# Irrelevant field search results

**URL:** <https://discuss.elastic.co/t/irrelevant-field-search-results/293188>\
**Category:** Elasticsearch\
**Created:** [December 30, 2021, 9:13am UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188 "2021-12-30T09:13:11Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [December 30, 2021, 9:13am UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/1 "2021-12-30T09:13:12Z")

</div>

Hi,

I've made this Lucene query in Kibana to search if Nginx access logs contain a URL with the word "malware":

```auto
source.as.organization.name: (/.*[Mm][Aa][Ll][Ww][Aa][Rr][Ee].*/) 

```

But in Kibana I'm getting the results from other Filebeats fields like

`event.dataset:threatintel.abusemalware` although I'm expecting to have returned values from ` source.as.organization.name:`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/c/9c158bb554f0439e8bd605d89bfd514a4c808173.png)

Is this a bug where I search values form a field and get results from other fields? Or is there something wrong from my side?

Regards,

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [December 30, 2021, 9:51am UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/2 "2021-12-30T09:51:29Z")

</div>

A few questions:

1. Which version of Kibana are you using?
2. Could you open Inspector in Discover and paste the `query` part of the request and the `highlight` part of the response? You should see something like this in the request:

```auto
"query_string": {
     "query": "Dest: Reno*",
      "analyze_wildcard": true,
 }

```

and something like this in the response:

```auto
"highlight": {
    "Dest": [
         "@kibana-highlighted-field@Reno Tahoe International Airport@/kibana-highlighted-field@"
    ]
},

```

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [December 30, 2021, 12:05pm UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/3 "2021-12-30T12:05:48Z")

</div>

Thanks @majagrubic for getting back.

1. Which version of Kibana are you using?

- Latest 7.16

1. Could you open Inspector in Discover and paste the `query` part of the request and the `highlight` part of the response? You should see something like this in the request:

```auto
"query_string": {
            "query": "source.as.organization.name: (/.*[Mm][Aa][Ll][Ww][Aa][Rr][Ee].*/) ",
            "analyze_wildcard": true,

```

```auto
"highlight": {
            "fileset.name": [
              "@kibana-highlighted-field@abusemalware@/kibana-highlighted-field@"
            ],
            "event.dataset": [
              "@kibana-highlighted-field@threatintel.abusemalware@/kibana-highlighted-field@"
            ],
            "tags": [
              "@kibana-highlighted-field@threatintel-abusemalware@/kibana-highlighted-field@"
            ]
          }

```

Your help is appreciated.

Regards,

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [December 30, 2021, 12:16pm UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/4 "2021-12-30T12:16:27Z")

</div>

Discover is correctly highlight what is receives from an Elasticsearch response. I will move this to the ES forum, perhaps they have more insight into what is happening.

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [December 30, 2021, 1:02pm UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/5 "2021-12-30T13:02:25Z")

</div>

Ok many thanks, I don't know if I'm right but the highlight should return `source.as.organization.name` instead of `event.dataset` right?

Regarding the reply, I should get it here in this ticket right?

Regards,

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [December 30, 2021, 7:33pm UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/6 "2021-12-30T19:33:48Z")

</div>

That's right, my colleagues should pick it up next.

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [January 6, 2022, 7:40am UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/7 "2022-01-06T07:40:42Z")

</div>

Hi @majagrubic,

Any updates on this? Hope we found a solution.

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [January 18, 2022, 12:59pm UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/8 "2022-01-18T12:59:22Z")

</div>

Hi @majagrubic and all elastic members.

I've updated to the latest 7.16.3 environment but still get same issue. Is this a bug to be reported or is there any help regarding this?

Any help is really appreciated.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [January 18, 2022, 3:07pm UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/9 "2022-01-18T15:07:08Z")

</div>

@majagrubic would have to confirm this, but I believe discover uses `require_field_match: false` on the highlighting config - so that'll highlight all of those terms. [Here](https://www.elastic.co/guide/en/elasticsearch/reference/current/highlighting.html) are the docs for that. In other words - I think kibana is asking for ES to do this. Kibana has a "debug" link in discover that'll show you the search it sent to ES. If it has that parameter in it then it's _asking_ for ES to highlight all of the fields.

If it isn't then maybe it's something to do with the lucene query. I'm not particularly good with those, but I wonder if it should be `source.as.organization.name:/.*[Mm][Aa][Ll][Ww][Aa][Rr][Ee].*/` - without the space between the name and the term. I don't the query string query syntax much - I tend to use explicit queries for this sort of thing. Kibana let's you build those as "filters" I think. So, like, if you make a filter on `source.as.organization.name` of type `regexp` and pass that regex that'll be more explicit.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2022, 6:48am UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/10 "2022-01-19T06:48:28Z")

</div>

7.1 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [January 20, 2022, 9:12am UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/11 "2022-01-20T09:12:58Z")

</div>

Thanks @nik9000

I think the removing "space" from the query solved part of the problem.

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2022, 9:13am UTC](https://discuss.elastic.co/t/irrelevant-field-search-results/293188/12 "2022-02-17T09:13:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
