# Finding fields with a "-"

**URL:** <https://discuss.elastic.co/t/finding-fields-with-a/106079>\
**Category:** Kibana\
**Created:** [November 1, 2017, 6:40pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079 "2017-11-01T18:40:33Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![dfinn](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Post date:** [November 1, 2017, 6:40pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/1 "2017-11-01T18:40:33Z")

</div>

Running ELK 5.3.1

We are working on trying to track down an issue where our Apache responses sometimes have a content length of 0 bytes. Unfortunately 0 actually gets logged as a "-" by apache. I'm looking at changing this in apache but we need to analyze our current logs to track this down.

I tried this as my kibana search:

type:apache AND bytes:\-

but I get the following error from kibana:

Discover: failed to create query: { "bool" : { "must" : [{ "query\_string" : { "query" : "type:apache AND bytes:-", "fields" : [], "use\_dis\_max" : true, "tie\_breaker" : 0.0, "default\_operator" : "or", "auto\_generate\_phrase\_queries" : false, "max\_determinized\_states" : 10000, "enable\_position\_increments" : true, "fuzziness" : "AUTO", "fuzzy\_prefix\_length" : 0, "fuzzy\_max\_expansions" : 50, "phrase\_slop" : 0, "analyze\_wildcard" : true, "escape" : false, "split\_on\_whitespace" : true, "boost" : 1.0 } }, { "match" : { "bytes" : { "query" : "-", "type" : "phrase", "operator" : "OR", "prefix\_length" : 0, "max\_expansions" : 50, "fuzzy\_transpositions" : true, "lenient" : false, "zero\_terms\_query" : "NONE", "boost" : 1.0 } } }, { "range" : { "@timestamp" : { "from" : 1509560579745, "to" : 1509561479745, "include\_lower" : true, "include\_upper" : true, "format" : "epoch\_millis", "boost" : 1.0 } } } ], "disable\_coord" : false, "adjust\_pure\_negative" : true, "boost" : 1.0 } }

Is there a way to filter on these existing log entries that have a bytes field of "-"?

Thanks,  
Dan

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [November 1, 2017, 9:24pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/2 "2017-11-01T21:24:34Z")

</div>

Can you please let us know your mappings to debug further. if its a key word field you can wrap the keyword in quotes.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![dfinn](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Post date:** [November 1, 2017, 9:36pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/3 "2017-11-01T21:36:57Z")

</div>

I'd be happy to if you wouldn't mind helping me that. How can I get my field mappings?

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [November 1, 2017, 9:48pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/4 "2017-11-01T21:48:06Z")

</div>

you may use `GET /_mapping` or may be specifically for an index like : `GET /my-index/_mapping`  
For future ref: [https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![dfinn](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Post date:** [November 1, 2017, 9:51pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/5 "2017-11-01T21:51:46Z")

</div>

If I'm reading this right, it looks to be:

"bytes":{"type":"long"}

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [November 1, 2017, 9:59pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/6 "2017-11-01T21:59:55Z")

</div>

Can you try `_exists_:bytes`. Am guessing the field aren't hyphens but actually nulls

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![dfinn](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Post date:** [November 1, 2017, 10:05pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/7 "2017-11-01T22:05:58Z")

</div>

> [@rashmi](#):
>
> _exists_:bytes

I tried that. It returned lots of log entries. Every apache log that we get has the bytes field. It certainly exists but I'm trying to the find the ones that are either 0 (none return as 0 when searching bytes:0) or "-".

From the apache documentation on how it's currently logging:  
"Size of response in bytes, excluding HTTP headers. In CLF format, i.e. a '-' rather than a 0 when no bytes are sent."

so 0 should be getting logged as "-" according to that.

I tried searching for bytes:null and bytes:"null" but it didn't like either of those.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [November 1, 2017, 10:23pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/8 "2017-11-01T22:23:42Z")

</div>

Can we try taking a look at your raw elasticsearch data to see what is stored in the field? If the bytes field is mapped as a long, we'll get a number parsing exception if an '-' is indexed. If it's a hyphen I'm a little confused as to how it's being added.

To search over the index:

```auto
GET index/_search?size=100

```

If the field is 0, then `bytes:0` should work. If it's null or empty (`""`), `NOT _exists_:bytes` should work.

---

<div class="post-metadata">

**Author:** ![dfinn](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Post date:** [November 1, 2017, 10:30pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/9 "2017-11-01T22:30:39Z")

</div>

I'm trying to run that like so:

curl -XGET '[http://localhost:9200/index/\_search?size=100](http://localhost:9200/index/_search?size=100)'

but it doesn't like that. Am I missing something?

edit: I figured out what I was doing wrong and I've run it against a few indices. I'm still not getting any bytes field in anything that is being returned though. I'm now running it like so:

curl -XGET '[http://localhost:9200/logstash-2017.12.27/\_search?size=100](http://localhost:9200/logstash-2017.12.27/_search?size=100)'

---

<div class="post-metadata">

**Author:** ![dfinn](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Post date:** [November 1, 2017, 10:58pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/10 "2017-11-01T22:58:47Z")

</div>

Not sure I'm totally doing this right but I tried some specific searches. This returned 0:

curl -XGET '[http://localhost:9200/logstash-2017.10.31/\_search?q=bytes:0](http://localhost:9200/logstash-2017.10.31/_search?q=bytes:0)'

and every form of search where I tried -, \-, "-" or "\-" resulted in a "failed to create query" error.

---

<div class="post-metadata">

**Author:** ![dfinn](https://avatars.discourse-cdn.com/v4/letter/d/8c91f0/32.png) [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Post date:** [November 1, 2017, 11:11pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/11 "2017-11-01T23:11:40Z")

</div>

Actually, maybe logstash is just dropping it if it's a "-". Here's the grok pattern that is being used:

(?:%{NUMBER:bytes}|-)

I'm not a grok expert but I think that says to grab it if it's a NUMBER otherwise do nothing?

If this is the case we may only be capturing from 1 and higher.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2017, 11:11pm UTC](https://discuss.elastic.co/t/finding-fields-with-a/106079/12 "2017-11-29T23:11:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
