# "NOT Empty" KQL query returns records with empty fields

**URL:** <https://discuss.elastic.co/t/not-empty-kql-query-returns-records-with-empty-fields/320193>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [November 30, 2022, 8:40pm UTC](https://discuss.elastic.co/t/not-empty-kql-query-returns-records-with-empty-fields/320193 "2022-11-30T20:40:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wpm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wpm/32/110146_2.png) [@wpm](https://discuss.elastic.co/u/wpm)\
**Post date:** [November 30, 2022, 8:40pm UTC](https://discuss.elastic.co/t/not-empty-kql-query-returns-records-with-empty-fields/320193/1 "2022-11-30T20:40:57Z")

</div>

My records have a text field called "My Field". For some records these are the empty string and for others they have a value. I want to find all the ones for which "My Field" is not the empty string. In the KQL query bar of Discover I create a query that says "NOT My Field: (empty)". This returns all the records in the index. I get the same result if I temporarily disable this query clause. If instead I create a query of the form "My Field: some value" I do get records returned.

(The data is proprietary, so I can't post an example.)

I must not be understanding something about KQL. What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [December 7, 2022, 10:02am UTC](https://discuss.elastic.co/t/not-empty-kql-query-returns-records-with-empty-fields/320193/2 "2022-12-07T10:02:24Z")

</div>

Hi @wpm,

Try querying a field with "keyword" field type instead if it's present in your index mapping.  
For example: `not my_field.keyword: ""`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2023, 8:57am UTC](https://discuss.elastic.co/t/not-empty-kql-query-returns-records-with-empty-fields/320193/3 "2023-01-04T08:57:32Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2023, 8:57am UTC](https://discuss.elastic.co/t/not-empty-kql-query-returns-records-with-empty-fields/320193/4 "2023-02-01T08:57:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
