# Kibana query on data from Filebeat not returning anything

**URL:** <https://discuss.elastic.co/t/kibana-query-on-data-from-filebeat-not-returning-anything/365286>\
**Category:** Kibana\
**Created:** [August 21, 2024, 1:11pm UTC](https://discuss.elastic.co/t/kibana-query-on-data-from-filebeat-not-returning-anything/365286 "2024-08-21T13:11:15Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![kernelpanic](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Post date:** [August 21, 2024, 1:11pm UTC](https://discuss.elastic.co/t/kibana-query-on-data-from-filebeat-not-returning-anything/365286/1 "2024-08-21T13:11:15Z")

</div>

Elasticsearch version: 7.17.22

Kibana version: 7.17.22

Filebeat version: 7.17.7

Hello all, we're using Filebeat to ingest the Microsoft System Center Endpoint protection logs so we can monitor and alert on malware / virus detections etc.

An example is shown below if I run **message:** \* in Kibana:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f3783e3334a8750903a7087693b3dea600f2628.png)

However if I try to query for an individual word e.g. **message:_tanium_** then nothing is returned - the only time I can get anything back from the **message:** field is if I do a wildcard query or search for an individual letter e.g. **message:t**

Can anyone help?

Thanks.
