Quiz Entry - updated: 2026.09.24
How do you write basic searches in Kibana's Lucene query syntax?
Keywords, field:value matches, Boolean operators AND/OR/NOT (in capitals), phrases in double quotes, _exists_:field for field presence, wildcards * and ?, and ranges in square or curly brackets.
| Search | Example |
|---|---|
| Keyword | usbstor |
| Boolean | usbstor AND deviceclasses, http AND (get OR post), NOT ssl |
| Must / must not | +www.google.com, -www.google.com |
| Phrase | "WINDOWS system32 config" (double quotes only; single quotes do not work) |
| Field match | http.host:www.google.com |
| Several values for one field | source_short:(reg evt) |
| Field exists / missing | _exists_:http.host, NOT _exists_:http.user_agent |
| Wildcards | *.exe, *.ppt? |
| Inclusive range | port:[1 TO 1024] |
| Exclusive range | port:{0 TO 1025} |
Special characters + - && || ! ( ) { } [ ] ^ " ~ * ? : \ have to be escaped with \ when meant literally.
Note that Kibana's default search bar today uses KQL (Kibana Query Language), which is similar for simple searches (field:value, and/or/not, field:* for existence) but lacks Lucene's regex, fuzzy and proximity search. The Lucene syntax can be switched on in the search bar.
Go deeper:
Elasticsearch — Query string syntax — the full Lucene syntax reference.
Elastic — KQL — Kibana's default query language and how it differs from Lucene.