# Match an empty field in kibana

**URL:** <https://discuss.elastic.co/t/match-an-empty-field-in-kibana/178002>\
**Category:** Kibana\
**Created:** [April 23, 2019, 9:59am UTC](https://discuss.elastic.co/t/match-an-empty-field-in-kibana/178002 "2019-04-23T09:59:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![desai\_sheetal28](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@desai\_sheetal28](https://discuss.elastic.co/u/desai_sheetal28)\
**Post date:** [April 23, 2019, 9:59am UTC](https://discuss.elastic.co/t/match-an-empty-field-in-kibana/178002/1 "2019-04-23T09:59:37Z")

</div>

Hi I am trying to query kibana for empty value i.e. in the scenario where the field is present but the value sent is empty.  
I used the operator "is" and matched it with different values such as ''/'\*' but that returns 0 results.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [April 23, 2019, 10:49pm UTC](https://discuss.elastic.co/t/match-an-empty-field-in-kibana/178002/2 "2019-04-23T22:49:48Z")

</div>

For a field called "title":

In lucene: `-_exists_:title`

In KQL `not title:*`

---

<div class="post-metadata">

**Author:** ![desai\_sheetal28](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@desai\_sheetal28](https://discuss.elastic.co/u/desai_sheetal28)\
**Post date:** [April 24, 2019, 12:33pm UTC](https://discuss.elastic.co/t/match-an-empty-field-in-kibana/178002/3 "2019-04-24T12:33:25Z")

</div>

Hi Matt, thank you for your answer. I am trying to create dashboard in kibana and I want list of events where field was sent with an empty value.  
So the options that I have is something as below  
_Filter_ by "field name" + _Operator_ = 'is','is not','is one of','is not one of','exist','does not exist' + _Value_ =  
The issue that I have is I don't have value to / or not to match.  
I am not using "Query DSL".

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [April 24, 2019, 3:18pm UTC](https://discuss.elastic.co/t/match-an-empty-field-in-kibana/178002/4 "2019-04-24T15:18:03Z")

</div>

Ah I see, you're trying to create a filter not a query. What do you mean exactly when you say the field was sent with an empty value? Does the field not exist at all in the source doc? Does it have an empty string? A null value? `does not exist` should work if the field does not exist in the doc at all.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2019, 3:18pm UTC](https://discuss.elastic.co/t/match-an-empty-field-in-kibana/178002/5 "2019-05-22T15:18:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
