# Upgrade to 7.4.2 no results with KQL query

**URL:** <https://discuss.elastic.co/t/upgrade-to-7-4-2-no-results-with-kql-query/208071>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [November 15, 2019, 12:17pm UTC](https://discuss.elastic.co/t/upgrade-to-7-4-2-no-results-with-kql-query/208071 "2019-11-15T12:17:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sulinder](https://avatars.discourse-cdn.com/v4/letter/s/85f322/32.png) [@sulinder](https://discuss.elastic.co/u/sulinder)\
**Post date:** [November 15, 2019, 12:17pm UTC](https://discuss.elastic.co/t/upgrade-to-7-4-2-no-results-with-kql-query/208071/1 "2019-11-15T12:17:13Z")

</div>

Hi All,  
I upgrade my on-premise ELK stack from 7.3.1 to 7.4.2. Now I have noticed that when I type in a KQL command into the Kibana search field, then click on Apply nothing happens.  
If I use the Filter tool to create a query, then it works fine and returns a result.  
Also if I change from KQL to Lucene in the search field, then type in a valid query, I get results.

So basically it looks like when I type in some syntax e.g. destination-address : 8.8.8.8 when it is set to KQL, nothing happens and no results are returned.

This was working fine with ELK 7.3.1

Thank you.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 18, 2019, 10:08pm UTC](https://discuss.elastic.co/t/upgrade-to-7-4-2-no-results-with-kql-query/208071/2 "2019-11-18T22:08:09Z")

</div>

Can you look in the Inspector menu when you run it with and without the KQL query and post them here?

---

<div class="post-metadata">

**Author:** ![sulinder](https://avatars.discourse-cdn.com/v4/letter/s/85f322/32.png) [@sulinder](https://discuss.elastic.co/u/sulinder)\
**Post date:** [November 19, 2019, 11:16am UTC](https://discuss.elastic.co/t/upgrade-to-7-4-2-no-results-with-kql-query/208071/3 "2019-11-19T11:16:15Z")

</div>

Hi Marius,  
Please find the output below:

When I put in destination-address : 8.8.8.8 into search field I get below

Inspect menu shows:  
{  
"version": true,  
"size": 500,  
"sort": [  
{  
"@timestamp": {  
"order": "desc",  
"unmapped\_type": "boolean"  
}  
}  
],  
"\_source": {  
"excludes":   
},  
"aggs": {  
"2": {  
"date\_histogram": {  
"field": "@timestamp",  
"fixed\_interval": "30s",  
"time\_zone": "Europe/London",  
"min\_doc\_count": 1  
}  
}  
},  
"stored\_fields": [  
"_"  
],  
"script\_fields": {},  
"docvalue\_fields": [  
{  
"field": "@timestamp",  
"format": "date\_time"  
}  
],  
"query": {  
"bool": {  
"must": [],  
"filter": [  
{  
"match\_all": {}  
},  
{  
"range": {  
"@timestamp": {  
"format": "strict\_date\_optional\_time",  
"gte": "2019-11-19T10:34:14.923Z",  
"lte": "2019-11-19T10:49:14.924Z"  
}  
}  
}  
],  
"should": [],  
"must\_not": []  
}  
},  
"highlight": {  
"pre\_tags": [  
"@kibana-highlighted-field@"  
],  
"post\_tags": [  
"@/kibana-highlighted-field@"  
],  
"fields": {  
"_": {}  
},  
"fragment\_size": 2147483647  
}  
}

#### 

When I put in just 8.8.8.8 into the search field

inspect menu shows

{  
"version": true,  
"size": 500,  
"sort": [  
{  
"@timestamp": {  
"order": "desc",  
"unmapped\_type": "boolean"  
}  
}  
],  
"\_source": {  
"excludes":   
},  
"aggs": {  
"2": {  
"date\_histogram": {  
"field": "@timestamp",  
"fixed\_interval": "30s",  
"time\_zone": "Europe/London",  
"min\_doc\_count": 1  
}  
}  
},  
"stored\_fields": [  
"_"  
],  
"script\_fields": {},  
"docvalue\_fields": [  
{  
"field": "@timestamp",  
"format": "date\_time"  
}  
],  
"query": {  
"bool": {  
"must": [],  
"filter": [  
{  
"multi\_match": {  
"type": "best\_fields",  
"query": "8.8.8.8",  
"lenient": true  
}  
},  
{  
"range": {  
"@timestamp": {  
"format": "strict\_date\_optional\_time",  
"gte": "2019-11-19T10:42:40.788Z",  
"lte": "2019-11-19T10:57:40.788Z"  
}  
}  
}  
],  
"should": [],  
"must\_not": []  
}  
},  
"highlight": {  
"pre\_tags": [  
"@kibana-highlighted-field@"  
],  
"post\_tags": [  
"@/kibana-highlighted-field@"  
],  
"fields": {  
"_": {}  
},  
"fragment\_size": 2147483647  
}  
}

---

<div class="post-metadata">

**Author:** ![sulinder](https://avatars.discourse-cdn.com/v4/letter/s/85f322/32.png) [@sulinder](https://discuss.elastic.co/u/sulinder)\
**Post date:** [December 10, 2019, 4:37pm UTC](https://discuss.elastic.co/t/upgrade-to-7-4-2-no-results-with-kql-query/208071/4 "2019-12-10T16:37:24Z")

</div>

I just upgraded to 7.5.0 and it works now, meaning when I type in a KQL command the results are returned. Inspector menu now shows query being made, which it was not doing in version 7.4.2 when I typed a KQL command.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2020, 4:37pm UTC](https://discuss.elastic.co/t/upgrade-to-7-4-2-no-results-with-kql-query/208071/5 "2020-01-07T16:37:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
