# Searching specific fields

**URL:** <https://discuss.elastic.co/t/searching-specific-fields/100612>\
**Category:** Kibana\
**Created:** [September 14, 2017, 9:59pm UTC](https://discuss.elastic.co/t/searching-specific-fields/100612 "2017-09-14T21:59:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tcouto](https://avatars.discourse-cdn.com/v4/letter/t/9d8465/32.png) [@tcouto](https://discuss.elastic.co/u/tcouto)\
**Post date:** [September 14, 2017, 9:59pm UTC](https://discuss.elastic.co/t/searching-specific-fields/100612/1 "2017-09-14T21:59:08Z")

</div>

I have a document with a field called request which stores the path component of the URL. I'd like to find all documents where field contains a substring. For example, consider a document containing the following request field.

```auto
"request": "app/profile/form/index.html"

```

From [the docs](https://www.elastic.co/guide/en/beats/packetbeat/5.0/kibana-queries-filters.html#_field_based_queries) it seems like I should be able to search `request: form` to find all documents where the request field contains form. However, this search is actually matching `form` on any field. How can I search for `form` on only the `request` field?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [September 14, 2017, 10:06pm UTC](https://discuss.elastic.co/t/searching-specific-fields/100612/2 "2017-09-14T22:06:07Z")

</div>

Your lucene query syntax looks correct. What is the ES mapping for the `request` field

---

<div class="post-metadata">

**Author:** ![tcouto](https://avatars.discourse-cdn.com/v4/letter/t/9d8465/32.png) [@tcouto](https://discuss.elastic.co/u/tcouto)\
**Post date:** [September 14, 2017, 10:38pm UTC](https://discuss.elastic.co/t/searching-specific-fields/100612/3 "2017-09-14T22:38:44Z")

</div>

Hi, @Nathan_Reese. Thanks for responding. Here's the mapping of the request field:

```auto
"request": {
  "type": "text",
  "fields": {
    "keyword": {
      "type": "keyword",
      "ignore_above": 256
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [September 15, 2017, 1:51pm UTC](https://discuss.elastic.co/t/searching-specific-fields/100612/4 "2017-09-15T13:51:54Z")

</div>

What does the Elasticsearch request look like? In the lower left corner of the visualization, click the toggle spy panel button. Look at the request for the visualization. Do you see your filter in the request?

---

<div class="post-metadata">

**Author:** ![tcouto](https://avatars.discourse-cdn.com/v4/letter/t/9d8465/32.png) [@tcouto](https://discuss.elastic.co/u/tcouto)\
**Post date:** [September 15, 2017, 6:46pm UTC](https://discuss.elastic.co/t/searching-specific-fields/100612/5 "2017-09-15T18:46:01Z")

</div>

I'm actually using discover rather than visualizations; however, I don't see that button in either view.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2017, 6:46pm UTC](https://discuss.elastic.co/t/searching-specific-fields/100612/6 "2017-10-13T18:46:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
