# ESQL where the field value is a list

**URL:** <https://discuss.elastic.co/t/esql-where-the-field-value-is-a-list/376907>\
**Category:** Kibana\
**Tags:** esql\
**Created:** [April 8, 2025, 11:52am UTC](https://discuss.elastic.co/t/esql-where-the-field-value-is-a-list/376907 "2025-04-08T11:52:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![duckasylum](https://avatars.discourse-cdn.com/v4/letter/d/a5b964/32.png) [@duckasylum](https://discuss.elastic.co/u/duckasylum)\
**Post date:** [April 8, 2025, 11:52am UTC](https://discuss.elastic.co/t/esql-where-the-field-value-is-a-list/376907/1 "2025-04-08T11:52:54Z")

</div>

Hi, I have an index created from JSON files and due to the structure of the JSON with multiple same name keys I have now fields which are lists. I am wondering how to use such fields in ESQL queries. For example in the index named _someindex_ there is a document with a field _someIDs_ with the value [123,456]. The query  
`FROM someindex* | WHERE someIDs IN ("456")`  
does not find that document. I also tried the query the other way around as in  
`FROM someindex* | WHERE "456" IN someIDs`  
but that gave an error.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 8, 2025, 1:33pm UTC](https://discuss.elastic.co/t/esql-where-the-field-value-is-a-list/376907/2 "2025-04-08T13:33:46Z")

</div>

Hi @duckasylum

Yeah it is kinda weird... try `MV_EXPAND`

```auto
FROM logs-* 
| MV_EXPAND someIDs
| where someIDs == "456"
| LIMIT 10

```
