# What does = do in Filters?

**URL:** <https://discuss.elastic.co/t/what-does-do-in-filters/199291>\
**Category:** Kibana\
**Created:** [September 12, 2019, 4:40pm UTC](https://discuss.elastic.co/t/what-does-do-in-filters/199291 "2019-09-12T16:40:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alan\_Home](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alan_home/32/45644_2.png) [@Alan\_Home](https://discuss.elastic.co/u/Alan_Home)\
**Post date:** [September 12, 2019, 4:40pm UTC](https://discuss.elastic.co/t/what-does-do-in-filters/199291/1 "2019-09-12T16:40:09Z")

</div>

I know the correct way to look for user 12345678 in Discover is to say  
userId:12345678

But if I type userId=12345678, I get every message that contains any userId. So what does = do? Does it do anything? Does Kibana just stop when it sees it and trim the query to "userId"?

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [September 12, 2019, 6:05pm UTC](https://discuss.elastic.co/t/what-does-do-in-filters/199291/2 "2019-09-12T18:05:07Z")

</div>

`=` isn't an operator, so it's treated as part of the query itself, just like the letters before and numbers afterwards. I'm assuming at least one of your fields that is analyzed contain the actual text `userId` somewhere within it, which would probably match that query.

---

<div class="post-metadata">

**Author:** ![Alan\_Home](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alan_home/32/45644_2.png) [@Alan\_Home](https://discuss.elastic.co/u/Alan_Home)\
**Post date:** [September 12, 2019, 9:16pm UTC](https://discuss.elastic.co/t/what-does-do-in-filters/199291/3 "2019-09-12T21:16:59Z")

</div>

If I Filter on userId=12345678 my results come back -  
**userId** =1236  
**userId** =1234  
**userId** =1238  
where the bold is the highlighted text indicating that Kibana found what you were searching for.

But, if I filter with it in double quotes "userId=12345678" I get  
**userId** = **12345678**

It never seems to recognize the = as part of the search query. It treats it almost like an OR statement without the quotes and an AND statement with the quotes.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [September 12, 2019, 9:29pm UTC](https://discuss.elastic.co/t/what-does-do-in-filters/199291/4 "2019-09-12T21:29:04Z")

</div>

Most likely because the field you're querying is analyzed. When you search special characters like that against an analyzed field, those special characters get stripped. You could try explicitly querying the `keyword` version of the field, in which case it should actually query the `=`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2019, 9:29pm UTC](https://discuss.elastic.co/t/what-does-do-in-filters/199291/5 "2019-10-10T21:29:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
