# KQL to elastic query string

**URL:** <https://discuss.elastic.co/t/kql-to-elastic-query-string/312216>\
**Category:** Kibana\
**Tags:** language-clients\
**Created:** [August 16, 2022, 7:30pm UTC](https://discuss.elastic.co/t/kql-to-elastic-query-string/312216 "2022-08-16T19:30:59Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Drpkton](https://avatars.discourse-cdn.com/v4/letter/d/f4b2a3/32.png) [@Drpkton](https://discuss.elastic.co/u/Drpkton)\
**Post date:** [August 16, 2022, 7:30pm UTC](https://discuss.elastic.co/t/kql-to-elastic-query-string/312216/1 "2022-08-16T19:30:59Z")

</div>

When I perform a Kibana Query, ie,  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c8c19771ff96a5f6cf6bd5056726b82106183808.png)

I know it is converted to a json blob which represents a valid elasticsearch json query, ie,

```auto
{
    "version": true,
    "size": 500,
    "sort":
    [
        {
            "@timestamp":
            {
                "order": "desc",
                "unmapped_type": "boolean"
            }
        }
    ],
    "aggs":
    {
        "2":
        {
            "date_histogram":
            {
                "field": "@timestamp",
                "fixed_interval": "30s",
                "time_zone": "America/Chicago",
                "min_doc_count": 1
            }
        }
    },
    "stored_fields":
    [
        "*"
    ],
    "script_fields": {},
    "docvalue_fields":
    [
        {
            "field": "@timestamp",
            "format": "date_time"
        },
        {
            "field": "event.created",
            "format": "date_time"
        }
    ],
    "_source":
    {
        "excludes": []
    },
    "query":
    {
        "bool":
        {
            "must": [],
            "filter":
            [
                {
                    "bool":
                    {
                        "filter":
                        [
                            {
                                "bool":
                                {
                                    "should":
                                    [
                                        {
                                            "match":
                                            {
                                                "event.id": 5
                                            }
                                        }
                                    ],
                                    "minimum_should_match": 1
                                }
                            },
                            {
                                "bool":
                                {
                                    "should":
                                    [
                                        {
                                            "match":
                                            {
                                                "user": "root"
                                            }
                                        }
                                    ],
                                    "minimum_should_match": 1
                                }
                            }
                        ]
                    }
                },
                {
                    "range":
                    {
                        "@timestamp":
                        {
                            "gte": "2022-08-16T19:12:28.172Z",
                            "lte": "2022-08-16T19:27:28.172Z",
                            "format": "strict_date_optional_time"
                        }
                    }
                }
            ],
            "should": [],
            "must_not": []
        }
    },
    "highlight":
    {
        "pre_tags":
        [
            "@kibana-highlighted-field@"
        ],
        "post_tags":
        [
            "@/kibana-highlighted-field@"
        ],
        "fields":
        {
            "*": {}
        },
        "fragment_size": 2147483647
    }
}

```

I use the Elasticsearch python API to send Elasticsearch queries, however, I would like to send a query from python that is initially in the friendly Kibana Query Language (KQL), ie, `python.SendKQLQuery("event.id:5 and user:root")` and it would get converted into the appropriate json blob that elasticsearch expects... can someone help with this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2022, 7:31pm UTC](https://discuss.elastic.co/t/kql-to-elastic-query-string/312216/2 "2022-09-13T19:31:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
