# Searching substring with escape characters

**URL:** <https://discuss.elastic.co/t/searching-substring-with-escape-characters/111816>\
**Category:** Kibana\
**Created:** [December 14, 2017, 4:51pm UTC](https://discuss.elastic.co/t/searching-substring-with-escape-characters/111816 "2017-12-14T16:51:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pablo\_Rovedo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pablo_rovedo/32/25585_2.png) [@Pablo\_Rovedo](https://discuss.elastic.co/u/Pablo_Rovedo)\
**Post date:** [December 14, 2017, 4:51pm UTC](https://discuss.elastic.co/t/searching-substring-with-escape-characters/111816/1 "2017-12-14T16:51:09Z")

</div>

Hi Everyone, I need to search messages contain the following substring of escape characters: "~$". I tried escaping with \ but with Kibana Visualize no result was found. Anyone can help me or give me some tips to solve it?

Thanks in Advance  
Pablo

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [December 14, 2017, 9:04pm UTC](https://discuss.elastic.co/t/searching-substring-with-escape-characters/111816/2 "2017-12-14T21:04:14Z")

</div>

This will probably only scale if you index your data in elasticsearch so that those terms are searchable. By default ES assumes the data is "text", which should be searchable using words. I suggest describing your data a bit, sharing your mappings, and asking in the elasticsearch forum for the best way to index your data for getting the results you seek.

If reindexing your data isn't an option then you could probably use regex on the specific field you are interested in, but I believe you will need a `keyword` version of that field (aka not-analyzed, meaning it hasn't been stripped of punctuation or other characteristics that are typically not meaningful when searching through text).

---

<div class="post-metadata">

**Author:** ![Pablo\_Rovedo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pablo_rovedo/32/25585_2.png) [@Pablo\_Rovedo](https://discuss.elastic.co/u/Pablo_Rovedo)\
**Post date:** [December 15, 2017, 3:46pm UTC](https://discuss.elastic.co/t/searching-substring-with-escape-characters/111816/3 "2017-12-15T15:46:37Z")

</div>

ok, maybe if I explain in more detail what I need you'll understand better. I just want to set a kibana Discover filter to filter out all the records where the field "filename" contains a substring "~$" which means, in windows fs envirnoment, that is a temporary file,. For this reason , is important leave out of analysis that kind of files.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2018, 3:47pm UTC](https://discuss.elastic.co/t/searching-substring-with-escape-characters/111816/4 "2018-01-12T15:47:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
