# Kibana Graph KQL not being followed

**URL:** <https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096>\
**Category:** Kibana\
**Tags:** elastic-stack-graph\
**Created:** [July 21, 2020, 8:23pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096 "2020-07-21T20:23:11Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [July 21, 2020, 8:23pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096/1 "2020-07-21T20:23:11Z")

</div>

I'm testing out the Kibana Graph feature and am running into an issue. I would expect the KQL field to limit the search, however, it appears that this doesn't happen. Anyone know why?

Example below, I would not expect this response at all if KQL was being applied:

![kibana_graph_example](https://us1.discourse-cdn.com/elastic/original/3X/b/e/be09ab1461b0d9b1d89ab5674308770407bd97e9.png)

Here is the request that is being sent:

```auto
{
	"query": {
		"bool": {
			"should": [
				{
					"query_string": {
						"fields": [
							"email.subject"
						],
						"query": "*Stock#*"
					}
				}
			],
			"minimum_should_match": 1
		}
	},
	"controls": {
		"use_significance": false,
		"sample_size": 200000,
		"timeout": 50000
	},
	"connections": {
		"vertices": [
			{
				"field": "email.source.email",
				"size": 5,
				"min_doc_count": 1
			},
			{
				"field": "email.subject",
				"size": 5,
				"min_doc_count": 1
			},
			{
				"field": "email.target.email",
				"size": 5,
				"min_doc_count": 1
			}
		]
	},
	"vertices": [
		{
			"field": "email.source.email",
			"size": 5,
			"min_doc_count": 1
		},
		{
			"field": "email.subject",
			"size": 5,
			"min_doc_count": 1
		},
		{
			"field": "email.target.email",
			"size": 5,
			"min_doc_count": 1
		}
	]
}

```

---

<div class="post-metadata">

**Author:** ![cheiligers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheiligers/32/73114_2.png) [@cheiligers](https://discuss.elastic.co/u/cheiligers)\
**Post date:** [July 29, 2020, 8:06pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096/2 "2020-07-29T20:06:54Z")

</div>

@BenB196  
The KQL 'search` is within the query context but you're assuming a filter context. Queries effect the search result score, while filters only answer the 'does it match or not' question.  
Here's a [link](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-filter-context.html#query-context) to the docs.

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [July 29, 2020, 8:47pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096/3 "2020-07-29T20:47:07Z")

</div>

Thanks for the information. Is there a way to filter on the Graph visualization, I wasn't able to find anything obvious on the Graph UI.

---

<div class="post-metadata">

**Author:** ![cheiligers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheiligers/32/73114_2.png) [@cheiligers](https://discuss.elastic.co/u/cheiligers)\
**Post date:** [July 29, 2020, 9:15pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096/4 "2020-07-29T21:15:02Z")

</div>

@BenB196 I'm not a graph expert but I _think_ what you're looking for is a ["blocked term"](https://www.elastic.co/guide/en/kibana/current/graph-getting-started.html#graph-block-terms). The link takes you to a guide on using Graph

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [July 29, 2020, 9:20pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096/5 "2020-07-29T21:20:15Z")

</div>

I looked at that as well, but found it to do the opposite of what I wanted. It will only block a specific term, if I have 1000 terms, but only want to show 1, then I'll need to block 999 terms individually, which I don't think is particularly feasible.

---

<div class="post-metadata">

**Author:** ![cheiligers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheiligers/32/73114_2.png) [@cheiligers](https://discuss.elastic.co/u/cheiligers)\
**Post date:** [July 29, 2020, 9:39pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096/6 "2020-07-29T21:39:07Z")

</div>

@BenB196 from going through the [graph troubleshooting docs](https://www.elastic.co/guide/en/kibana/current/graph-troubleshooting.html#graph-troubleshooting), I think you'll need to reduce your sample size before creating the graph. Quote:

Reducing the `sample_size` . Considering fewer documents can actually be better when the quality of matches is quite variable.

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [July 29, 2020, 10:21pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096/7 "2020-07-29T22:21:23Z")

</div>

Don't think that's the right solution as it would then limit the amount of values that I can get. I guess my original example was kind of bad. A better example would be I want to show all emails with the subject that contain \*Stock#\*, and I don't want to include anything else. I've found that if I limit sample\_size it will initially return accurate values, but won't return all possible values, and if I expand the sample size, it will stop show relevant info, while not showing all possible values. Maybe this use case isn't really supported by Graph currently? Do you think vega would provide a better solution for this use case: [https://vega.github.io/vega/examples/force-directed-layout/](https://vega.github.io/vega/examples/force-directed-layout/)?

---

<div class="post-metadata">

**Author:** ![cheiligers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheiligers/32/73114_2.png) [@cheiligers](https://discuss.elastic.co/u/cheiligers)\
**Post date:** [July 29, 2020, 10:25pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096/8 "2020-07-29T22:25:00Z")

</div>

@BenB196 I don't know Vega at all but I hear it can perform what I call 'magic'! There's cetainly a lot of documentation available and the examples are great 🙂  
Good luck!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2020, 10:25pm UTC](https://discuss.elastic.co/t/kibana-graph-kql-not-being-followed/242096/9 "2020-08-26T22:25:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
