# Query for an empty string?

**URL:** <https://discuss.elastic.co/t/query-for-an-empty-string/83070>\
**Category:** Kibana\
**Created:** [April 20, 2017, 2:16pm UTC](https://discuss.elastic.co/t/query-for-an-empty-string/83070 "2017-04-20T14:16:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rthompson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rthompson/32/17539_2.png) [@rthompson](https://discuss.elastic.co/u/rthompson)\
**Post date:** [April 20, 2017, 2:16pm UTC](https://discuss.elastic.co/t/query-for-an-empty-string/83070/1 "2017-04-20T14:16:10Z")

</div>

I am trying to query for an empty string and am having little luck. I have a set of logs with the field 'CharacterId', some of which have a value and others that do not. [[http://i.imgur.com/xMmxKFZ.png](http://i.imgur.com/xMmxKFZ.png)]Here is an example.([http://i.imgur.com/xMmxKFZ.png](http://i.imgur.com/xMmxKFZ.png)). Basically I need to differentiate between the two for visualization purposes but am unable to filter them in this manner. I have tried:

- `CharacterId:""`
- `CharacterId: " "`
- `-CharacterId:""`
- `"CharacterId:"""`
- `CharacterId:[]`
- `CharacterId:`
- `_exists_:CharacterId`
- `!(_exists_:CharacterId)`

Any tips on how to filter by this field being empty or not?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [April 20, 2017, 6:24pm UTC](https://discuss.elastic.co/t/query-for-an-empty-string/83070/2 "2017-04-20T18:24:54Z")

</div>

Hi @rthompson,

in order to be able to perform that kind of query, the field has to be indexed as the `keyword` type. Otherwise it would be analyzed by Elasticsearch's full-text analyzer, which tokenizes the string, and therefore makes queries for whitespace impossible. For fields of type `keyword` the query `field:""` should match all documents with an empty string in that field.

---

<div class="post-metadata">

**Author:** ![rthompson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rthompson/32/17539_2.png) [@rthompson](https://discuss.elastic.co/u/rthompson)\
**Post date:** [April 20, 2017, 6:38pm UTC](https://discuss.elastic.co/t/query-for-an-empty-string/83070/3 "2017-04-20T18:38:40Z")

</div>

Thanks @weltenwort! Querying by keyword allows me to filter them appropriately:

- `CharacterId.keyword:""`
- `!(CharacterId.keyword:"")`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 6:52pm UTC](https://discuss.elastic.co/t/query-for-an-empty-string/83070/4 "2017-05-18T18:52:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
