# Search for % character

**URL:** <https://discuss.elastic.co/t/search-for-character/99784>\
**Category:** Kibana\
**Created:** [September 8, 2017, 4:38am UTC](https://discuss.elastic.co/t/search-for-character/99784 "2017-09-08T04:38:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nnet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nnet/32/25982_2.png) [@nnet](https://discuss.elastic.co/u/nnet)\
**Post date:** [September 8, 2017, 4:38am UTC](https://discuss.elastic.co/t/search-for-character/99784/1 "2017-09-08T04:38:32Z")

</div>

ES 2.4.6, Kibana 4.6.6.

Trying to search for strings containing % character, example:

Sep 7 23:22:56 kritek-sw-001 1567: 17w0d: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/1, changed state to down

I was initially trying to regex %_-[0-4]-_: but no results get returned, so tried searches with just % and still get no results.

How can I search for % ?

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [September 9, 2017, 6:00am UTC](https://discuss.elastic.co/t/search-for-character/99784/2 "2017-09-09T06:00:38Z")

</div>

It's possible you need to escape the %, based on how you've indexed your data. I assume the issue is caused by how your data is indexed in elasticsearch. Checkout [1] for similar question

1: [Indexing and searching on special characters?](https://discuss.elastic.co/t/indexing-and-searching-on-special-characters/9312)

---

<div class="post-metadata">

**Author:** ![nnet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nnet/32/25982_2.png) [@nnet](https://discuss.elastic.co/u/nnet)\
**Post date:** [September 9, 2017, 3:00pm UTC](https://discuss.elastic.co/t/search-for-character/99784/3 "2017-09-09T15:00:23Z")

</div>

Spencer, thanks for responding. I read the link but I don't understand how thats supposed to help me. I see the % character when I search for messages by hostname, ie; syslog\_hostname:sw-001

Sep 8 23:26:34 sw-001 1577: 17w1d: %SYS-5-CONFIG\_I: Configured from console by user on vty0 (192.168.15.7)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2017, 3:00pm UTC](https://discuss.elastic.co/t/search-for-character/99784/4 "2017-10-07T15:00:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
