# Warn users when they do unindexed searches

**URL:** https://discuss.elastic.co/t/warn-users-when-they-do-unindexed-searches/286164
**Category:** Kibana
**Created:** [October 7, 2021, 9:37pm UTC](https://discuss.elastic.co/t/warn-users-when-they-do-unindexed-searches/286164 "2021-10-07T21:37:22Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![vibgy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vibgy/32/95564_2.png) [@vibgy](https://discuss.elastic.co/u/vibgy)
#### Post date: [October 7, 2021, 9:37pm UTC](https://discuss.elastic.co/t/warn-users-when-they-do-unindexed-searches/286164/1 "2021-10-07T21:37:22Z")

</div>

We have observed in our stack that a lot of the users are making queries without specifying a single indexed field. And we would like to soft-warn our users when they do so.

What would be the best way to implement something like that?

I thought of a few options -

- Chrome extension
- Kibana plugin
- Implement rejecting the query in the proxy layer (we run a proxy layer)

Any recommendations ?

---

<div class="post-metadata">

### Author: ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)
#### Post date: [October 8, 2021, 5:11am UTC](https://discuss.elastic.co/t/warn-users-when-they-do-unindexed-searches/286164/2 "2021-10-08T05:11:41Z")

</div>

How are your users making queries? Are they using Kibana? Which version of the Elastic stack are you using?

> without specifying a single indexed field.

I'm a bit confused by that statement, can you provide an example?

---

<div class="post-metadata">

### Author: ![vibgy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vibgy/32/95564_2.png) [@vibgy](https://discuss.elastic.co/u/vibgy)
#### Post date: [October 8, 2021, 5:17am UTC](https://discuss.elastic.co/t/warn-users-when-they-do-unindexed-searches/286164/3 "2021-10-08T05:17:46Z")

</div>

The users are using kibana to make the queries. We are on 7.10  
An example of a query is searching for a UUID or GUID ... without adding any filter.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [October 8, 2021, 6:41am UTC](https://discuss.elastic.co/t/warn-users-when-they-do-unindexed-searches/286164/4 "2021-10-08T06:41:03Z")

</div>

Hi @vibgy Welcome to the Community.

Have you thought about just setting the following setting found [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules.html#index-modules-settings)

By Default when this is not specified the query searches every field.. and that is usually not a good thing, but you can set a single or a couple fields to search by default like your UUID Field

`index.query.default_field`

(string or array of strings) Wildcard ( `*` ) patterns matching one or more fields. The following query types search these matching fields by default:

- [More like this](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-mlt-query.html)
- [Multi-match](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-multi-match-query.html)
- [Query string](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html)
- [Simple query string](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-simple-query-string-query.html)

Defaults to `*` , which matches all fields eligible for [term-level queries](https://www.elastic.co/guide/en/elasticsearch/reference/current/term-level-queries.html), excluding metadata fields.

---

<div class="post-metadata">

### Author: ![vibgy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vibgy/32/95564_2.png) [@vibgy](https://discuss.elastic.co/u/vibgy)
#### Post date: [October 8, 2021, 6:11pm UTC](https://discuss.elastic.co/t/warn-users-when-they-do-unindexed-searches/286164/5 "2021-10-08T18:11:52Z")

</div>

Well, we do not want to restrict the search of a UUID to specific fields. That would be problematic for teams trying to debug a particular transaction but no one knows exactly where that particular UUID shows up.

We are just looking for a way to warm them when they do not specify even one filter... like `k8s_namespace` or `app` or `k8s_container` .. In absence of this filter, ES searches all the logs and these become very expensive queries.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [October 8, 2021, 6:23pm UTC](https://discuss.elastic.co/t/warn-users-when-they-do-unindexed-searches/286164/6 "2021-10-08T18:23:58Z")

</div>

I don't think there's anything built into Kibana that does what you're looking for.

What I have seen some other users do is keep the original log message in example the message field that is of type text, so all the content is in there and then the default search searches that as a text field.

But no I don't think there's anything built into Kibana to warn when a field is not specfied

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 5, 2021, 6:24pm UTC](https://discuss.elastic.co/t/warn-users-when-they-do-unindexed-searches/286164/7 "2021-11-05T18:24:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
