# General confusion with Kibna's search bar

**URL:** <https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665>\
**Category:** Kibana\
**Created:** [October 22, 2016, 3:28pm UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665 "2016-10-22T15:28:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 22, 2016, 3:28pm UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665/1 "2016-10-22T15:28:30Z")

</div>

So here's the filter:

`type:connlog AND NOT (history:.*D.*)`

I'm attempting to filter out anything that contains a "D" or "d". Why does Kibana actually give me contents with a D?  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1b28f33e1ebad0e12ca00c1098dca6d95f3c3dda.png)

Thank you.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 22, 2016, 3:29pm UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665/2 "2016-10-22T15:29:02Z")

</div>

I've also tried regext with /._D._/ to no avail.

---

<div class="post-metadata">

**Author:** ![ara](https://avatars.discourse-cdn.com/v4/letter/a/b5a626/32.png) [@ara](https://discuss.elastic.co/u/ara)\
**Post date:** [October 22, 2016, 8:12pm UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665/3 "2016-10-22T20:12:39Z")

</div>

Hi DidiAngel

If want to " filter out anything that contains a "D" or "d" "  
your query could simply look like

`type:connlog AND NOT (history: *d*)`

The reason your query does not work is that Kibana search expression is not a standard regular expression, it is a Lucene query expression.  
There is a support for some wildcards like \* ? and [] but not .  
There is also support for special features (fuzzy, proximity, ranges etc).  
See the list of special characters given [there](http://lucene.apache.org/core/6_2_1/queryparser/org/apache/lucene/queryparser/classic/package-summary.html#package.description)

- 
  - && || ! ( ) { } [] ^ " ~ \* ? : \ /

. is not a lucene query special character but it is a word breaker, see [here](http://unicode.org/reports/tr29/#Word_Boundaries)  
I think it is not escapable

HTH

Alain

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 22, 2016, 11:34pm UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665/4 "2016-10-22T23:34:17Z")

</div>

First off thank you for the info. I tested out my Sense line..here's what I got:

```
{
  "tokens": [
    {
      "token": "d",
      "start_offset": 1,
      "end_offset": 2,
      "type": "<ALPHANUM>",
      "position": 0
    }
  ]
}

```

However I still see the same results:  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0be66084253d836b146c584fca91c4afd23e13a2.png)

Interestingly, if I try and match instead of negate, it works fine:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/02af094373bcdbc99ffc038c423112fdf7f933fd.png)

---

<div class="post-metadata">

**Author:** ![ara](https://avatars.discourse-cdn.com/v4/letter/a/b5a626/32.png) [@ara](https://discuss.elastic.co/u/ara)\
**Post date:** [October 23, 2016, 7:09am UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665/5 "2016-10-23T07:09:35Z")

</div>

But in your last example, when it works fine, the field contains some 'D' and 'd' ?  
I thought you wanted to remove them from the output (as you said 'filter out') ??  
...  
BTW, I'm glad you found the link interesting and it finally works for you  
🙂

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 23, 2016, 12:45pm UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665/6 "2016-10-23T12:45:26Z")

</div>

I do want to filter out anything that contains "d" or "D". I'm showing that the inverse, match anything that DOES contain "d" or "D" does work. But, when I add the "NOT", I still get history items with "d" or "D", even with `type:connlog AND NOT (history: *d*)`. Maybe this is a beta issue?

---

<div class="post-metadata">

**Author:** ![ara](https://avatars.discourse-cdn.com/v4/letter/a/b5a626/32.png) [@ara](https://discuss.elastic.co/u/ara)\
**Post date:** [October 23, 2016, 1:07pm UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665/7 "2016-10-23T13:07:18Z")

</div>

ah ok,  
For me it works fine with match and NOT match, except with the pattern with '.'  
which does not works.  
But I'm not using a beta version (yet)  
As you said, may be a problem in beta?

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 23, 2016, 3:42pm UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665/8 "2016-10-23T15:42:23Z")

</div>

Cool...I'll file a bug report on github...thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:35pm UTC](https://discuss.elastic.co/t/general-confusion-with-kibnas-search-bar/63665/9 "2017-07-06T13:35:58Z")

</div>


