# WHERE clause does not work for Kibana INDECES

**URL:** <https://discuss.elastic.co/t/where-clause-does-not-work-for-kibana-indeces/233521>\
**Category:** Kibana\
**Tags:** elastic-stack-sql\
**Created:** [May 20, 2020, 11:31am UTC](https://discuss.elastic.co/t/where-clause-does-not-work-for-kibana-indeces/233521 "2020-05-20T11:31:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vaclav1](https://avatars.discourse-cdn.com/v4/letter/v/c68b51/32.png) [@vaclav1](https://discuss.elastic.co/u/vaclav1)\
**Post date:** [May 20, 2020, 11:31am UTC](https://discuss.elastic.co/t/where-clause-does-not-work-for-kibana-indeces/233521/1 "2020-05-20T11:31:24Z")

</div>

Hello all,

I have tried to execute below query to return all indexed documents where type = dashboard. Idea is to grab all dashboard objects and do some visualization in canvas.

> ```
> POST _xpack/sql?format=txt
> 
> ```
> 
> {  
> "query": "SELECT \* FROM .kibana\_1 WHERE type = dashboard"  
> }

returns:

Failed to connect to Console's backend.  
Please check the Kibana server is up and running

---

<div class="post-metadata">

**Author:** ![matriv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matriv/32/43656_2.png) [@matriv](https://discuss.elastic.co/u/matriv)\
**Post date:** [May 20, 2020, 4:58pm UTC](https://discuss.elastic.co/t/where-clause-does-not-work-for-kibana-indeces/233521/2 "2020-05-20T16:58:44Z")

</div>

```auto
{
    "query" : "SELECT * FROM \".kibana_1\" WHERE type = 'dashboard'"
}

```

You'd probably get:

```auto
{
    "error": {
        "root_cause": [
            {
                "type": "illegal_argument_exception",
                "reason": "Trying to retrieve too many docvalue_fields. Must be less than or equal to: [100] but was [269]. This limit can be set by changing the [index.max_docvalue_fields_search] index level setting."
            }
        ],
....

```

So you'd need to SELECT the fields you need instead of `*`.

---

<div class="post-metadata">

**Author:** ![vaclav1](https://avatars.discourse-cdn.com/v4/letter/v/c68b51/32.png) [@vaclav1](https://discuss.elastic.co/u/vaclav1)\
**Post date:** [May 22, 2020, 6:45am UTC](https://discuss.elastic.co/t/where-clause-does-not-work-for-kibana-indeces/233521/3 "2020-05-22T06:45:03Z")

</div>

This worked! thank you :-)))

---

<div class="post-metadata">

**Author:** ![matriv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matriv/32/43656_2.png) [@matriv](https://discuss.elastic.co/u/matriv)\
**Post date:** [May 22, 2020, 1:47pm UTC](https://discuss.elastic.co/t/where-clause-does-not-work-for-kibana-indeces/233521/4 "2020-05-22T13:47:49Z")

</div>

You're welcome!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2020, 1:48pm UTC](https://discuss.elastic.co/t/where-clause-does-not-work-for-kibana-indeces/233521/5 "2020-06-19T13:48:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
