query-string-with-special-characters/123766/15 "2018-04-13T13:27:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
