# Why query works in DevTools but not in a Rule?

**URL:** <https://discuss.elastic.co/t/why-query-works-in-devtools-but-not-in-a-rule/277467>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [June 30, 2021, 1:18pm UTC](https://discuss.elastic.co/t/why-query-works-in-devtools-but-not-in-a-rule/277467 "2021-06-30T13:18:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [June 30, 2021, 1:18pm UTC](https://discuss.elastic.co/t/why-query-works-in-devtools-but-not-in-a-rule/277467/1 "2021-06-30T13:18:39Z")

</div>

Dear all =)

Here is an odd one!

If I in Dev Tools do

```auto
GET _search
{ "query": { "query_string": { "query": "besked:*" } } }

```

then I get lots of results. If I do the same in a rule, I don't get any results.

 ![00023](https://us1.discourse-cdn.com/elastic/original/3X/e/a/eaaeda2af294de655acb3bba75adb03ea937ecf9.png)

Are extra permissions needed?

What am I doing wrong?

Hugs  
Sandra =)

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [June 30, 2021, 2:47pm UTC](https://discuss.elastic.co/t/why-query-works-in-devtools-but-not-in-a-rule/277467/2 "2021-06-30T14:47:25Z")

</div>

Hey @Sandra_Schlichting,

In dev tools, running `GET _search` will search across all of your indices. When defining a rule, you need to specify the set of indices you wish to search against. Are you sure that the indices you've chosen in the rule actually have data?

Can you run the `_search` in dev tools constrained to the indices you've set in the rule to see if that returns any results? For example:

```json
GET /my-index-name/_search
{ "query": { "query_string": { "query": "besked:*" } } }

```

---

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [June 30, 2021, 5:44pm UTC](https://discuss.elastic.co/t/why-query-works-in-devtools-but-not-in-a-rule/277467/3 "2021-06-30T17:44:44Z")

</div>

Dear Larry. Thanks a lot! Very useful debug trick you gave me there. Apparently indices in rules can't use wildcard it seams. Entering the full index name solved the problem. Thanks again =)

Hugs  
Sandra =)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 1, 2021, 12:20am UTC](https://discuss.elastic.co/t/why-query-works-in-devtools-but-not-in-a-rule/277467/4 "2021-07-01T00:20:16Z")

</div>

Hi @Sandra_Schlichting

I just happen to come across this. You can absolutely use an index pattern in a DSL Query. I just find the index selector a bit tricky.

You have to type in your pattern say` filebeat-*`  
Then wait for the selector list to finish... then scroll down and actually select the index-pattern or the wildcard pattern... that is the trick

This is with an index pattern

 ![Screen Shot 2021-06-30 at 5.10.42 PM](https://us1.discourse-cdn.com/elastic/original/3X/8/9/89932dcbfb31d868b953417a2c83b4b601cc009d.png)

This is with an arbitrary wildcard ` filebeat-11.2-*`

 ![Screen Shot 2021-06-30 at 5.18.25 PM](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ffda9708df3bac3abe6c53b04b2b87b1d7fc11a8.png)

and the test query works

 ![Screen Shot 2021-06-30 at 5.19.11 PM](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d66b22a03cedaa5666a2fcee1753377682c783f9.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2021, 12:20am UTC](https://discuss.elastic.co/t/why-query-works-in-devtools-but-not-in-a-rule/277467/5 "2021-07-29T00:20:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
