# SNMP output and ES|QL

**URL:** <https://discuss.elastic.co/t/snmp-output-and-es-ql/364546>\
**Category:** Kibana\
**Tags:** esql\
**Created:** [August 7, 2024, 3:14pm UTC](https://discuss.elastic.co/t/snmp-output-and-es-ql/364546 "2024-08-07T15:14:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gaston\_Beltramelli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gaston_beltramelli/32/112623_2.png) [@Gaston\_Beltramelli](https://discuss.elastic.co/u/Gaston_Beltramelli)\
**Post date:** [August 7, 2024, 3:14pm UTC](https://discuss.elastic.co/t/snmp-output-and-es-ql/364546/1 "2024-08-07T15:14:26Z")

</div>

Hello community, i want to know if any of you have knowledge of ES|QL  
Im trying to do some viwes for a dashboard and i think this new feature can help but i was unable to do so.

this is an example of the data

 ![snmp](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a7ae0506a857c26bea7bde57f67524de61c4b812.png)

but as soon i want to search something it just doesn´t work, so its kind of useless

 ![snmp2](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e79e9568b613baef142c658ccd7935db6b59e692.png)

any help will be very useful

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 7, 2024, 3:33pm UTC](https://discuss.elastic.co/t/snmp-output-and-es-ql/364546/2 "2024-08-07T15:33:05Z")

</div>

could you try with:

```auto
from snmp*
| where tags like "snm*"

```

?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 7, 2024, 3:33pm UTC](https://discuss.elastic.co/t/snmp-output-and-es-ql/364546/3 "2024-08-07T15:33:35Z")

</div>

Added #esql and removed #kql-kibana-query-language

---

<div class="post-metadata">

**Author:** ![Gaston\_Beltramelli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gaston_beltramelli/32/112623_2.png) [@Gaston\_Beltramelli](https://discuss.elastic.co/u/Gaston_Beltramelli)\
**Post date:** [September 13, 2024, 4:00pm UTC](https://discuss.elastic.co/t/snmp-output-and-es-ql/364546/4 "2024-09-13T16:00:19Z")

</div>

> [@dadoonet](#):
>
> ```auto
> from snmp*
> | where tags like "snm*"
> 
> ```

no luck, i gave up with ES|QL I think its too new and its not working yet, will wait for the next releases.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 13, 2024, 6:34pm UTC](https://discuss.elastic.co/t/snmp-output-and-es-ql/364546/5 "2024-09-13T18:34:16Z")

</div>

@Gaston_Beltramelli cc @dadoonet

Please share a document or two...

Tags is an array so that needs to be considered...

There are 2 basic approaches to searching / matching on Arrays

- Use `MV_EXPAND` which will create a new row for each tag value and then a simple `where tags like "snm*"` will work

- Use `MV_CONCAT` to concatenate all the tags into a single new string then use the wildcard match

ESQL is GA and works well, could this use case be easier yes, are more functions being added yes...

Hope this helps
