# KQL search problem

**URL:** <https://discuss.elastic.co/t/kql-search-problem/229451>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [April 23, 2020, 11:21am UTC](https://discuss.elastic.co/t/kql-search-problem/229451 "2020-04-23T11:21:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![papmik](https://avatars.discourse-cdn.com/v4/letter/p/e495f1/32.png) [@papmik](https://discuss.elastic.co/u/papmik)\
**Post date:** [April 23, 2020, 11:21am UTC](https://discuss.elastic.co/t/kql-search-problem/229451/1 "2020-04-23T11:21:05Z")

</div>

I want to filter it in the logs : message:_cod=49_ and the result: "No results match your search criteria". I try it like this message:_cod?49_ the result is same. I try it like this: message:_cod=49_ the result is Expected AND, OR, end of input, whitespace but "" found. message:_cod=49_ -----------------^.  
How could i find the "cod=49" string in the "messge" field? (KIBANA v 7.6.1)  
Thank you in advance for your help!

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 23, 2020, 12:05pm UTC](https://discuss.elastic.co/t/kql-search-problem/229451/2 "2020-04-23T12:05:04Z")

</div>

Is `cod=49` the only thing in the message field or is it just a substring? If it's just a substring and the field is of type `keyword`, then you have to match via `message:*cod=49*`.

It's recommended though to ingest the field as `text` in this case, then `message:cod=49` should work and it's much more performant.

---

<div class="post-metadata">

**Author:** ![papmik](https://avatars.discourse-cdn.com/v4/letter/p/e495f1/32.png) [@papmik](https://discuss.elastic.co/u/papmik)\
**Post date:** [April 23, 2020, 4:01pm UTC](https://discuss.elastic.co/t/kql-search-problem/229451/3 "2020-04-23T16:01:54Z")

</div>

Thank you very much for your help, but it still does not work.

Summary:

The `message` field contains a long string, including "delimiters" like `|` , key-value pairs like `cod=491234567` etc.

In the index patterns, we see that the field is of type `string` not `text`. Or is that the same? (It is marked as searchable.)

**I need to find records/entries whose `message` field contains `cod=49` as a substring.**  
What query do I need to use for this?

These are the things I tried, with variable results, but never what I wanted:  
Query: `message:cod=49`  
Result: Finds entries with substring `49` OR `cod`, but not (only) `cod=49`

Query: `message:"cod=49"`  
Result: No results match your search criteria

Query: `message:"cod\=49"`  
Result: No results match your search criteria

Query: `message:cod\=49`  
Result: Expected AND, OR, end of input, whitespace but "" found. message:cod=49 ---------------^

Query: `message:"*cod=49*"`  
Result: No results match your search criteria

Query: `message:*cod=49*`  
Result: No results match your search criteria

Query: `message:"*cod\=49*"`  
Result: No results match your search criteria

Query: `message:*cod\=49*`  
Result: Expected AND, OR, end of input, whitespace but "" found. message:_cod=49_ ----------------^

It worked differently in the previous version of KIBANA (Version: 6.2.4.)  
There I query with`message:*cod=49*` and the result was all logs that contained `xxxx, cod=49xxxx,` as a substring in the message field.

---

<div class="post-metadata">

**Author:** ![papmik](https://avatars.discourse-cdn.com/v4/letter/p/e495f1/32.png) [@papmik](https://discuss.elastic.co/u/papmik)\
**Post date:** [May 4, 2020, 4:55am UTC](https://discuss.elastic.co/t/kql-search-problem/229451/4 "2020-05-04T04:55:11Z")

</div>

any solutions?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2020, 4:55am UTC](https://discuss.elastic.co/t/kql-search-problem/229451/5 "2020-06-01T04:55:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
