LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

How do you write basic searches in Kibana's Lucene query syntax?

Keywords, field:value matches, Boolean operators AND/OR/NOT (in capitals), phrases in double quotes, _exists_:field for field presence, wildcards * and ?, and ranges in square or curly brackets.

Search Example
Keyword usbstor
Boolean usbstor AND deviceclasses, http AND (get OR post), NOT ssl
Must / must not +www.google.com, -www.google.com
Phrase "WINDOWS system32 config" (double quotes only; single quotes do not work)
Field match http.host:www.google.com
Several values for one field source_short:(reg evt)
Field exists / missing _exists_:http.host, NOT _exists_:http.user_agent
Wildcards *.exe, *.ppt?
Inclusive range port:[1 TO 1024]
Exclusive range port:{0 TO 1025}

Special characters + - && || ! ( ) { } [ ] ^ " ~ * ? : \ have to be escaped with \ when meant literally.

Note that Kibana's default search bar today uses KQL (Kibana Query Language), which is similar for simple searches (field:value, and/or/not, field:* for existence) but lacks Lucene's regex, fuzzy and proximity search. The Lucene syntax can be switched on in the search bar.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026