WARNING: Version 6.1 of Kibana has passed its EOL date.
This documentation is no longer being maintained and may be removed. If you are running this version, we strongly advise you to upgrade. For the latest information, see the current release documentation.
To perform a free text search, simply enter a text string. For example, if
you’re searching web server logs, you could enter
safarito search all fields for the term
To search for a value in a specific field, prefix the value with the name
of the field. For example, you could enter
status:200to find all of the entries that contain the value
To search for a range of values, you can use the bracketed range syntax,
[START_VALUE TO END_VALUE]. For example, to find entries that have 4xx status codes, you could enter
status:[400 TO 499].
To specify more complex search criteria, you can use the Boolean operators
NOT. For example, to find entries that have 4xx status codes and have an extension of
html, you could enter
status:[400 TO 499] AND (extension:php OR extension:html).
For more detailed information about the Lucene query syntax, see the Query String Query docs.
These examples use the Lucene query syntax. When lucene is selected as your query language you can also submit queries using the Elasticsearch Query DSL.