# Filebeat logging MSSQL ERROR log, but not able to search on Message field in Kibana

**URL:** <https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428>\
**Category:** Kibana\
**Created:** [October 4, 2023, 8:09pm UTC](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428 "2023-10-04T20:09:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dbaddorf](https://avatars.discourse-cdn.com/v4/letter/d/858c86/32.png) [@dbaddorf](https://discuss.elastic.co/u/dbaddorf)\
**Post date:** [October 4, 2023, 8:09pm UTC](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428/1 "2023-10-04T20:09:58Z")

</div>

I have Filebeat using the MSSQL module running on a Windows SQL Server exporting logs to an Elasticsearch server. I can view the Filebeat logs in Kibana. But I can't (seem) to search on the Message field. For example, none of the following Kibana searches work:

```auto
agent.hostname: "SQL1" and messages: *
agent.hostname: "SQL1" and messages: %Login%

```

When I expand the documents, I see the text "message" file with data like "Login succeeded for user 'reportuser'. Connection made using SQL Server authentication. [CLIENT: xx.xx.xx.xx]".

The "message" field is there, I just can't seem to access it for searching.

My ultimate goal is to get the username into a separate field so I can Visualize it for Dashboards. Would I do this on the Filebeat mssql module or on the Elasticsearch backend? Any direction on this would certainly be appreciated.

As you can tell, I'm just beginning to figure out the power of Elasticsearch. Glad for assistance!

---

<div class="post-metadata">

**Author:** ![dbaddorf](https://avatars.discourse-cdn.com/v4/letter/d/858c86/32.png) [@dbaddorf](https://discuss.elastic.co/u/dbaddorf)\
**Post date:** [October 5, 2023, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428/3 "2023-10-05T22:26:19Z")

</div>

Thanks for your response. My problem wasn't the time range. And I don't understand how the filter would help me, when I don't have any data to filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2023, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428/4 "2023-11-02T22:26:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
