# Query on KQL to get an exact match

**URL:** <https://discuss.elastic.co/t/query-on-kql-to-get-an-exact-match/222131>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [March 4, 2020, 5:18pm UTC](https://discuss.elastic.co/t/query-on-kql-to-get-an-exact-match/222131 "2020-03-04T17:18:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ldomenella](https://avatars.discourse-cdn.com/v4/letter/l/41988e/32.png) [@ldomenella](https://discuss.elastic.co/u/ldomenella)\
**Post date:** [March 4, 2020, 5:18pm UTC](https://discuss.elastic.co/t/query-on-kql-to-get-an-exact-match/222131/1 "2020-03-04T17:18:03Z")

</div>

hi all,  
im running elastic 7.6 and kibana 7.6. Im getting logs from my 2 servers tomcat and i use filebeat to send them directly to elasticseach..  
doing it i added some custom fields: project  
the project field is populated like that (for example):

- myproject-platform-backend
- myproject2-platform-backend
- platform-backend

when i add this on the discovery -\> query:  
fields.project : "platform-backend"

i expect to see only my logs coming from this tomcat here.... but i see also the logs from the other 2...

the : is an exact match from the docs... what am i doing wrong ?

best  
Luca

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [March 4, 2020, 8:53pm UTC](https://discuss.elastic.co/t/query-on-kql-to-get-an-exact-match/222131/2 "2020-03-04T20:53:01Z")

</div>

Is the `project` field mapped as a `text` field? If you want to do exact matches, it's recommended to use a keyword indexed field, then the query should only return the third document.

---

<div class="post-metadata">

**Author:** ![ldomenella](https://avatars.discourse-cdn.com/v4/letter/l/41988e/32.png) [@ldomenella](https://discuss.elastic.co/u/ldomenella)\
**Post date:** [March 5, 2020, 7:57am UTC](https://discuss.elastic.co/t/query-on-kql-to-get-an-exact-match/222131/3 "2020-03-05T07:57:58Z")

</div>

> [@flash1293](#):
>
> keyword indexed field

hi,  
this is mapping i've got:  
"project": {  
"fields": {  
"keyword": {  
"ignore\_above": 256,  
"type": "keyword"  
}  
},  
"type": "text"  
}

looks to be keyword...

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [March 5, 2020, 8:06am UTC](https://discuss.elastic.co/t/query-on-kql-to-get-an-exact-match/222131/4 "2020-03-05T08:06:35Z")

</div>

This means “project” is a text field, but there is a keyword indexed version of the same field called “project.keyword”. Try filtering on the second one, that should work as you expect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2020, 8:07am UTC](https://discuss.elastic.co/t/query-on-kql-to-get-an-exact-match/222131/5 "2020-04-02T08:07:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
