# Search syntax

**URL:** <https://discuss.elastic.co/t/search-syntax/31653>\
**Category:** Kibana\
**Created:** [October 5, 2015, 6:46pm UTC](https://discuss.elastic.co/t/search-syntax/31653 "2015-10-05T18:46:13Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![scaarup](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scaarup/32/4615_2.png) [@scaarup](https://discuss.elastic.co/u/scaarup)\
**Post date:** [October 5, 2015, 6:46pm UTC](https://discuss.elastic.co/t/search-syntax/31653/1 "2015-10-05T18:46:13Z")

</div>

In Discover I am searching like this: event:"auth". I thought that would ONLY match the string auth in the event field, since I have quoted the string. But it also results in hits where auth is included in other fields. Is it supposed to be like that? If yes, how can I search for a string in a specific field only?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 6, 2015, 3:52am UTC](https://discuss.elastic.co/t/search-syntax/31653/2 "2015-10-06T03:52:45Z")

</div>

The quotes there won't matter too much, as per [the docs](https://www.elastic.co/guide/en/kibana/current/discover.html#search).

Are you sure there isn't a `*` at the start?

---

<div class="post-metadata">

**Author:** ![scaarup](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scaarup/32/4615_2.png) [@scaarup](https://discuss.elastic.co/u/scaarup)\
**Post date:** [October 6, 2015, 7:18am UTC](https://discuss.elastic.co/t/search-syntax/31653/3 "2015-10-06T07:18:29Z")

</div>

I am positive. Please have a look at my attached screenshots ![](https://us1.discourse-cdn.com/elastic/original/2X/b/b7d95fc14dd9d92351885c35fc4b848035e8c0b9.png)

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/bd667486a9b6934e25615af64b6ba6388bb0732f.png)

---

<div class="post-metadata">

**Author:** ![scaarup](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scaarup/32/4615_2.png) [@scaarup](https://discuss.elastic.co/u/scaarup)\
**Post date:** [October 6, 2015, 7:20am UTC](https://discuss.elastic.co/t/search-syntax/31653/4 "2015-10-06T07:20:52Z")

</div>

In the json request, I can see it says : fields:"\*"

```
    {
  "size": 500,
  "sort": [
    {
      "@timestamp": {
        "order": "desc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "query": {
    "filtered": {
      "query": {
        "query_string": {
          "query": "event: \"auth\"",
          "analyze_wildcard": true
        }
      },
      "filter": {
        "bool": {
          "must": [
            {
              "range": {
                "@timestamp": {
                  "gte": 1444072616816,
                  "lte": 1444115816816
                }
              }
            }
          ],
          "must_not": []
        }
      }
    }
  },
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {}
    },
    "fragment_size": 2147483647
  },
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "@timestamp",
        "interval": "10m",
        "pre_zone": "+02:00",
        "pre_zone_adjust_large_interval": true,
        "min_doc_count": 0,
        "extended_bounds": {
          "min": 1444072616816,
          "max": 1444115816816
        }
      }
    }
  },
  "fields": [
    "*",
    "_source"
  ],
  "script_fields": {},
  "fielddata_fields": [
    "_timestamp",
    "@timestamp"
  ]
}
```

---

<div class="post-metadata">

**Author:** ![Pieter\_Agenbag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pieter_agenbag/32/4562_2.png) [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Post date:** [October 6, 2015, 7:58am UTC](https://discuss.elastic.co/t/search-syntax/31653/5 "2015-10-06T07:58:20Z")

</div>

I did some tests on my side - and it looks like , although it Does only apply the filter to the spcified field (event) , if will still highlight the search parameter in all fields.

So event though you see "auth" highlighted in "status\_descr", you should not see any records that does NOT have "auth" in "event".

The

> "fields": [  
> "\*",  
> "\_source"  
> ],  
> Just indicates which fields are going to be returned and has no implication on what the filter is applied to.

---

<div class="post-metadata">

**Author:** ![scaarup](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scaarup/32/4615_2.png) [@scaarup](https://discuss.elastic.co/u/scaarup)\
**Post date:** [October 6, 2015, 1:46pm UTC](https://discuss.elastic.co/t/search-syntax/31653/6 "2015-10-06T13:46:43Z")

</div>

Thanks Pieter.  
I would like to confirm this behaviour though...

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [October 6, 2015, 2:03pm UTC](https://discuss.elastic.co/t/search-syntax/31653/7 "2015-10-06T14:03:06Z")

</div>

Pieter is correct, this is known (and at this point, by design) behavior.

Please feel free to add to the discussion - some users did ask us to change it:

> <https://github.com/elastic/kibana/issues/2358>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:11pm UTC](https://discuss.elastic.co/t/search-syntax/31653/8 "2017-07-06T14:11:50Z")

</div>


