mirror of
https://github.com/elastic/kibana.git
synced 2025-04-21 16:29:04 -04:00
31 lines
1.8 KiB
Text
31 lines
1.8 KiB
Text
[[query-bar]]
|
|
=== Advanced queries
|
|
|
|
The query bar is a powerful data query feature.
|
|
Similar to the query bar in {kibana-ref}/discover.html[Discover],
|
|
it enables you to pass advanced queries on your data to filter on particular pieces of information that you're interested in.
|
|
It comes with a handy autocomplete that helps find the fields and even provides suggestions to the data they include.
|
|
You can select the query bar and hit the down arrow on your keyboard to begin seeing recommendations.
|
|
|
|
When querying, you're simply searching and selecting data from fields in Elasticsearch documents.
|
|
It may be helpful to view some of your documents in {kibana-ref}/discover.html[Discover] to better understand how APM data is stored in Elasticsearch.
|
|
|
|
The query bar is available in the Services, Transactions, Errors, Metrics, and Traces views,
|
|
and any input will persist as you move between pages.
|
|
|
|
TIP: Interactions with the query bar change the URL of the page you're on.
|
|
This means you can simply copy and paste the URL of your page to share a specific query or view with others.
|
|
|
|
In the screenshot below, you can begin to see some of the transaction fields available for filtering on:
|
|
|
|
[role="screenshot"]
|
|
image::apm/images/apm-query-bar.png[Example of the Kibana Query bar in APM UI in Kibana]
|
|
|
|
==== Example queries
|
|
|
|
* Exclude response times slower than 2000 ms: `transaction.duration.us > 2000000`
|
|
* Filter by response status code: `context.response.status_code >= 400`
|
|
* Filter by single user ID: `context.user.id : 12`
|
|
* View _all_ transactions for an endpoint, instead of just a sample - `processor.event: "transaction" AND transaction.name: "<TRANSACTION_NAME_HERE>"`
|
|
|
|
TIP: Read the {kibana-ref}/kuery-query.html[Kibana Query Language Enhancements] documentation to learn more about the capabilities of the {kib} query language.
|