# How to search a value by special character

**URL:** <https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [May 29, 2023, 5:46pm UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611 "2023-05-29T17:46:53Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 29, 2023, 5:46pm UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/1 "2023-05-29T17:46:53Z")

</div>

Hi there,

so i have a field named uri\_api and some of them have a value like this:  
/scrt/kpi/v3/code/shean%20jeremy%20patok

i want to search other value like that in uri\_api field. how can i achieve it? i already try it like this but it doesn't return any result:  
`uri_api : *%20*`

then i try make a query like this and it give me the result :  
`uri_api : *20*`

so my question is why i can't use special character to search some value? based on [this](https://www.elastic.co/guide/en/kibana/7.17/kuery-query.html) documentation, it says the characters that must be escaped just this  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/2/b21134f2048c0d7a39d7409847235cae5873de86.png)

so why my query using % didn't work?

Thanks

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [May 29, 2023, 6:48pm UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/2 "2023-05-29T18:48:34Z")

</div>

Hello @yuswanul,

Yes, `*%20*` should work,

Is there any error message? If you don't see any error messages, I suggest you try copying and pasting this full `uri_api` value for testing purposes. As it contains `%` it shouldn't work without escaping the character as well.

Additionally, please ensure that the time range is correct. You can perform a test using `uri_api: *` and check if the documents containing `%20` are included.

Hope this helps!

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 29, 2023, 7:37pm UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/3 "2023-05-29T19:37:33Z")

</div>

The full uri\_api value is same with i wrote before. And for the time range i'm sure there's no problem there but for error full message maybe i can send you later.

But for sure the value of uri\_api is exactly same with i mention before. So you can test it locally. Thanks

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [May 29, 2023, 7:45pm UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/4 "2023-05-29T19:45:17Z")

</div>

What version of Elastic are you using? I would appreciate it if you could share the error message with me. This will help me better understand the context in which the error occurred.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 29, 2023, 8:11pm UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/5 "2023-05-29T20:11:15Z")

</div>

I'm using v7.17. I can't share the error message right now cause i'm not on my laptop. I'll send you later

Pada tanggal Sel, 30 Mei 2023 02.55, Priscilla Parodi via Discuss the Elastic Stack \<[notifications@elastic.discoursemail.com](mailto:notifications@elastic.discoursemail.com)\> menulis:

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 31, 2023, 2:29am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/6 "2023-05-31T02:29:44Z")

</div>

i've tried using `*%20*` and it's doesn't return any error or result. but when i try to using `*\%20*` it give me this error  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6aa49728900994e10024445efa8dac9c7d94c23a.jpeg)

the only one query that give me the result is this:  
20\*

the `%` didn't included in search result  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d338e346c375a108fe9366b5cb396cc0f2933859.png)

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [May 31, 2023, 4:42am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/7 "2023-05-31T04:42:37Z")

</div>

You're right, I tested it running Elastic 8.7, and it worked. However, now I tested it running on 7.17 and it didn't work.

`%` is not listed as a character to escape in the documentation, for both versions.

So, there might be some other reason for this issue. Would you mind opening an issue in the [Kibana repository](https://github.com/elastic/kibana/issues) and mention this post?

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [May 31, 2023, 5:52am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/8 "2023-05-31T05:52:02Z")

</div>

sure, i can do that. but for now, i have another question.

how if i want to search a value that has a space inside it in 7.17?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a1d38bdbe27484006fa9dcfc8827425b82a411e4.png)

the data that has `+` between **N** and **7hWw** are still included in search results.

i already tried to search like this and it's match with one data

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/9/99856acaea285de7997f159537212cdb588153a1.png)

but why can't i use the same way to search the data that has whitespace?  
do you think it's possible to include whitespace as a search?

thanks

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [May 31, 2023, 11:51pm UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/9 "2023-05-31T23:51:11Z")

</div>

To include whitespace as part of the query you can add the keyword value surrounded by double quotes.

For example, considering the message values:

`Sean 20`

`Sean+20`

And the query:

`message.keyword : "Sean 20"`

This should match `Sean 20` but not `Sean+20`.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [June 1, 2023, 1:59am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/10 "2023-06-01T01:59:15Z")

</div>

But if i using keyword, it means i need a exact value of the field right? How about if i want to search initial value that contain a whitespace?

Thanks

Pada tanggal Kam, 1 Jun 2023 07.01, Priscilla Parodi via Discuss the Elastic Stack \<[notifications@elastic.discoursemail.com](mailto:notifications@elastic.discoursemail.com)\> menulis:

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [June 1, 2023, 3:36am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/11 "2023-06-01T03:36:57Z")

</div>

What is your use case and why did you choose KQL?

If your goal is to be able to fetch data trough the Kibana Discover query bar, you can add a filter “+ Add Filter” and click “Edit as Query DSL” and then for something similar to what you want I would use a [query\_string query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html) and save the filter.

Example:

 ![IMG_1317](https://us1.discourse-cdn.com/elastic/original/3X/6/b/6bd885622a7f41f7be7386640f983a0fb65e65e9.jpeg)

You can use \* and whitespace, so it works for both use cases. Considering the context, in my opinion, it seems to be a good option.

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [June 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/12 "2023-06-01T04:05:42Z")

</div>

Note: This is just an example in fact you can add the [Query DSL](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/query-dsl.html) that makes more sense, considering the use case. [Full text queries.](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/full-text-queries.html)

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [June 5, 2023, 7:06am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/13 "2023-06-05T07:06:20Z")

</div>

so i had a field that have these types of value. note that the value is actually pretty long. these are just the snippets and the name of the field is `requestPayload`

1. "hho/uFChjOENdwrbN 7hWw=="
2. "hho/uFChjOENdwrbN+7hWw=="

i want to search requestPayload field that has value like #1. but it seems if i use query like `requestPayload.keyword : *hho/uFChjOENdwrbN 7hWw==*` it doesn't give me the result. it keeps give me the result of type #2 which has `+` on it, not space

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [June 6, 2023, 3:24am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/14 "2023-06-06T03:24:45Z")

</div>

> [@Priscilla\_Parodi](#):
>
> If your goal is to be able to fetch data trough the Kibana Discover query bar, you can add a filter “+ Add Filter” and click “Edit as Query DSL” and then for something similar to what you want I would use a [query\_string query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html) and save the filter.

Are you adding a Query DSL filter like I suggested?

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [June 6, 2023, 4:23am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/15 "2023-06-06T04:23:16Z")

</div>

> [@Priscilla\_Parodi](#):
>
> What is your use case and why did you choose KQL?

i just expain my problem. i forgot to mention your question, sorry. let me try your suggestion first. thanks

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [June 6, 2023, 4:29am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/16 "2023-06-06T04:29:08Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/375162176981a916326d0c62f0bbf2a72b601bcb.png)

i got this exception after i create the filter. do i need to escape the "/" character? but i already try it too and this exception still appear

i think the regex will give me the result. i'll try it

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [June 6, 2023, 4:45am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/17 "2023-06-06T04:45:54Z")

</div>

this is the filter  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/1/611e444941ae07bdc6604a316d9cec8882d889c1.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/7/47f3513f0f72ac09b03e239b7e8b894067e68d98.png)

and this is the value of the field  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/d/edb967764db43becf26d0e1c3522139966956ea6.png)

finally it's work, thank you so much @Priscilla_Parodi

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [June 6, 2023, 11:17am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/18 "2023-06-06T11:17:22Z")

</div>

Awesome! You're welcome!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2023, 11:18am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611/19 "2023-07-04T11:18:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
