# Query with NOT logic doesn't work in Kibana 6.5

**URL:** <https://discuss.elastic.co/t/query-with-not-logic-doesnt-work-in-kibana-6-5/169717>\
**Category:** Kibana\
**Created:** [February 24, 2019, 11:51am UTC](https://discuss.elastic.co/t/query-with-not-logic-doesnt-work-in-kibana-6-5/169717 "2019-02-24T11:51:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrey\_Tomilin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrey_tomilin/32/77563_2.png) [@Andrey\_Tomilin](https://discuss.elastic.co/u/Andrey_Tomilin)\
**Post date:** [February 24, 2019, 11:51am UTC](https://discuss.elastic.co/t/query-with-not-logic-doesnt-work-in-kibana-6-5/169717/1 "2019-02-24T11:51:15Z")

</div>

When I want filter out some results, I use the '-' before the field name (in Kibana search bar according to this documentation: [https://www.elastic.co/guide/en/elasticsearch/reference/6.7/query-dsl-query-string-query.html#\_boolean\_operators](https://www.elastic.co/guide/en/elasticsearch/reference/6.7/query-dsl-query-string-query.html#_boolean_operators)):  
-cs-ua-device:Spider

This creates the below query, which is obvious wrong:  
...  
"match": {  
"-cs-ua-device": "Spider"  
}  
...

The above works in case I use "Add Filter" UI, and creates this query:  
...  
"must\_not": [  
{ "match\_phrase": { "cs-ua-device.keyword": { "query": "Spider" } } }  
]  
...

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [February 25, 2019, 11:33pm UTC](https://discuss.elastic.co/t/query-with-not-logic-doesnt-work-in-kibana-6-5/169717/2 "2019-02-25T23:33:46Z")

</div>

Have you opted in to the new language features (e.g. autocomplete)? If so, the simplified syntax no longer supports `-` and `+`, you'll just use `not` instead.

---

<div class="post-metadata">

**Author:** ![Andrey\_Tomilin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrey_tomilin/32/77563_2.png) [@Andrey\_Tomilin](https://discuss.elastic.co/u/Andrey_Tomilin)\
**Post date:** [February 26, 2019, 3:26pm UTC](https://discuss.elastic.co/t/query-with-not-logic-doesnt-work-in-kibana-6-5/169717/3 "2019-02-26T15:26:19Z")

</div>

Yep, I turned it on. Looks you are right. So the only thing I would add here is that I would expect this info in relevant documentation. By the way, is there a list of such changes that caused by new autocomplete feature?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [March 1, 2019, 7:36pm UTC](https://discuss.elastic.co/t/query-with-not-logic-doesnt-work-in-kibana-6-5/169717/4 "2019-03-01T19:36:16Z")

</div>

[This doc](https://www.elastic.co/guide/en/kibana/current/kuery-query.html#_new_simplified_syntax) explains the new syntax. We're also working on better error messages that will detect when you're using the outdated syntax and link you to info about what has changed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2019, 7:51pm UTC](https://discuss.elastic.co/t/query-with-not-logic-doesnt-work-in-kibana-6-5/169717/5 "2019-03-29T19:51:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
