# Inverse Query

**URL:** <https://discuss.elastic.co/t/inverse-query/160628>\
**Category:** Kibana\
**Tags:** elastic-stack-sql, canvas\
**Created:** [December 12, 2018, 10:08pm UTC](https://discuss.elastic.co/t/inverse-query/160628 "2018-12-12T22:08:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![rudyamid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rudyamid/32/38393_2.png) [@rudyamid](https://discuss.elastic.co/u/rudyamid)\
**Post date:** [December 12, 2018, 10:08pm UTC](https://discuss.elastic.co/t/inverse-query/160628/1 "2018-12-12T22:08:19Z")

</div>

I'm trying to create a Canvas markdown element with data from the following Elasticsearch SQL query:

```
SELECT Severity FROM "firewall-logs*" WHERE Severity LIKE '%critical%' AND ThreatName.keyword IS NOT NULL

```

My problem is, how do I get the inverse or "NOT LIKE" of the severity column (ie. that is not critical)? I tried using NOT LIKE and Canvas shows Expression failed with the message:

_[essql] \> Unexpected error from Elasticsearch: [sql\_illegal\_argument\_exception] Cannot evaluate script for expression LikePattern[%critical%,]_

Any ideas?

regards  
Rudy

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [December 12, 2018, 10:12pm UTC](https://discuss.elastic.co/t/inverse-query/160628/2 "2018-12-12T22:12:09Z")

</div>

cc @Catherine_Liu @Joe_Fleming can either of you please take a stab at this ?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [December 12, 2018, 11:20pm UTC](https://discuss.elastic.co/t/inverse-query/160628/3 "2018-12-12T23:20:28Z")

</div>

The problem is actually the quotes you are using. In SQL, `'` and `"` mean different things. If you are just quoting a value to handle special characters, I believe you want to use double quotes (`"`).

I get a different error when I use double quotes, and you might too:

```auto
SELECT extension,sum(bytes) AS bytes FROM "logstash*"
WHERE extension LIKE "%jpg%"
GROUP BY extension

```

> [essql] \> Couldn't parse Elasticsearch SQL query. You may need to add double quotes to names containing special characters. Check your query and try again. Error: [parsing\_exception] line 2:22: mismatched input '"%jpg%"' expecting {'?', STRING}

I'm not totally sure the sql adapter supports LIKE and NOT LIKE yet... @costin can you chime in here?

---

<div class="post-metadata">

**Author:** ![Andrei\_Stefan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrei_stefan/32/47533_2.png) [@Andrei\_Stefan](https://discuss.elastic.co/u/Andrei_Stefan)\
**Post date:** [December 13, 2018, 7:24am UTC](https://discuss.elastic.co/t/inverse-query/160628/4 "2018-12-13T07:24:24Z")

</div>

Unfortunately that's a bug. I created an issue and we'll look at it with priority: [https://github.com/elastic/elasticsearch/issues/36584](https://github.com/elastic/elasticsearch/issues/36584)

---

<div class="post-metadata">

**Author:** ![costin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/costin/32/44950_2.png) [@costin](https://discuss.elastic.co/u/costin)\
**Post date:** [December 13, 2018, 7:34am UTC](https://discuss.elastic.co/t/inverse-query/160628/5 "2018-12-13T07:34:27Z")

</div>

To clarify a bit:

1. NOT LIKE currently doesn't work - there's a bug raised for that.
2. `"` are used for identifiers, `'` is used for strings - this is all standard SQL.

The pattern matching supported by SQL is explained here:  
[https://www.elastic.co/guide/en/elasticsearch/reference/6.x/sql-index-patterns.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.x/sql-index-patterns.html)

---

<div class="post-metadata">

**Author:** ![rudyamid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rudyamid/32/38393_2.png) [@rudyamid](https://discuss.elastic.co/u/rudyamid)\
**Post date:** [January 9, 2019, 8:48pm UTC](https://discuss.elastic.co/t/inverse-query/160628/6 "2019-01-09T20:48:10Z")

</div>

Has it been fixed in release 6.5.4?

---

<div class="post-metadata">

**Author:** ![Andrei\_Stefan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrei_stefan/32/47533_2.png) [@Andrei\_Stefan](https://discuss.elastic.co/u/Andrei_Stefan)\
**Post date:** [January 10, 2019, 7:25am UTC](https://discuss.elastic.co/t/inverse-query/160628/7 "2019-01-10T07:25:01Z")

</div>

@rudyamid that issue was fixed and will be available in 6.6.0 and 7.0.0.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2019, 7:25am UTC](https://discuss.elastic.co/t/inverse-query/160628/8 "2019-02-07T07:25:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
