# Kibana Search for greater than or Less than values in string type Field

**URL:** <https://discuss.elastic.co/t/kibana-search-for-greater-than-or-less-than-values-in-string-type-field/168339>\
**Category:** Kibana\
**Created:** [February 14, 2019, 6:22am UTC](https://discuss.elastic.co/t/kibana-search-for-greater-than-or-less-than-values-in-string-type-field/168339 "2019-02-14T06:22:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Suhas\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suhas_k/32/31525_2.png) [@Suhas\_K](https://discuss.elastic.co/u/Suhas_K)\
**Post date:** [February 14, 2019, 6:22am UTC](https://discuss.elastic.co/t/kibana-search-for-greater-than-or-less-than-values-in-string-type-field/168339/1 "2019-02-14T06:22:20Z")

</div>

Hi,

I have a document which has information related to Methodlogger.

My log line looks like this

```auto
[TIMESTAMP] [LOG_TYPE] [MESSAGE]

```

Timestamp, Log\_type, Message are different fields in a single document .

The message field contains information as

```auto
getMethodtime:-234 ms

```

Is it possible to make a search based time greater than 1000ms as the Message filed type is string.

Regards 🐅

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [February 14, 2019, 7:06pm UTC](https://discuss.elastic.co/t/kibana-search-for-greater-than-or-less-than-values-in-string-type-field/168339/2 "2019-02-14T19:06:22Z")

</div>

It's possible, but not in an efficient way. We could parse this field out with a painless script and then search over it as a number. Scripted fields can be added from the Index management page. Would that work for you?

A more efficient way would be to pre-process with [ingest-node](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html) so we can move it to a different field.

---

<div class="post-metadata">

**Author:** ![Suhas\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suhas_k/32/31525_2.png) [@Suhas\_K](https://discuss.elastic.co/u/Suhas_K)\
**Post date:** [February 15, 2019, 6:37am UTC](https://discuss.elastic.co/t/kibana-search-for-greater-than-or-less-than-values-in-string-type-field/168339/3 "2019-02-15T06:37:34Z")

</div>

Hey @jbudz Thanks for your reply.

Probably i was looking for some option.

I'm using painless scripting to make new fields. If i'm modifying my fields or creating new.  
**Will that effect my search time ?**

---

<div class="post-metadata">

**Author:** ![stiltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stiltz/32/39714_2.png) [@stiltz](https://discuss.elastic.co/u/stiltz)\
**Post date:** [February 16, 2019, 2:33am UTC](https://discuss.elastic.co/t/kibana-search-for-greater-than-or-less-than-values-in-string-type-field/168339/4 "2019-02-16T02:33:27Z")

</div>

A potentially more efficient way would be to update your ingest pipeline to also put the just the value in a field like **getMethodtime.ms**. Make sure you set the field type to the proper numeric datatype (integer probably) and then you would have a key value pair of **getMethodtime.ms: -234**. With that you could do a range query as described here: [https://www.elastic.co/guide/en/beats/packetbeat/current/kibana-queries-filters.html](https://www.elastic.co/guide/en/beats/packetbeat/current/kibana-queries-filters.html)

---

<div class="post-metadata">

**Author:** ![Suhas\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suhas_k/32/31525_2.png) [@Suhas\_K](https://discuss.elastic.co/u/Suhas_K)\
**Post date:** [February 16, 2019, 3:15pm UTC](https://discuss.elastic.co/t/kibana-search-for-greater-than-or-less-than-values-in-string-type-field/168339/5 "2019-02-16T15:15:02Z")

</div>

Hey @stiltz I got your point, @jbudz has suggested the same thing to make changes in my injest node. My concern starts here.

The data flow with my Elasticsearch looks like this.

```auto
Filebeat sends data to Logstash, Logstash to Elasticsearch and my 
visualisations are in Kibana. 

```

I'm looking forward to make changes with ingest-node, will that effect my existing gork filter?

Still in confusion regarding making changes in grok filter.

@stiltz you have mentioned that I'll need to take care about the datatype.

```auto
Make sure you set the field type to the proper numeric datatype
(integer probably) and then you would have a key value pair 
of getMethodtime.ms: -234

```

can you help me on this. How do I set the datatype ?

Thank you guys for your response.  
Regards 🐅

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [February 20, 2019, 1:21am UTC](https://discuss.elastic.co/t/kibana-search-for-greater-than-or-less-than-values-in-string-type-field/168339/6 "2019-02-20T01:21:12Z")

</div>

painless scripts: yep, it'll be crunched at runtime so it will include a fixed overheard \* the number of results. in practice i'm not sure the magnitude, it may not be that much.

grok: you got it, a grok filter to pull that number out of a field. The data type would be set independently, depending on how you manage types in elasticsearch.

Your logstash output to elasticsearch can be assigned a template, or you can set the type directly on your index for example.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2019, 1:21am UTC](https://discuss.elastic.co/t/kibana-search-for-greater-than-or-less-than-values-in-string-type-field/168339/7 "2019-03-20T01:21:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
