# Querying log.file.path returns no results

**URL:** <https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794>\
**Category:** Kibana\
**Created:** [April 10, 2021, 11:50pm UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794 "2021-04-10T23:50:26Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![strshp\_419](https://avatars.discourse-cdn.com/v4/letter/s/43a26b/32.png) [@strshp\_419](https://discuss.elastic.co/u/strshp_419)\
**Post date:** [April 10, 2021, 11:50pm UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/1 "2021-04-10T23:50:26Z")

</div>

_Elasticsearch, Filebeat, and Kibana versions are 7.12.0 on Windows Server 2016_

In Kibana, querying on log.file.path returns no results in certain scenarios.

Example:  
In Kibana, I go to Observability \> Logs and submit a query that successfully returns results. After the results are returned, I select "View details" on a given row and filter on log.file.path. No results are returned.

 ![no-results](https://us1.discourse-cdn.com/elastic/original/3X/4/3/4369adeaa0ba99277838d0280713b7cec1b60e90.png)

When I take the same log file and copy it to C:\Temp (also being crawled by filebeat), I can filter on that log.file.path with no issues.

 ![results](https://us1.discourse-cdn.com/elastic/original/3X/2/8/2878f0445d8a37dba248ddecf65589f13ff0bf32.png)

Does anyone know why filtering/searching on log.file.path doesn't work in the first scenario above but works fine in the second? Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![wayneseymour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayneseymour/32/42945_2.png) [@wayneseymour](https://discuss.elastic.co/u/wayneseymour)\
**Post date:** [April 16, 2021, 12:52am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/2 "2021-04-16T00:52:22Z")

</div>

@strshp_419 you know my first "knee jerk" question is: What is the length in characters of the file path in the first scenario? I'm guessing that in the second scenario, the file path is way shorter, yes?

---

<div class="post-metadata">

**Author:** ![strshp\_419](https://avatars.discourse-cdn.com/v4/letter/s/43a26b/32.png) [@strshp\_419](https://discuss.elastic.co/u/strshp_419)\
**Post date:** [April 16, 2021, 3:44am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/3 "2021-04-16T03:44:32Z")

</div>

Correct! The character length of the first file path is indeed much longer. That length is 103 characters. The second path is only 36 characters long.

I also had the same knee jerk reaction but I couldn't find any indicator that the file path length was an issue.

---

<div class="post-metadata">

**Author:** ![wayneseymour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayneseymour/32/42945_2.png) [@wayneseymour](https://discuss.elastic.co/u/wayneseymour)\
**Post date:** [April 16, 2021, 3:49am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/4 "2021-04-16T03:49:47Z")

</div>

Hrmm, perhaps we can try placing it at a file path of around 80 characters or so? Truly, I'm not sure, but I wonder if there might be a limit within the software, and not just an os limit.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 16, 2021, 5:05am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/5 "2021-04-16T05:05:40Z")

</div>

Wonder if the \U ... Is getting interpreted as unicode?

---

<div class="post-metadata">

**Author:** ![wayneseymour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayneseymour/32/42945_2.png) [@wayneseymour](https://discuss.elastic.co/u/wayneseymour)\
**Post date:** [April 16, 2021, 7:44am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/6 "2021-04-16T07:44:36Z")

</div>

Oh good one @stephenb !

---

<div class="post-metadata">

**Author:** ![strshp\_419](https://avatars.discourse-cdn.com/v4/letter/s/43a26b/32.png) [@strshp\_419](https://discuss.elastic.co/u/strshp_419)\
**Post date:** [April 17, 2021, 4:06am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/7 "2021-04-17T04:06:05Z")

</div>

I think you are on the right path @stephenb but it appears to be \t and not \U.

I can reliably recreate this issue now when using a file path that contains \t. Below are my findings.

I can't filter or search on file path for the following:

- C:\Temp\toast\U6943acbex6074a4a2e3ex\_m.log
- C:\Temp\task\U6943acbex6074a4a2e3ex\_m.log
- C:\Temp\test\U6943acbex6074a4a2e3ex\_m.log

These work fine:

- C:\Temp\coast\U6943acbex6074a4a2e3ex\_m.log
- C:\Temp\kask\U6943acbex6074a4a2e3ex\_m.log
- C:\Temp\best\U6943acbex6074a4a2e3ex\_m.log
- C:\Temp\TyrannosaurusRex\U6943acbex6074a4a2e3ex\_m.log

When I escape the \t like this when searching, results are returned as expected:  
`log.file.path:"C:\Temp\\toast\U6943acbex6074a4a2e3ex_m.log`

I'm really not sure what to do with this info yet but I'm happy I can recreate the issue.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 17, 2021, 4:19am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/8 "2021-04-17T04:19:41Z")

</div>

Good to know....

Wonder if lowercase `\u` would cause issue too

If you try KQL query bar and put the path in single quotes what happens?

`log.file.path : 'C:\Temp\toast\U6943acbex6074a4a2e3ex_m.log'`

---

<div class="post-metadata">

**Author:** ![strshp\_419](https://avatars.discourse-cdn.com/v4/letter/s/43a26b/32.png) [@strshp\_419](https://discuss.elastic.co/u/strshp_419)\
**Post date:** [April 17, 2021, 4:27am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/9 "2021-04-17T04:27:43Z")

</div>

`\u` seems to work fine.

