# KQL Inline Comments?

**URL:** <https://discuss.elastic.co/t/kql-inline-comments/362977>\
**Category:** Kibana\
**Tags:** discover\
**Created:** [July 11, 2024, 6:51pm UTC](https://discuss.elastic.co/t/kql-inline-comments/362977 "2024-07-11T18:51:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jscheitel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jscheitel/32/133235_2.png) [@jscheitel](https://discuss.elastic.co/u/jscheitel)\
**Post date:** [July 11, 2024, 6:51pm UTC](https://discuss.elastic.co/t/kql-inline-comments/362977/1 "2024-07-11T18:51:59Z")

</div>

Does anyone know any tricks to let you have an inline comment in search dialog of Discover? For instance for a "Firewall Drops" saved search I want to have something like this:

`panw.panos.sub_type : ("drop" or "deny") /* and source.ip : "0.0.0.0" */`

So that they can then set the source IP easily to narrow the search. We are trying to roll Kibana out to a wider audience in IT.

I added the instruction to the comments for the saved search, but when loading a saved search the user never sees that note?

Any ideas or comments appreciated, thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 12, 2024, 5:44am UTC](https://discuss.elastic.co/t/kql-inline-comments/362977/2 "2024-07-12T05:44:42Z")

</div>

Hi @jscheitel  
What's version are you on...

ESQL allows comments in lnline ... Not to mention it's much more powerful than KQL

> **[ES|QL syntax reference | Elasticsearch Guide \[8.14\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/esql-syntax.html#esql-comments)**

---

<div class="post-metadata">

**Author:** ![jscheitel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jscheitel/32/133235_2.png) [@jscheitel](https://discuss.elastic.co/u/jscheitel)\
**Post date:** [July 12, 2024, 12:29pm UTC](https://discuss.elastic.co/t/kql-inline-comments/362977/3 "2024-07-12T12:29:40Z")

</div>

We are on 8.12 currently. Upgrade to current planned for August.  
Also... adding a picture for context:

 ![Discover_saved_search_comments2](https://us1.discourse-cdn.com/elastic/original/3X/d/a/daf3b9c177e1b202d1b9209664c25b51133c9fae.png)

---

<div class="post-metadata">

**Author:** ![jscheitel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jscheitel/32/133235_2.png) [@jscheitel](https://discuss.elastic.co/u/jscheitel)\
**Post date:** [July 12, 2024, 12:50pm UTC](https://discuss.elastic.co/t/kql-inline-comments/362977/4 "2024-07-12T12:50:23Z")

</div>

@stephenb , thank you - you are a rock star! that is perfect!

 ![Discover_saved_search_esql](https://us1.discourse-cdn.com/elastic/original/3X/3/8/3807e95266cfbb53189da63159e97be718c44790.png)

The only problem I am having is that when it is in ESQL mode I had to rebuild the field selection list, which is fine... but... it will not let me have the @timestamp as the first field. I can have it in any other position but when it moves to the first column it gets removed from the selected fields list. Not sure if that has something to do with the feature being in preview for 8.12.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 12, 2024, 2:17pm UTC](https://discuss.elastic.co/t/kql-inline-comments/362977/5 "2024-07-12T14:17:44Z")

</div>

ES|QL is GA in 8.14 with a LOT of bug fixes and enhancements. 🙂  
Time to upgrade...
