# Simple Kibana "term query" not searching the all the fields

**URL:** <https://discuss.elastic.co/t/simple-kibana-term-query-not-searching-the-all-the-fields/252113>\
**Category:** Kibana\
**Created:** [October 14, 2020, 10:45pm UTC](https://discuss.elastic.co/t/simple-kibana-term-query-not-searching-the-all-the-fields/252113 "2020-10-14T22:45:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [October 14, 2020, 10:45pm UTC](https://discuss.elastic.co/t/simple-kibana-term-query-not-searching-the-all-the-fields/252113/1 "2020-10-14T22:45:18Z")

</div>

Hello, I'm puzzled by the following explanation here: [Kibana Query Language | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/kuery-query.html)

> Terms without fields are matched against the default field in your index settings. If a default field is not set, terms are matched against all fields. For example, a query for `response:200` searches for the value 200 in the response field, but a query for just `200` searches for 200 across all fields in your index.

I have 2 fields, one is `event.message` and the other is `log.message`, they are both very similar (`log.message` is created by a GREEDYDATA grok filter from `event.message`).

Since these 2 fields are very similar, I'm dropping `event.message`. The problem now is that Kibana doesn't search `log.message` using term queries (just using `"query here"` in the Kibana search bar without explicit field).

Why does Kibana not searching this field when they are both text/string fields? Any idea? Thanks!

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [October 15, 2020, 12:55am UTC](https://discuss.elastic.co/t/simple-kibana-term-query-not-searching-the-all-the-fields/252113/2 "2020-10-15T00:55:43Z")

</div>

mind sharing your query?  
also, what do you mean by not searching? what is the result? what is the expected result?

---

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [October 15, 2020, 1:07am UTC](https://discuss.elastic.co/t/simple-kibana-term-query-not-searching-the-all-the-fields/252113/3 "2020-10-15T01:07:46Z")

</div>

Here's a log in Discover:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f2c8b9ffea40ba997feaad1ab9f5eed36d7b68f1.png)

Here I type "initial" (because in the log, you see the word "initial":

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7f23f40eb749389d1f50558b02c7255d0de41ae0.png)

But no result...

As I said, it searches properly the field `event.message` - which I am dropping now.

But as you see, Kibana doesn't search the current `log.message` (both are very similar fields, I drop one of them to save space).

I though that a "term query" (just putting a word into the search bar) will search all field (i.e "\*"), but it doesn't catch `log.message`.

If I search using the field name in the query bar like this `log.message : *initial*`, it finds it:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/5/158761417d2000e04917004cc91874a98f1aceee.png)

If I do a "term query" with the word "informational", it finds it in the field `syslog.severity`:

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f91a81f3b1ab0d1700d0a067132243082fa305ef.png)

So why does Kibana not really searching all fields "\*" when doing a "term query"? Why does not it search `log.message`?

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [October 15, 2020, 2:17am UTC](https://discuss.elastic.co/t/simple-kibana-term-query-not-searching-the-all-the-fields/252113/4 "2020-10-15T02:17:32Z")

</div>

Could be a few reasons.

1. your second example is a single word, while your first search is inside a long string.  
Try to have the same conditions, as much as possible
2. check differences in the filed definition.
3. bug

---

<div class="post-metadata">

**Author:** ![lamp123432](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Post date:** [October 15, 2020, 2:32am UTC](https://discuss.elastic.co/t/simple-kibana-term-query-not-searching-the-all-the-fields/252113/5 "2020-10-15T02:32:11Z")

</div>

It was working fine with `event.message`, I am now dropping that field because `log.message` is a duplicate of it. Kibana was searching the first field just with one word, while the other it refuses to search. Maybe it's a bug, but I think there is something more to this.

Check this out: [Query string query | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html)

> `default_field`

> (Optional, string) Default field you wish to search if no field is provided in the query string.

> Defaults to the `index.query.default_field` index setting, which has a default value of `*` . The `*` value extracts all fields that are eligible for term queries and filters the metadata fields. All extracted fields are then combined to build a query if no `prefix` is specified.

> Searching across all eligible fields does not include [nested documents](https://www.elastic.co/guide/en/elasticsearch/reference/current/nested.html). Use a [`nested` query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-nested-query.html) to search those documents.

> For mappings with a large number of fields, searching across all eligible fields could be expensive.

> There is a limit on the number of fields that can be queried at once. It is defined by the `indices.query.bool.max_clause_count` [search setting](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-settings.html), which defaults to 1024.

What do they mean by "eligible fields"? Could `log.message` not be eligible for some reason? What are the requirements for a field to be "eligible"?

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [October 15, 2020, 2:59am UTC](https://discuss.elastic.co/t/simple-kibana-term-query-not-searching-the-all-the-fields/252113/6 "2020-10-15T02:59:38Z")

</div>

> [@lamp123432](#):
>
> eligible

I believe the meaning is **eligible to _term_ queries**  
So a string made out of more than 1 word, cannot be used with _ **term** _ queries. Unless you match the whole string, and not just part of it, like in your case.

Terms query - [Terms query | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-terms-query.html)

> Returns documents that contain one or more **exact** terms in a provided field.  
> The `terms` query is the same as the [`term` query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-term-query.html), except you can search for multiple values

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2020, 2:59am UTC](https://discuss.elastic.co/t/simple-kibana-term-query-not-searching-the-all-the-fields/252113/7 "2020-11-12T02:59:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
