# How to quote/escape esQuery when it contains quotes?

**URL:** <https://discuss.elastic.co/t/how-to-quote-escape-esquery-when-it-contains-quotes/277384>\
**Category:** Kibana\
**Created:** [June 29, 2021, 8:39pm UTC](https://discuss.elastic.co/t/how-to-quote-escape-esquery-when-it-contains-quotes/277384 "2021-06-29T20:39:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [June 29, 2021, 8:39pm UTC](https://discuss.elastic.co/t/how-to-quote-escape-esquery-when-it-contains-quotes/277384/1 "2021-06-29T20:39:55Z")

</div>

Dear all =)

I am using the [Create Rule API](https://www.elastic.co/guide/en/kibana/master/create-rule-api.html) with the Elasticsearch query action. It works perfectly until I need to query something that includes quotes. Example `host:"10.250.11.11"`.

Ideally I would like to write it as

```auto
"esQuery": '{ "query": { "query_string": { "query": "host:"10.250.11.11" } } }'

```

but then Kibana fails with invalid json. If I do

```auto
"esQuery": "{ \"query\": { \"query_string\": { \"query\": \"host:\"10.250.11.11\"\" } } }"

```

then Kibana removes the quotes around the IP address.

**Question**

Does anyone know how to quote this correctly?

Below is my entire payload

Hugs  
Sandra =)

```auto
{
   "params":{
      "esQuery": " _____REPLACE_THIS_____",
      "size":100,
      "timeWindowSize":" _____REPLACE_THIS_____",
      "timeWindowUnit":"s",
      "threshold":[
         " _____REPLACE_THIS_____"
      ],
      "thresholdComparator":">=",
      "index":[
         " _____REPLACE_THIS_____"
      ],
      "timeField":"@timestamp"
   },
   "consumer":"alerts",
   "schedule":{
      "interval":" _____REPLACE_THIS_____"
   },
   "tags":[

   ],
   "name":" _____REPLACE_THIS_____",
   "enabled":true,
   "throttle":null,
   "rule_type_id":".es-query",
   "notify_when":"onActiveAlert",
   "actions":[
      {
         "group":"query matched",
         "id":" _____REPLACE_THIS_____",
         "params":{
            "body":{
               _____REPLACE_THIS_____
            }
         }
      }
   ]
}

```

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [June 29, 2021, 9:29pm UTC](https://discuss.elastic.co/t/how-to-quote-escape-esquery-when-it-contains-quotes/277384/2 "2021-06-29T21:29:40Z")

</div>

I think I understand what you're trying to achieve; I believe you need to double-escape your innermost quotation marks. For example:

```auto
"esQuery": "{ \"query\": { \"query_string\": { \"query\": \"host:\\\"10.250.11.11\\\"\" } } }"

```

When that esQuery string is parsed into JSON, it becomes:

```auto
{ "query": { "query_string": { "query": "host:\"10.250.11.11\"" } } }

```

Give that a shot and see if it works!

---

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [June 30, 2021, 11:26am UTC](https://discuss.elastic.co/t/how-to-quote-escape-esquery-when-it-contains-quotes/277384/3 "2021-06-30T11:26:31Z")

</div>

Thanks a lot Joe! It did the trick =)

Hugs,  
Sandra =)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2021, 11:26am UTC](https://discuss.elastic.co/t/how-to-quote-escape-esquery-when-it-contains-quotes/277384/4 "2021-07-28T11:26:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
