# Text search in Kibana

**URL:** <https://discuss.elastic.co/t/text-search-in-kibana/249157>\
**Category:** Kibana\
**Created:** [September 18, 2020, 6:32pm UTC](https://discuss.elastic.co/t/text-search-in-kibana/249157 "2020-09-18T18:32:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fredrick.bb](https://avatars.discourse-cdn.com/v4/letter/f/7bcc69/32.png) [@fredrick.bb](https://discuss.elastic.co/u/fredrick.bb)\
**Post date:** [September 18, 2020, 6:32pm UTC](https://discuss.elastic.co/t/text-search-in-kibana/249157/1 "2020-09-18T18:32:16Z")

</div>

Hello,

I have application log message with following details as message : " some message; partition=-1;offset=-1;lag=275545;RetryCount=0; some message ".

All my message will have "lag=". "lag" is a key comes as a part of message. I need to query to find out lag value greater than 500 or with in a range.

What is the query syntax should I give get extract based on my message.

Thanks

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [September 24, 2020, 5:02pm UTC](https://discuss.elastic.co/t/text-search-in-kibana/249157/2 "2020-09-24T17:02:33Z")

</div>

Hi  
The recommended way would be to extract this value when ingesting data. This could be done with e.g. with logstash or using the Elasticsearch ingest pipeline. Would that be an option for you?  
Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2020, 5:02pm UTC](https://discuss.elastic.co/t/text-search-in-kibana/249157/3 "2020-10-22T17:02:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
