# Kibana's filter (partial matching)

**URL:** <https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494>\
**Category:** Kibana\
**Created:** [August 27, 2017, 11:38pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494 "2017-08-27T23:38:15Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [August 27, 2017, 11:38pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/1 "2017-08-27T23:38:15Z")

</div>

I'm running elasticsearch 5.5.1 and while trying to follow [Partial Matching | Elasticsearch: The Definitive Guide [2.x] | Elastic](https://www.elastic.co/guide/en/elasticsearch/guide/2.x/partial-matching.html), I was not able to do partial matching through Kibana's filter(

My filter:

```
{
  "query": {
    "match": {
      "bin": {
        "query": "414720*",
        "type": "phrase"
      }
    }
  }
}

```

Please advise.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [August 28, 2017, 8:45pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/2 "2017-08-28T20:45:17Z")

</div>

> [@alexus](#):
>
> partial matching through Kibana’s filter

Yes, you could possibly use the kibana filters to achieve this. Just use the part of the word you want to match?

Thanks  
Rashmi

 ![21 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7d79b4152546795af7f74968a9f54a477c9877ca.png)

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 8, 2017, 8:28pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/3 "2017-09-08T20:28:45Z")

</div>

@rashmi if I use parts of my query, I do _NOT_ get any match(

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [September 11, 2017, 4:31pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/4 "2017-09-11T16:31:43Z")

</div>

I don't understand your q. Can you plz rephrase it ?

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 11, 2017, 5:00pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/5 "2017-09-11T17:00:45Z")

</div>

@rashmi

I have field that contains 6-7 digits:

- if I use 6 digit inside of filter - I get no match
- if I use 6 digit in search field (above filter) - I get partial match.

Why do I not get partial match using filter? How can I do partial match using filter instead of search?

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [September 11, 2017, 5:53pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/6 "2017-09-11T17:53:14Z")

</div>

Here's one way to make it work. I'm not sure it's the only way or even the best way.

If you create a filter, and then edit it;

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/b/0ba64247193a8c934bdcc1a334576ac996bd01b7.png)

You can change your query to be like this;

```auto
{
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "query": "bin:414720*",
            "analyze_wildcard": true
          }
        }
      ]
    }
  }
}

```

It seems like there could be an option like "contains" in the Add filter dialog to do this. I'll check and see if there's any enhancement request for something like that.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [September 11, 2017, 5:56pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/7 "2017-09-11T17:56:39Z")

</div>

I should mention how I got the query to do this very easily. I just used the query bar to search, and then clicked the little ^ under the histogram and looked at the request. Then copied that bit of the query. Then created a filter and edited it.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/2/a29221ec2c059b9a99c151d9b5624a85ecc4b1a6.png)

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [September 11, 2017, 7:32pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/8 "2017-09-11T19:32:31Z")

</div>

I would use a [wildcard query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-wildcard-query.html) instead of a query string query. If it's a number field a range query should work also.

The query in the original post does not work because the match query does not support wildcards.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [September 11, 2017, 7:45pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/9 "2017-09-11T19:45:55Z")

</div>

I raised an enhancement request for the same here: [https://github.com/elastic/kibana/issues/13943](https://github.com/elastic/kibana/issues/13943)

you can subscribe to the issue above to get more updates.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 11, 2017, 8:27pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/10 "2017-09-11T20:27:56Z")

</div>

unfortunately there is no "contain", there are only followings: "is", "is not", "is one of", "is not one of", "exists", "does not exists".

I'm not quite sure how you create query (manually?), but I did noticed you now have _query\_string_, can you please explain step by step how to get there?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [September 11, 2017, 8:50pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/11 "2017-09-11T20:50:15Z")

</div>

@alexus When you've got the filter editor open, click the "Edit Query DSL" link in the top right corner of the editor. Here you can type in raw elasticsearch query DSL.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2017, 8:50pm UTC](https://discuss.elastic.co/t/kibanas-filter-partial-matching/98494/12 "2017-10-09T20:50:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
