# Query does not return any information -- Problem with Kibana Query Language

**URL:** <https://discuss.elastic.co/t/query-does-not-return-any-information-problem-with-kibana-query-language/239476>\
**Category:** Kibana\
**Created:** [July 1, 2020, 11:49am UTC](https://discuss.elastic.co/t/query-does-not-return-any-information-problem-with-kibana-query-language/239476 "2020-07-01T11:49:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cleared\_blue\_sky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cleared_blue_sky/32/49699_2.png) [@cleared\_blue\_sky](https://discuss.elastic.co/u/cleared_blue_sky)\
**Post date:** [July 1, 2020, 11:49am UTC](https://discuss.elastic.co/t/query-does-not-return-any-information-problem-with-kibana-query-language/239476/1 "2020-07-01T11:49:41Z")

</div>

Hi all,

I'm struggling with KQL recently. I have tried so many different styles of queries but I cannot, for some reason, get this query to match logs that do exist.

I am trying to match all logs that contain the word 'apache'. However, when trying all my queries no results are returned.

Does anyone know of a query that would match the word apache when it is in this style:  
 ![Log Example](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5abcb90d55458505c57b23875b1daec7b16046b0.png)

One of the queries I have tried is: ![Apache KQL](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4d60ca91afa3231245564942fb64f3a28c5967fb.png)

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 1, 2020, 2:43pm UTC](https://discuss.elastic.co/t/query-does-not-return-any-information-problem-with-kibana-query-language/239476/2 "2020-07-01T14:43:08Z")

</div>

hmm, thats pretty strange : Few questions:

- What version of Kibana are you using?
- Can you click the `Options` button in the query bar and tell me if you have KQL enabled? Depending on the version you're using it might just be called "Enhanced query features" or something like that.
- Do you have a `keyword` version of this field? If so you may try querying on that. My best guess is that there's something odd happening with the parsing or analysis of the query, and using the `keyword` version may avoid that complication. For example: `application.api.responseText.keyword: *eligible\”\:true*`

any helpful logs?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![cleared\_blue\_sky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cleared_blue_sky/32/49699_2.png) [@cleared\_blue\_sky](https://discuss.elastic.co/u/cleared_blue_sky)\
**Post date:** [July 1, 2020, 3:08pm UTC](https://discuss.elastic.co/t/query-does-not-return-any-information-problem-with-kibana-query-language/239476/3 "2020-07-01T15:08:28Z")

</div>

I have been using Kibana 7.7 (issue existed here) and recently migrated to 7.8.

KQL is enabled and using the keyword version of the field makes no change to the result of the search. (message.keyword: apache or message.keyword: \*apache)

No logs available. Running this query in Lucene: message : /.\*apache.\*/ does return results of the word apache.

I believe the issue is that when using KQL and running the search, message: apache, it is looking for the word apache, separated by spaces. It does not exist in this format. My reasoning for this is because it does find the existence of the entire phrase 'org.apache.solr.core.SolrCore.Request' when searched for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2020, 3:08pm UTC](https://discuss.elastic.co/t/query-does-not-return-any-information-problem-with-kibana-query-language/239476/4 "2020-07-29T15:08:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
