# Kibana dashboard multiple wildcard filters

**URL:** <https://discuss.elastic.co/t/kibana-dashboard-multiple-wildcard-filters/112530>\
**Category:** Kibana\
**Created:** [December 20, 2017, 12:34am UTC](https://discuss.elastic.co/t/kibana-dashboard-multiple-wildcard-filters/112530 "2017-12-20T00:34:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 20, 2017, 12:34am UTC](https://discuss.elastic.co/t/kibana-dashboard-multiple-wildcard-filters/112530/1 "2017-12-20T00:34:54Z")

</div>

I want to build a dashboard with filters that check for a list of phrases with wildcards to a kibana dashboard

so if any one of these(or multiple) appear in the log field I want it to appear in the dash, if not, the dash should be empty

as examples :  
net use \*  
net user user\_name \* /domain  
netsh firewall \*  
net localgroup \*

The goal is to be able to see if a workstation, adding something to the registry, added a user, mapped a network drive etc. I wan t to be able to see if activity on a workstation did one or multiple.

Please tell me this is possible, would be very cool.

Something like this -

| Computer | Command |
| --- | --- |
| VICTIMWORKSTATION | reg add “hklm\system\currentcontrolset\control\terminal server” /f /v fDenyTSConnections /t REG\_DWORD /d 0 |
| VICTIMWORKSTATION | netsh firewall set service remoteadmin enable |
| VICTIMWORKSTATION | netsh firewall set service remotedesktop enable |

Starting with this query but it doesn't want to work -  
But this doesn't want to work --

```
{
  "query": {
    "bool": {
      "must": [
        {
          "wildcard": {
            "event_data.CommandLine": "net *"
          }
        },
        {
          "wildcard": {
            "event_data.CommandLine": "reg *"
          }
        },
        {
          "wildcard": {
            "event_data.CommandLine": "netsh firewall*"
          }
        },
        {
          "wildcard": {
            "event_data.CommandLine": "net localgroup *"
          }
        },
        {
          "wildcard": {
            "event_data.CommandLine": "putty.exe *"
          }
        }
      ],
      "minimum_should_match": 1
    }
  }
}

```

Thanks!!!

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 20, 2017, 4:17am UTC](https://discuss.elastic.co/t/kibana-dashboard-multiple-wildcard-filters/112530/2 "2017-12-20T04:17:41Z")

</div>

I think I might be close to it...

```
{
  "query": {
    "bool": {
      "should": [
        {
          "wildcard": {
            "event_data.Suspicious": "net *"
          }
        },
        {
          "wildcard": {
            "event_data.Suspicious": "reg *"
          }
        }
      ],
      "minimum_should_match": 1
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 20, 2017, 7:39pm UTC](https://discuss.elastic.co/t/kibana-dashboard-multiple-wildcard-filters/112530/3 "2017-12-20T19:39:04Z")

</div>

I'm stuck...

'should' seems to be perfect for checking for a list of things. BUT can I add a 'NOT' to it? I.E. this won't work -

```
 {
  "query": {
    "bool": {
      "minimum_should_match": 1,
      "should": [
        {
          "wildcard": {
            "event_data.Suspicious": "net *"
          }
        },
        {
          "wildcard": {
            "event_data.Suspicious": "reg *"
          }
        }
      ],
  "must_not": [
    {
      "match_phrase": {
        "event_data.Suspicious": "reg add HKLM\\SOFTWARE\\Microsoft\\windows\\currentversion\\policies\\system"
      }
    }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 21, 2017, 4:58pm UTC](https://discuss.elastic.co/t/kibana-dashboard-multiple-wildcard-filters/112530/4 "2017-12-21T16:58:43Z")

</div>

Whew got it to work but it had to be an exact match. Trick that helped me --  
Find what you want to filter in the dashboard, hit the '-' sign that will add the filter to the top of the dashboard. Edit that filter and that should give the DSL elasticsearch uses to see that data! Copy that into your own filter and boom it works.

---

<div class="post-metadata">

**Author:** ![Court](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/court/32/6640_2.png) [@Court](https://discuss.elastic.co/u/Court)\
**Post date:** [December 22, 2017, 3:39pm UTC](https://discuss.elastic.co/t/kibana-dashboard-multiple-wildcard-filters/112530/5 "2017-12-22T15:39:31Z")

</div>

Sorry no one was able to help you, but thanks for posting the solution you came up with! That'll help folks in the future that are trying to do the same thing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2018, 3:40pm UTC](https://discuss.elastic.co/t/kibana-dashboard-multiple-wildcard-filters/112530/6 "2018-01-19T15:40:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
