# How to search visualizations that use a specific index pattern

**URL:** <https://discuss.elastic.co/t/how-to-search-visualizations-that-use-a-specific-index-pattern/134236>\
**Category:** Kibana\
**Created:** [June 1, 2018, 2:23pm UTC](https://discuss.elastic.co/t/how-to-search-visualizations-that-use-a-specific-index-pattern/134236 "2018-06-01T14:23:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexandre\_Bunn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexandre_bunn/32/49369_2.png) [@Alexandre\_Bunn](https://discuss.elastic.co/u/Alexandre_Bunn)\
**Post date:** [June 1, 2018, 2:23pm UTC](https://discuss.elastic.co/t/how-to-search-visualizations-that-use-a-specific-index-pattern/134236/1 "2018-06-01T14:23:14Z")

</div>

Good morning

I would like to check which Visualizations on kibana are using a certain index pattern. I am trying to query it on .kibana indice but I'am doing something wrong. I am running the query on DevTools of Kibana:

GET /.kibana/\_search  
{  
"query" : {  
"match" : { "kibanaSavedObjectMeta.searchSourceJSON.index": "imap-cxp-\*" }  
}  
}

THe query above returns o Objects, but it was supposed to return something because matching just by \_type: "visualization" One of the records returned as we can see below:

```
  {
    "_index": ".kibana",
    "_type": "visualization",
    "_id": "0c62a2a0-34c2-11e7-871a-37e0d55ebfb9",
    "_score": 1,
    "_source": {
      "title": "GazlinuxLogs - Falha envio Hostopia",
      "visState": """{"title":"GazlinuxLogs - Falha envio","type":"metric","params":{"handleNoResults":true,"fontSize":60},"aggs":[{"id":"1","enabled":true,"type":"count","schema":"metric","params":{"customLabel":"Erro envio"}}],"listeners":{}}""",
      "uiStateJSON": "{}",
      "description": "",
      "version": 1,
      "kibanaSavedObjectMeta": {
        "searchSourceJSON": """{"index":"imap-cxp-*","query":{"query_string":{"query":"subject: (+\"ERRO ao tentar enviar\")","analyze_wildcard":true}},"filter":[]}"""
      }
    }
  },

```

Thanks for the attention

Regards

Alexandre

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [June 1, 2018, 3:03pm UTC](https://discuss.elastic.co/t/how-to-search-visualizations-that-use-a-specific-index-pattern/134236/2 "2018-06-01T15:03:07Z")

</div>

That field kibanaSavedObjectMeta.searchSourceJSON is stored as a string, so you would need to do a prefix query. Pretty sure this will work:  
GET .kibana/\_search  
{  
"query": {  
"prefix": {  
"kibanaSavedObjectMeta.searchSourceJSON": {  
"value": "{\"index\":\"imap-cxp-\*\""  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [June 1, 2018, 3:07pm UTC](https://discuss.elastic.co/t/how-to-search-visualizations-that-use-a-specific-index-pattern/134236/3 "2018-06-01T15:07:19Z")

</div>

Discuss is mangling the formatting, sorry about that.

---

<div class="post-metadata">

**Author:** ![Alexandre\_Bunn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexandre_bunn/32/49369_2.png) [@Alexandre\_Bunn](https://discuss.elastic.co/u/Alexandre_Bunn)\
**Post date:** [June 2, 2018, 5:51pm UTC](https://discuss.elastic.co/t/how-to-search-visualizations-that-use-a-specific-index-pattern/134236/4 "2018-06-02T17:51:27Z")

</div>

> [@Bill\_McConaghy](#):
>
> mangling

I've tried with your suggestion but it didn't work:

GET .kibana/\_search  
{  
"query": {  
"prefix": {  
"kibanaSavedObjectMeta.searchSourceJSON": {  
"value": "{"index":"imap-cxp-\*""  
}  
}  
}  
}

The result is:

{  
"took": 1,  
"timed\_out": false,  
"\_shards": {  
"total": 1,  
"successful": 1,  
"failed": 0  
},  
"hits": {  
"total": 0,  
"max\_score": null,  
"hits":   
}  
}

Let me show you the complete json of a query that get just one record based on its \_id and type:

GET /.kibana/\_search  
{  
"query" : {  
"bool": {  
"must": [  
{"term" : { "\_type": "visualization" }},  
{"term" : { "\_id": "f85a92a0-34c0-11e7-871a-37e0d55ebfb9" }}  
]  
}  
}  
}

The result is:

{  
"took": 1,  
"timed\_out": false,  
"\_shards": {  
"total": 1,  
"successful": 1,  
"failed": 0  
},  
"hits": {  
"total": 1,  
"max\_score": 2,  
"hits": [  
{  
"\_index": ".kibana",  
"\_type": "visualization",  
"\_id": "f85a92a0-34c0-11e7-871a-37e0d55ebfb9",  
"\_score": 2,  
"\_source": {  
"title": "GazlinuxLogs - Recorredor",  
"visState": """{"title":"GazlinuxLogs - Recorredor","type":"metric","params":{"handleNoResults":true,"fontSize":60},"aggs":[{"id":"1","enabled":true,"type":"count","schema":"metric","params":{"customLabel":"Recorredor"}}],"listeners":{}}""",  
"uiStateJSON": "{}",  
"description": "",  
"version": 1,  
"kibanaSavedObjectMeta": {  
"searchSourceJSON": """{"index":"imap-cxp-\*","query":{"query\_string":{"query":"subject: Sistema Recorredor","analyze\_wildcard":true}},"filter":}"""  
}  
}  
}  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![Alexandre\_Bunn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexandre_bunn/32/49369_2.png) [@Alexandre\_Bunn](https://discuss.elastic.co/u/Alexandre_Bunn)\
**Post date:** [June 8, 2018, 7:16pm UTC](https://discuss.elastic.co/t/how-to-search-visualizations-that-use-a-specific-index-pattern/134236/5 "2018-06-08T19:16:04Z")

</div>

Is there a documentation that I can check to try to perform this query?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2018, 7:16pm UTC](https://discuss.elastic.co/t/how-to-search-visualizations-that-use-a-specific-index-pattern/134236/6 "2018-07-06T19:16:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
