# How to write kql query in kibana to include only 9 characters of a field?

**URL:** <https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672>\
**Category:** Kibana\
**Created:** [June 8, 2022, 9:56am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672 "2022-06-08T09:56:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arifullah](https://avatars.discourse-cdn.com/v4/letter/a/c6cbf5/32.png) [@Arifullah](https://discuss.elastic.co/u/Arifullah)\
**Post date:** [June 8, 2022, 9:56am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672/1 "2022-06-08T09:56:33Z")

</div>

I am using kibana 8.1 so I want to filter the data in discover section. Tha index has a field whic is in number format and it has different kinds of numbers which range from 4 characters up to 12 or 13 characters. So I want to show me only the data which are 9 or above 9 characters in that specific field. The field name is for example phone\_number.

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [June 8, 2022, 10:17am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672/2 "2022-06-08T10:17:06Z")

</div>

Hi @Arifullah ,

if the field is numeric I think you might leverage Kibana filters for this use case:

 ![Screenshot 2022-06-08 at 12.12.58](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c90f344210f24d6161cf74a60db8e32e208e1e2.png)

If your field is keyword based, you might leverage runtime fields to create a new field with only values which have a length of 9, and return null otherwise.

---

<div class="post-metadata">

**Author:** ![Arifullah](https://avatars.discourse-cdn.com/v4/letter/a/c6cbf5/32.png) [@Arifullah](https://discuss.elastic.co/u/Arifullah)\
**Post date:** [June 8, 2022, 10:23am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672/3 "2022-06-08T10:23:03Z")

</div>

Hi @Marco_Liberati  
there is no field by the name of byte in my index. The field which I want to filter is phone\_number and it's type is long

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [June 8, 2022, 10:43am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672/4 "2022-06-08T10:43:06Z")

</div>

Hi @Arifullah ,

you can configure the filter with your field name, but the same logic should apply.

---

<div class="post-metadata">

**Author:** ![Arifullah](https://avatars.discourse-cdn.com/v4/letter/a/c6cbf5/32.png) [@Arifullah](https://discuss.elastic.co/u/Arifullah)\
**Post date:** [June 8, 2022, 10:53am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672/5 "2022-06-08T10:53:20Z")

</div>

Thank you @Marco_Liberati your answer solved my problem.

---

<div class="post-metadata">

**Author:** ![Arifullah](https://avatars.discourse-cdn.com/v4/letter/a/c6cbf5/32.png) [@Arifullah](https://discuss.elastic.co/u/Arifullah)\
**Post date:** [June 8, 2022, 11:02am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672/6 "2022-06-08T11:02:04Z")

</div>

@Marco_Liberati I have also another question if you can help me I shal be very thankfull.  
There is also field by the name date but the data of that field is not in a proper date format its only a number. So I want a filter to include only the data of max date field I mean how to create a filter which finds the maximum value of the date field and filter the index based upon that value.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2022, 11:02am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672/7 "2022-07-06T11:02:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
