# Start with filter or query

**URL:** <https://discuss.elastic.co/t/start-with-filter-or-query/117319>\
**Category:** Kibana\
**Created:** [January 27, 2018, 5:54pm UTC](https://discuss.elastic.co/t/start-with-filter-or-query/117319 "2018-01-27T17:54:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [January 27, 2018, 5:54pm UTC](https://discuss.elastic.co/t/start-with-filter-or-query/117319/1 "2018-01-27T17:54:12Z")

</div>

How do I perform a search in Kibana so that douments starting with a string match? I've done a ton of Googling and come up with nothing. I am searching a typical Apache log line in the request field.

---

<div class="post-metadata">

**Author:** ![Melvyn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/melvyn/32/35269_2.png) [@Melvyn](https://discuss.elastic.co/u/Melvyn)\
**Post date:** [January 28, 2018, 6:26pm UTC](https://discuss.elastic.co/t/start-with-filter-or-query/117319/2 "2018-01-28T18:26:05Z")

</div>

What do you mean by "document starting with a string"?

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [February 3, 2018, 12:36am UTC](https://discuss.elastic.co/t/start-with-filter-or-query/117319/3 "2018-02-03T00:36:51Z")

</div>

I want the search to return only fields that start with a term. Somewhere I read that ^ would do the trick but it didn't work. This would be searching a typical apache access log index. I want to return log lines that either start with, or do not start with "/admin/index.php" regardless of the url parameters after the question mark index.php?thisfield=test1&thatfield=test2.

request:^/admin/index.php

Here is a full record.

{  
"\_index": "apache-access\_2018.01.31",  
"\_type": "doc",  
"\_id": "4vVETmEB3Wi\_gLjvSceJ",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"geoip": {  
"ip": "177.37.134.130",  
"longitude": -39.3346,  
"coordinates": [  
-39.3346,  
-5.1342  
],  
"region\_name": "Ceara",  
"city\_name": "Quixeramobim",  
"country\_code2": "BR",  
"latitude": -5.1342,  
"location": {  
"lon": -39.3346,  
"lat": -5.1342  
},  
"timezone": "America/Fortaleza",  
"region\_code": "CE",  
"country\_code3": "BR",  
"postal\_code": "63800",  
"country\_name": "Brazil",  
"continent\_code": "SA"  
},  
"agent": ""-"",  
"virtualhost": "[exampledomain.com](http://exampledomain.com)",  
"source": "/var/log/httpd/access\_log",  
"request": "/index.php",  
"message": "177.37.134.130 - - [31/Jan/2018:22:09:08 +0000] [exampledomain.com](http://exampledomain.com) "GET /index.php HTTP/1.1" 301 260 "-" "-" Server=aws7 "-" 191 0",  
"apache-access": true,  
"@timestamp": "2018-01-31T22:09:08.000Z",  
"host": "[aws7.hostdomain.net](http://aws7.hostdomain.net)",  
"bytes": 260,  
"referrer": ""-"",  
"clientip": "177.37.134.130",  
"offset": 17617570,  
"tags": [  
"beats\_input\_codec\_plain\_applied"  
],  
"response": "301",  
"server": "aws7",  
"timestamp": "31/Jan/2018:22:09:08 +0000",  
"httpversion": "1.1",  
"user\_agent": {  
"device": "Other",  
"build": "",  
"name": "Other",  
"os": "Other",  
"os\_name": "Other"  
},  
"logline": "177.37.134.130 - - [31/Jan/2018:22:09:08 +0000] [exampledomain.com](http://exampledomain.com) "GET /index.php HTTP/1.1" 301 260 "-" "-" Server=aws7 "-" 191 0",  
"verb": "GET",  
"@version": "1",  
"request\_duration\_ms": 191,  
"request\_duration\_s": 0,  
"beat": {  
"name": "[aws7.hostdomain.net](http://aws7.hostdomain.net)",  
"version": "6.1.2",  
"hostname": "[aws7.hostdomain.net](http://aws7.hostdomain.net)"  
}  
},  
"fields": {  
"@timestamp": [  
"2018-01-31T22:09:08.000Z"  
]  
},  
"highlight": {  
"logline": [  
"177.37.134.130 - - [31/Jan/2018:22:09:08 +0000] @kibana-highlighted-field@exampledomain.com@/kibana-highlighted-field@ "GET /index.php HTTP/1.1" 301 260 "-" "-" Server=aws7 "-" 191 0"  
],  
"message": [  
"177.37.134.130 - - [31/Jan/2018:22:09:08 +0000] @kibana-highlighted-field@exampledomain.com@/kibana-highlighted-field@ "GET /index.php HTTP/1.1" 301 260 "-" "-" Server=aws7 "-" 191 0"  
],  
"virtualhost.keyword": [  
"@kibana-highlighted-field@exampledomain.com@/kibana-highlighted-field@"  
],  
"virtualhost": [  
"@kibana-highlighted-field@exampledomain.com@/kibana-highlighted-field@"  
]  
},  
"sort": [  
1517436548000  
]  
}

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [February 10, 2018, 9:52pm UTC](https://discuss.elastic.co/t/start-with-filter-or-query/117319/4 "2018-02-10T21:52:53Z")

</div>

Bump

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [March 5, 2018, 4:23pm UTC](https://discuss.elastic.co/t/start-with-filter-or-query/117319/5 "2018-03-05T16:23:01Z")

</div>

bump

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [March 15, 2018, 3:33pm UTC](https://discuss.elastic.co/t/start-with-filter-or-query/117319/6 "2018-03-15T15:33:33Z")

</div>

bump

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2018, 3:33pm UTC](https://discuss.elastic.co/t/start-with-filter-or-query/117319/7 "2018-04-12T15:33:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