When I search with single quotes, Kibana gets angry...

```auto
Error: Expected AND, OR, end of input but ":" found.
log.file.path : 'C:\Temp\toast\U6943acbex6074a4a2e3ex_m.log'
------------------^
    at Object.fromKueryExpression (http://ht-alpha-tcdsp1:5601/39309/bundles/plugin/data/data.plugin.js:1:386086)
    at http://ht-alpha-tcdsp1:5601/39309/bundles/plugin/infra/infra.chunk.1.js:103:17156
    at Object.useMemo (http://ht-alpha-tcdsp1:5601/39309/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:382:64610)
    at useMemo (http://ht-alpha-tcdsp1:5601/39309/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:353:5228)
    at useLogStream (http://ht-alpha-tcdsp1:5601/39309/bundles/plugin/infra/infra.chunk.1.js:103:17023)
    at Provider (http://ht-alpha-tcdsp1:5601/39309/bundles/plugin/infra/infra.chunk.0.js:3:75009)
    at da (http://ht-alpha-tcdsp1:5601/39309/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:382:59332)
    at $a (http://ht-alpha-tcdsp1:5601/39309/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:382:67554)
    at xs (http://ht-alpha-tcdsp1:5601/39309/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:382:105587)
    at fl (http://ht-alpha-tcdsp1:5601/39309/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:382:90018)

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 17, 2021, 4:29am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/10 "2021-04-17T04:29:53Z")

</div>

Where is that error shown?

How are you submitting that query ... Confused where you are seeing error

Is that in Discover?

---

<div class="post-metadata">

**Author:** ![strshp\_419](https://avatars.discourse-cdn.com/v4/letter/s/43a26b/32.png) [@strshp\_419](https://discuss.elastic.co/u/strshp_419)\
**Post date:** [April 17, 2021, 4:42am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/11 "2021-04-17T04:42:15Z")

</div>

That error is being returned in Observability \> Logs. I just copied/pasted into the search bar like so...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/c/9c60496c5adaac09fdaaa04dd58ec773f8cb2410.png)

And then I get this...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/a/ca8c4478c5ee7e62c8be31071808f23fbaae3b30.png)

Discover also gives me the same...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/32486982493007e7168e9a1e077bf94fe1c7d12a.png)

Although the full message is a little different...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/0/00eea20bf5b51cda37f97cd9fa30b96aaaca52d4.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 17, 2021, 4:43am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/12 "2021-04-17T04:43:39Z")

</div>

Hmmm Here is my test case with 7.11.1

Yeah I was wrong with the Single Quote.... I was not in front of my computer

```
PUT test/
{
  "mappings": {
    "properties": {
      "mypath" : {
        "type": "keyword"
      }
    }
  }
}

POST test/_doc
{
  "mypath" : "C:\\Temp\\toast\\U6943acbex6074a4a2e3ex_m.log"
}

POST test/_doc
{
  "mypath" : "C:\\Temp\\coast\\U6943acbex6074a4a2e3ex_m.log"
}

```

And now without filter

 ![Screen Shot 2021-04-16 at 9.40.20 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77381dce594d489975ae2b2f1d9d0425c37579c7.png)

And now with filter... seems to work

 ![Screen Shot 2021-04-16 at 9.40.11 PM](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c73b8640f2a261f479b5d6f7bb43b07ed69eb63.png)

Now using KQL seems to work...

 ![Screen Shot 2021-04-16 at 9.42.10 PM](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8e47198af2e657fbf94c2f7d543216eb74966fc9.png)

 ![Screen Shot 2021-04-16 at 9.42.21 PM](https://us1.discourse-cdn.com/elastic/original/3X/1/2/127295a5a058d05a6c5bdd087a92614f39d730cb.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 17, 2021, 4:46am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/13 "2021-04-17T04:46:34Z")

</div>

So try in the KQL Bar of the logs stream.

Sorry wrong with the Single Quotes

`log.file.path : "C:\\Temp\\toast\\U6943acbex6074a4a2e3ex_m.log"`

it should do type ahead for you after you type

`log.file.path :`

if you wait it should suggest

 ![Screen Shot 2021-04-16 at 9.49.13 PM](https://us1.discourse-cdn.com/elastic/original/3X/5/9/590462c6e1ad3b3e1df65589defee6f19e31a603.png)

And for your paths it should look something like

 ![Screen Shot 2021-04-16 at 9.49.47 PM](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eed36dbb514e6a20af26ff00db056b915152570d.png)

---

<div class="post-metadata">

**Author:** ![strshp\_419](https://avatars.discourse-cdn.com/v4/letter/s/43a26b/32.png) [@strshp\_419](https://discuss.elastic.co/u/strshp_419)\
**Post date:** [April 17, 2021, 5:11am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/14 "2021-04-17T05:11:51Z")

</div>

Sorry. I'm new here...

I know that the query works fine when I use `\\t` instead of `\t`, but I'm not following how that resolves my issue. Are you saying that I just need to make sure that I replace `\` with `\\` when posting Windows logs?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 17, 2021, 5:15am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/15 "2021-04-17T05:15:39Z")

</div>

You do not need to change the ingested path just the way you search on it.

If that's what you're asking why the filter doesn't work I will have to try I don't have a log source with those types of paths that I can stream but the KQL should work and that's yes the` \\t` is how you will have to search on it.

And as you see the type of head should do that for you.

It is JSON an so the back slashes need to be escaped.

I will need to figure out how to try to get that into the Logs Viewer and see if the filter has a bug ... which perhaps it might

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 17, 2021, 5:19am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/16 "2021-04-17T05:19:24Z")

</div>

I think if you actually look at the source documents you will see it like that

 ![Screen Shot 2021-04-16 at 10.17.58 PM](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cca460caa0776da22af924e9a494171577730381.png)  
 ![Screen Shot 2021-04-16 at 10.18.04 PM](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d200793697447da84ff615cf2d605f11efa8e42.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2021, 5:20am UTC](https://discuss.elastic.co/t/querying-log-file-path-returns-no-results/269794/17 "2021-05-15T05:20:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
