# Search query containing an equal character

**URL:** https://discuss.elastic.co/t/search-query-containing-an-equal-character/16385
**Category:** Elasticsearch
**Created:** [March 14, 2014, 11:02pm UTC](https://discuss.elastic.co/t/search-query-containing-an-equal-character/16385 "2014-03-14T23:02:08Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Guillaume\_Loetscher](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@Guillaume\_Loetscher](https://discuss.elastic.co/u/Guillaume_Loetscher)
#### Post date: [March 14, 2014, 11:02pm UTC](https://discuss.elastic.co/t/search-query-containing-an-equal-character/16385/1 "2014-03-14T23:02:08Z")

</div>

Hello,

I'm trying to do a query search containing an equal ("=") character in it.

I've got plenty of logs looking like this :

\<22\>postfix/smtpd[9136]: E4A4E34AA5: client=localhost.localdomain[127.0.0.1]

I want to query all messages that haven't been posted from  
"localhost.localdomain".

I've looked at the query documentation[http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html)here and tried multiple queries in Kibana and through a "curl" command, but  
no luck.

Right now, I've did this query : -"client=localhost.localdomain", but no  
luck, it keeps giving me answers with this precise string.

I also tried to protect the "=" character with a backslash.

How is it possible to do a query search with this character ?

Thanks a lot,

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/535ac45a-6698-422e-848f-594a824032a5%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/535ac45a-6698-422e-848f-594a824032a5%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![Guillaume\_Loetscher](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@Guillaume\_Loetscher](https://discuss.elastic.co/u/Guillaume_Loetscher)
#### Post date: [March 17, 2014, 5:07pm UTC](https://discuss.elastic.co/t/search-query-containing-an-equal-character/16385/2 "2014-03-17T17:07:44Z")

</div>

Hi,

No one knows ? I can't imagine that no one hasn't done a query on a string  
containing a "=" character in it.

Maybe my question is not clear enough. If so, please tell me where, I'll  
try to make it clearer.

Many thanks,

Le samedi 15 mars 2014 00:02:08 UTC+1, Guillaume Loetscher a écrit :

> Hello,
> 
> I'm trying to do a query search containing an equal ("=") character in it.
> 
> I've got plenty of logs looking like this :
> 
> \<22\>postfix/smtpd[9136]: E4A4E34AA5:  
> client=localhost.localdomain[127.0.0.1]
> 
> I want to query all messages that haven't been posted from  
> "localhost.localdomain".
> 
> I've looked at the query documentation[http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html)here and tried multiple queries in Kibana and through a "curl" command, but  
> no luck.
> 
> Right now, I've did this query : -"client=localhost.localdomain", but no  
> luck, it keeps giving me answers with this precise string.
> 
> I also tried to protect the "=" character with a backslash.
> 
> How is it possible to do a query search with this character ?
> 
> Thanks a lot,

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/60540866-127a-4bf0-9085-2cea4a8a6401%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/60540866-127a-4bf0-9085-2cea4a8a6401%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![Binh\_Ly\_2](https://avatars.discourse-cdn.com/v4/letter/b/d07c76/32.png) [@Binh\_Ly\_2](https://discuss.elastic.co/u/Binh_Ly_2)
#### Post date: [March 17, 2014, 5:28pm UTC](https://discuss.elastic.co/t/search-query-containing-an-equal-character/16385/3 "2014-03-17T17:28:29Z")

</div>

Your field is likely using the standard analyzer which by default which  
strips the = symbol. If you have the raw (not\_analyzed) field indexed, you  
can do something like this:

.raw:_client=localhost.localdomain_

This is probably not the best query to execute (because of the wildcards),  
but it illustrates that the = symbol can be searched for if you map it  
correctly for indexing.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/2ca53306-35ad-45ab-8400-2500493f5ac3%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/2ca53306-35ad-45ab-8400-2500493f5ac3%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![Guillaume\_Loetscher](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@Guillaume\_Loetscher](https://discuss.elastic.co/u/Guillaume_Loetscher)
#### Post date: [March 17, 2014, 7:41pm UTC](https://discuss.elastic.co/t/search-query-containing-an-equal-character/16385/4 "2014-03-17T19:41:55Z")

</div>

Le lundi 17 mars 2014 18:28:29 UTC+1, Binh Ly a écrit :

> Your field is likely using the standard analyzer which by default which  
> strips the = symbol. If you have the raw (not\_analyzed) field indexed, you  
> can do something like this:
> 
> .raw:_client=localhost.localdomain_

I don't have such field, but thanks for the pointer to "elasticsearch  
analyzer", I'll look at it asap.

Thanks again.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/639c01a5-6c3a-48cd-9206-11dcfcbbb59f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/639c01a5-6c3a-48cd-9206-11dcfcbbb59f%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [March 18, 2014, 9:29am UTC](https://discuss.elastic.co/t/search-query-containing-an-equal-character/16385/5 "2014-03-18T09:29:10Z")

</div>

Hey Guillaume,

while it might make sense to fire a query like this, I think it is more  
useful to actually make your unstructured data more structured. When you  
take a look at all those postfix logs you have, you will clearly see a  
pattern, that client=$name[$IP] is always the same... so it might make more  
sense to actually try to extract the ip and the hostname and put that one  
into several fields. This is exactly what logstash is for: getting data in,  
enriching and parsing it and then store it into elasticsearch. The huge  
advantage of such an enrichment process is of course, that querying now is  
really simple, as you always have the "right" content (only the hostname or  
only the ip) in the fields you are going to query.

You can definately build a query which mimics this behavour, parsing the  
logfiles appropriately and querying only the fields you intend to query  
might make much more sense.

See [http://www.elasticsearch.org/overview/logstash/](http://www.elasticsearch.org/overview/logstash/) for more info...

--Alex

On Sat, Mar 15, 2014 at 12:02 AM, Guillaume Loetscher  
[sterfield@gmail.com](mailto:sterfield@gmail.com)wrote:

> Hello,
> 
> I'm trying to do a query search containing an equal ("=") character in it.
> 
> I've got plenty of logs looking like this :
> 
> \<22\>postfix/smtpd[9136]: E4A4E34AA5:  
> client=localhost.localdomain[127.0.0.1]
> 
> I want to query all messages that haven't been posted from  
> "localhost.localdomain".
> 
> I've looked at the query documentation[http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html)here and tried multiple queries in Kibana and through a "curl" command, but  
> no luck.
> 
> Right now, I've did this query : -"client=localhost.localdomain", but no  
> luck, it keeps giving me answers with this precise string.
> 
> I also tried to protect the "=" character with a backslash.
> 
> How is it possible to do a query search with this character ?
> 
> Thanks a lot,
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/535ac45a-6698-422e-848f-594a824032a5%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/535ac45a-6698-422e-848f-594a824032a5%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/535ac45a-6698-422e-848f-594a824032a5%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/535ac45a-6698-422e-848f-594a824032a5%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGCwEM\_p-CAB6d%2B\_DZp9Z0Dec4X4qntm4LJJfWxgPpkBpCe1zA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGCwEM_p-CAB6d%2B_DZp9Z0Dec4X4qntm4LJJfWxgPpkBpCe1zA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 1:42am UTC](https://discuss.elastic.co/t/search-query-containing-an-equal-character/16385/6 "2017-07-06T01:42:35Z")

</div>


