# Kibana filter

**URL:** <https://discuss.elastic.co/t/kibana-filter/57532>\
**Category:** Kibana\
**Created:** [August 8, 2016, 10:00pm UTC](https://discuss.elastic.co/t/kibana-filter/57532 "2016-08-08T22:00:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [August 8, 2016, 10:00pm UTC](https://discuss.elastic.co/t/kibana-filter/57532/1 "2016-08-08T22:00:04Z")

</div>

How would I filter the data on the current bar graph using filter like the one bellow that I run from curl (and it works) - need to reduce data on the graph by only showing records that have the value of query run time \> 10 seconds (this comes from slow\_qyery.log MySQL log file):

curl -X GET 'localhost:9200/my-filebeat-2016.08.08/\_search?pretty=true&size=10000' -d '  
{ "sort" : ["@timestamp"],  
"query": {  
"query\_string": {  
"query": "ses\_slowq\_rtime:\>10.0",  
"analyze\_wildcard": true  
}  
}  
}  
';

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 9, 2016, 12:14am UTC](https://discuss.elastic.co/t/kibana-filter/57532/2 "2016-08-09T00:14:54Z")

</div>

If you add a filter you can then edit that and add in your own json with this.

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [August 9, 2016, 12:46am UTC](https://discuss.elastic.co/t/kibana-filter/57532/3 "2016-08-09T00:46:29Z")

</div>

I tried - but JSON highlights the code as invalid - with red underlines - if I cut/paste the same code, plut the "1 ERROR" sign at the top:  
"query": {  
"query\_string": {  
"query": "ses\_slowq\_rtime:\>10.0",  
"analyze\_wildcard": true  
}  
}

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [August 9, 2016, 8:25pm UTC](https://discuss.elastic.co/t/kibana-filter/57532/4 "2016-08-09T20:25:45Z")

</div>

resolved - just like you said - added the json one line into the search bar of the graph:

{"query":{"query\_string":{"query":"ses\_slowq\_rtime:\>100.0","analyze\_wildcard":true}}}

Also had to flatten the script so there are no new lines and carriage returns.

Thank you - also thanks to my coworker Brad for pointing out that this goes into the top search bar and not into the JSON section inside the Advanced part of the graph build area.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 9, 2016, 8:59pm UTC](https://discuss.elastic.co/t/kibana-filter/57532/5 "2016-08-09T20:59:42Z")

</div>

Thanks Brad!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/kibana-filter/57532/6 "2017-07-06T13:41:30Z")

</div>


