# Lower/Upper case search

**URL:** <https://discuss.elastic.co/t/lower-upper-case-search/113322>\
**Category:** Kibana\
**Created:** [December 27, 2017, 2:21pm UTC](https://discuss.elastic.co/t/lower-upper-case-search/113322 "2017-12-27T14:21:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 27, 2017, 2:21pm UTC](https://discuss.elastic.co/t/lower-upper-case-search/113322/1 "2017-12-27T14:21:47Z")

</div>

In a kibana dashboard I need to query a field for upper or lowercase. The field is a scriptblock from powershell so it has to be a string(text), I need to be able to search for different words inside it.

After reading a ton of stuff, I guess I have a couple options -

1. Normalize the field, but all the examples use keywords so I m not sure if this is possible.  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/normalizer.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/normalizer.html)

2. Add another field, copy the data and then use the lowercase processor  
[https://www.elastic.co/guide/en/elasticsearch/reference/master/lowercase-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/lowercase-processor.html)

I want to be able to do a search like this -  
"minimum\_should\_match": 1,  
"should": [  
{  
"wildcard": {  
"powershell.scriptblock.text": "_Execution_Policy\*"  
}

Thanks!

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [December 27, 2017, 5:53pm UTC](https://discuss.elastic.co/t/lower-upper-case-search/113322/2 "2017-12-27T17:53:02Z")

</div>

Are you saying you want searches to be case sensitive? You can do wildcard queries in kibana if you want the not analyzed part of it,  
`{"wildcard":{"powershell.scriptblock.text":"ExecutionPolicy*"}}`

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 27, 2017, 5:58pm UTC](https://discuss.elastic.co/t/lower-upper-case-search/113322/3 "2017-12-27T17:58:14Z")

</div>

Hey Jon!

Case insensitive, actually -

Execution Policy or execution policy.

Currently, when I search with a wildcard it won't find it without case match.

This -  
`{"wildcard":{"powershell.scriptblock.text":"*Execution*Policy*"}}`  
only finds this  
Get Execution-Policy

not this ...

get execution-policy

but I need it to find both.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [December 27, 2017, 9:00pm UTC](https://discuss.elastic.co/t/lower-upper-case-search/113322/4 "2017-12-27T21:00:48Z")

</div>

Does using the default query string query work? It should run both the query and documents through the same analyzer, and will lowercase it by default

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/b/1bed185af639a44e9af3ddbd5d10598a8d97dff8.png)

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 27, 2017, 11:59pm UTC](https://discuss.elastic.co/t/lower-upper-case-search/113322/5 "2017-12-27T23:59:40Z")

</div>

I remember reading that but it doesn't seem to work. (modified to look in multiple fields)

Alright, if I do the search directly from the dashboards query it seems to work -

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/2/4269ea4b14e2c9336ae3b2665bac8930cc0a94d9.png)

if I do a DSL query with multiple fields case seems to matter  
this only gets me lowercase not the upper

```
{
  "query": {
    "bool": {
      "should": [
        { "wildcard": { "CommandLine": "*execution*" }},
        { "wildcard": { "powershell.*": "*execution*" }}
      ]
    }
  }
}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d014535a8b8ea82984a4c80b810bb4525852a3eb.png)

I appreciate your patience!

---

<div class="post-metadata">

**Author:** ![mathurin68](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Post date:** [December 29, 2017, 10:52pm UTC](https://discuss.elastic.co/t/lower-upper-case-search/113322/6 "2017-12-29T22:52:14Z")

</div>

Alright got it to work just by mutating the field to lowercase -  
mutate {  
lowercase =\> "[powershell][scriptblock][text]"  
}

... before production might be better to copy the data to a new field and lowercase that field just so we have the original.

I appreciate the help @jbudz! You guys always seem to point me in the right direction.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2018, 10:52pm UTC](https://discuss.elastic.co/t/lower-upper-case-search/113322/7 "2018-01-26T22:52:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
