# Searching from keyword field in Logstash with query

**URL:** <https://discuss.elastic.co/t/searching-from-keyword-field-in-logstash-with-query/361048>\
**Category:** Logstash\
**Created:** [June 7, 2024, 3:20pm UTC](https://discuss.elastic.co/t/searching-from-keyword-field-in-logstash-with-query/361048 "2024-06-07T15:20:42Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ma\_G](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ma_g/32/134906_2.png) [@Ma\_G](https://discuss.elastic.co/u/Ma_G)\
**Post date:** [June 7, 2024, 3:20pm UTC](https://discuss.elastic.co/t/searching-from-keyword-field-in-logstash-with-query/361048/1 "2024-06-07T15:20:42Z")

</div>

I would like to filter out the string "Alert" in the message field of my index. The field is a keyword field. To achieve this, I have written the following:

```auto
filter {
    mutate {
        add_field => {"secret" => "<my_secret>"}
    }

    elasticsearch {
        hosts => ["<my_host>:9200"]
        ssl => true
        ca_file => "/etc/ssl/certs/ca-certificates.crt"
        index => "<my_index>"
        query => 'message: "Alert"'
        user => "<my_user>"
        password => "<my_password>" 
        fields => {
            "message" => "[@metadata][message]"
        }
    }

```

It does not achieve the desired result. I believe I am missing something fundamental.
