# How to pass urlparam value to KQL

**URL:** <https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172>\
**Category:** Kibana\
**Created:** [July 20, 2021, 1:45pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172 "2021-07-20T13:45:32Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![tangkalo](https://avatars.discourse-cdn.com/v4/letter/t/cdc98d/32.png) [@tangkalo](https://discuss.elastic.co/u/tangkalo)\
**Post date:** [July 20, 2021, 1:45pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/1 "2021-07-20T13:45:32Z")

</div>

Hi, I read about threads related to this need and know that there is currently not a way to directly plug in the value in the KQL using urlparam; however, is there a way to do it indirectly? I am thinking about using variables. It works in markdown using var\_set and {var "variableName"} but I don't know the syntax of using {var "variableName"} in the KQL. I tried the following but it doesn't evaluate the '{var name="urlParameter"}' correctly(no result returned). Any tips will be apprepriated. Thanks.

```auto
| var_set name="requestMethodParam" value={urlparam param=requestMethod default="xxx"}
| var name="requestMethodParam"
| essql 
  query={string "SELECT \"@timestamp\"
as dateTime, (perfElapseTime)/1000 as \"Time\"
FROM \"log*\"
WHERE filename = 'performance.log'
ND perfMethodName = '{var name=\"urlParameter\"}'
ORDER BY dateTime asc"
}

```

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [July 20, 2021, 2:50pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/2 "2021-07-20T14:50:01Z")

</div>

1. You're not using KQL in your example, but I can see that you are having issues with your SQL WHERE clause.

2. The `{string` function only _concatenates strings_, it does not evaluate expressions inside strings

3. Try this:

```auto
| var_set name="requestMethodParam" value={urlparam param=requestMethod default="xxx"}
| var name="requestMethodParam"
| essql 
  query={string "SELECT \"@timestamp\"
as dateTime, (perfElapseTime)/1000 as \"Time\"
FROM \"log*\"
WHERE filename = 'performance.log'
ND perfMethodName = '"
{var name="urlParameter"}
"' ORDER BY dateTime asc"
}

```

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [July 20, 2021, 2:50pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/3 "2021-07-20T14:50:27Z")

</div>

The issue is that you not used a new expression within your query string.

You need to end the first string using "  
then it is evaluating your expression and concatinating the result String into the expression.

Here you can find examples die that

> **[Kibana Canvas examples | Download now from Elastic content share](https://elastic-content-share.eu/downloads/category/kibana/kibana-canvas-examples/)**
>
> Download Kibana Canvas examples or deploy directly into your Elastic Cloud deployments. Our Kibana Canvas examples helping you to quickly start. %

---

<div class="post-metadata">

**Author:** ![tangkalo](https://avatars.discourse-cdn.com/v4/letter/t/cdc98d/32.png) [@tangkalo](https://discuss.elastic.co/u/tangkalo)\
**Post date:** [July 20, 2021, 3:28pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/4 "2021-07-20T15:28:51Z")

</div>

Thanks. Unfortunately it didn't work. Here's the final version based on your suggestion on the expression.

```auto
filters
| var_set name="requestMethodParam" value={urlparam param=requestMethod default="xxx"}
| var name="requestMethodParam"
| essql 
  query={string "SELECT \"@timestamp\"
as dateTime, (perfElapseTime)/1000 as \"Time\"
FROM \"log*\"
WHERE filename = 'performance.log'
AND perfMethodName = '\"{var name=\"requestMethodParam\"}\"'
ORDER BY dateTime asc"

```

}

---

<div class="post-metadata">

**Author:** ![tangkalo](https://avatars.discourse-cdn.com/v4/letter/t/cdc98d/32.png) [@tangkalo](https://discuss.elastic.co/u/tangkalo)\
**Post date:** [July 20, 2021, 3:31pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/5 "2021-07-20T15:31:47Z")

</div>

Actually I got this error.

```auto
Whoops! Expression failed
Expression failed with the message:
[essql] > Can not cast 'string' to any of 'filter'

```

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [July 20, 2021, 3:44pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/6 "2021-07-20T15:44:44Z")

</div>

That error is because you have added the extra `| var name="requestMethodParam"` in front of `essql`. You need to remove that from line 3.

---

<div class="post-metadata">

**Author:** ![tangkalo](https://avatars.discourse-cdn.com/v4/letter/t/cdc98d/32.png) [@tangkalo](https://discuss.elastic.co/u/tangkalo)\
**Post date:** [July 20, 2021, 3:54pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/7 "2021-07-20T15:54:07Z")

</div>

Hi, Wylie. Do yo mean removing the whole line on line 3 or just the pipe |?

I am afraid I don't really understand how var\_set and var works according to the documentation below.

> **[Canvas function reference | Kibana Guide \[7.12\] | Elastic](https://www.elastic.co/guide/en/kibana/7.12/canvas-function-reference.html#var_set_fn)**

I also found examples of them here - [How to create a new line on a kibana canvas table - #6 by wylie](https://discuss.elastic.co/t/how-to-create-a-new-line-on-a-kibana-canvas-table/248179/6) .

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [July 20, 2021, 4:08pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/8 "2021-07-20T16:08:50Z")

</div>

You need to remove the whole piped `| var ...` function on line 3, because it is returning a `string` type that `essql` can't take.

---

<div class="post-metadata">

**Author:** ![tangkalo](https://avatars.discourse-cdn.com/v4/letter/t/cdc98d/32.png) [@tangkalo](https://discuss.elastic.co/u/tangkalo)\
**Post date:** [July 20, 2021, 4:14pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/9 "2021-07-20T16:14:25Z")

</div>

> [@tangkalo](#):
>
> `var name="requestMethodParam"`

Thanks. It makes sense.

Unfortunately it still returns a empty resultset - I verified by using | render as "debug".

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [July 20, 2021, 7:34pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/10 "2021-07-20T19:34:54Z")

</div>

At this point you will have to debug the SQL query using your own data. I recommend either looking at the Network tab to capture the actual SQL query that you're running, or you could remove the `essql` command and just run the `string "SELECT ..."` to get the query. That could help you debug.

---

<div class="post-metadata">

**Author:** ![tangkalo](https://avatars.discourse-cdn.com/v4/letter/t/cdc98d/32.png) [@tangkalo](https://discuss.elastic.co/u/tangkalo)\
**Post date:** [July 22, 2021, 9:01pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/11 "2021-07-22T21:01:52Z")

</div>

Thanks @wylie @Felix_Roessel . I finally got what Felix was saying. Here's the final version that works and be able to use the ulr param value.

```auto
filters
| var_set name="requestMethodParam" value={urlparam param="requestMethod" default="xxx"}
| essql {string "SELECT \"@timestamp\"
as dateTime, (perfElapseTime)/1000 as \"Time\"
FROM \"log*\"
WHERE filename = 'performance.log'
AND branch = 'chq' AND perfMethodName = '" {var "requestMethodParam"} "' ORDER BY dateTime asc"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2021, 9:01pm UTC](https://discuss.elastic.co/t/how-to-pass-urlparam-value-to-kql/279172/12 "2021-08-19T21:01:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
