# Search special chars in .kibana index

**URL:** <https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292>\
**Category:** Kibana\
**Created:** [April 17, 2018, 6:24am UTC](https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292 "2018-04-17T06:24:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrask](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrask/32/20318_2.png) [@andrask](https://discuss.elastic.co/u/andrask)\
**Post date:** [April 17, 2018, 6:24am UTC](https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292/1 "2018-04-17T06:24:07Z")

</div>

Hi,

I have a few visualizations that are messed up by this index pattern `"index_pattern":"*"` and I want to fix them. But I cannot figure out how I should escape the search string.

Thanks,  
A

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [April 17, 2018, 6:01pm UTC](https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292/2 "2018-04-17T18:01:28Z")

</div>

In general, you should be able to escape by using the backslash: `\*`

Is that not fixing your issue here?

---

<div class="post-metadata">

**Author:** ![andrask](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrask/32/20318_2.png) [@andrask](https://discuss.elastic.co/u/andrask)\
**Post date:** [April 18, 2018, 8:42am UTC](https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292/3 "2018-04-18T08:42:35Z")

</div>

**Expression 1** : `\"index_pattern\"\:\"filebeat\-\*\"`  
Highlights index\_pattern and filebeat in all pieces where these words appear independently from each other.

**Expression 2** : `visualization.visState:\"index_pattern\"\:\"filebeat\-\*\"`  
Highlights the matches only in the given field.  
Still it doesn't make any difference if I omit or add stuff after the filebeat word.

**Expression 3** : `visualization.visState:\"index_pattern\*`  
Still highlights `index_pattern`

This may be a consequence of the parser that is used on this field but I find it hard to believe that searching for these kind of strings is not possible.

PS: not being able to copy the request sent in Discovery mode from Kibana is a huge pain.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [April 18, 2018, 3:52pm UTC](https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292/4 "2018-04-18T15:52:13Z")

</div>

> not being able to copy the request sent in Discovery mode from Kibana is a huge pain

Yeah, unfortunately the best way to do this currently is through the browser dev tools, looking at the network tab.

Searching for these kinds of strings is tricky because of how the values get analyzed in Elasticsearch. When indexed, Elasticsearch strips out special characters (like `"`, `-`, `*`) which makes it difficult to search for them. Unfortunately, you don't have a lot of control over Kibana's mapping either, since it's set by Kibana itself.

---

<div class="post-metadata">

**Author:** ![andrask](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrask/32/20318_2.png) [@andrask](https://discuss.elastic.co/u/andrask)\
**Post date:** [April 25, 2018, 6:10am UTC](https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292/5 "2018-04-25T06:10:50Z")

</div>

In the end I went over all docs one-by-one and fixed stuff manually.

I understand but I find it strange that even if I would give up on processing performance, I can't do a simple text search on documents. (Given the analyzers are not set up accordingly to begin with.)

Anyway, thanks @lukas. I'm looking forward for the feature to be able to copy the queries in all kinds of visualizations. 🙂 That would make our lives so much easier. Btw, is there a github issue for this? I'd give it a thunbs up.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [April 25, 2018, 5:09pm UTC](https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292/6 "2018-04-25T17:09:26Z")

</div>

> [@andrask](#):
>
> I'm looking forward for the feature to be able to copy the queries in all kinds of visualizations.

I guess I'm not exactly sure what you mean... Can you explain?

---

<div class="post-metadata">

**Author:** ![andrask](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrask/32/20318_2.png) [@andrask](https://discuss.elastic.co/u/andrask)\
**Post date:** [April 26, 2018, 6:11am UTC](https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292/7 "2018-04-26T06:11:06Z")

</div>

I mentioned above that not being able to copy the queries that go to Elasticsearch is quite painful. Especially in Discovery. But the same applies to all other visualizations.  
Where it's present, make it easy to click copy the "Request" tab.  
Where not present, e.g. in Visual Builder or Discovery on non-timebased indices, add the tab.  
This would already be huge help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2018, 6:11am UTC](https://discuss.elastic.co/t/search-special-chars-in-kibana-index/128292/8 "2018-05-24T06:11:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
