# How do I check if field contains certain string?

**URL:** <https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148>\
**Category:** Elasticsearch\
**Created:** [July 7, 2022, 7:18pm UTC](https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148 "2022-07-07T19:18:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DataStorageMuse](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@DataStorageMuse](https://discuss.elastic.co/u/DataStorageMuse)\
**Post date:** [July 7, 2022, 7:18pm UTC](https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148/1 "2022-07-07T19:18:23Z")

</div>

How do I query an index to return documents where a field contains only a certain string (analagous to SQL contains). This is the corresponding SQL query I would like to do in ElasticSearch. SELECT \* FROM table WHERE CONTAINS(fieldname, string).

---

<div class="post-metadata">

**Author:** ![hansc](https://avatars.discourse-cdn.com/v4/letter/h/a8b319/32.png) [@hansc](https://discuss.elastic.co/u/hansc)\
**Post date:** [July 7, 2022, 8:26pm UTC](https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148/2 "2022-07-07T20:26:42Z")

</div>

To use REST API, for example

```auto

 GET /metricbeat-8.3.1/_search?size=1
{
  "query": {
    "wildcard": {
      "agent.name": "*file*"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![hansc](https://avatars.discourse-cdn.com/v4/letter/h/a8b319/32.png) [@hansc](https://discuss.elastic.co/u/hansc)\
**Post date:** [July 7, 2022, 8:43pm UTC](https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148/4 "2022-07-07T20:43:45Z")

</div>

I dont understand why not.

---

<div class="post-metadata">

**Author:** ![DataStorageMuse](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@DataStorageMuse](https://discuss.elastic.co/u/DataStorageMuse)\
**Post date:** [July 7, 2022, 8:47pm UTC](https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148/5 "2022-07-07T20:47:04Z")

</div>

I'm not asking how to make a query or using the REST API. I'm asking about how to do a SQL CONTAINS query in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![hansc](https://avatars.discourse-cdn.com/v4/letter/h/a8b319/32.png) [@hansc](https://discuss.elastic.co/u/hansc)\
**Post date:** [July 7, 2022, 9:23pm UTC](https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148/6 "2022-07-07T21:23:21Z")

</div>

Little curious why since the SQL is still passed to API and it has limitations but this is working.

```auto
 GET /_sql?format=txt
{
  "query": """
    SELECT agent.version FROM "metricbeat-8.3.1" WHERE agent.name LIKE '%file%' LIMIT 5
  """
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2022, 9:24pm UTC](https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148/7 "2022-08-04T21:24:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
