# Cannot search /var/log/messages without '\*' wildcard before string

**URL:** <https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 14, 2018, 4:45pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952 "2018-03-14T16:45:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wanderer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wanderer/32/55140_2.png) [@Wanderer](https://discuss.elastic.co/u/Wanderer)\
**Post date:** [March 14, 2018, 4:45pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952/1 "2018-03-14T16:45:53Z")

</div>

Version 6.2.2

System module enabled. When searching in Discover /var/log/messages returns zero results. However, the syslog messages are showing in Discover. If I search for _user_ I get results. If searching for user\* there are no results, as an example.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 16, 2018, 8:09pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952/2 "2018-03-16T20:09:26Z")

</div>

Can you post some screenshots to demonstrate the issue? It might be that the field you are trying to search by is not searchable.

---

<div class="post-metadata">

**Author:** ![Wanderer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wanderer/32/55140_2.png) [@Wanderer](https://discuss.elastic.co/u/Wanderer)\
**Post date:** [March 16, 2018, 8:34pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952/3 "2018-03-16T20:34:02Z")

</div>

Example syslog message:

system.syslog.message (?@123.456.789.000) [WARNING] Authentication failed for user

The message only appeared when I searched for _user_

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 16, 2018, 8:55pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952/4 "2018-03-16T20:55:02Z")

</div>

> [@Wanderer](#):
>
> When searching in Discover /var/log/messages returns zero results.

Does `source:"/var/log/messages"` work in Kibana?

---

<div class="post-metadata">

**Author:** ![Wanderer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wanderer/32/55140_2.png) [@Wanderer](https://discuss.elastic.co/u/Wanderer)\
**Post date:** [March 16, 2018, 8:57pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952/5 "2018-03-16T20:57:52Z")

</div>

When pasting source:"/var/log/messages" into the search field messages do show. They also show naturally with no search string. When searching with a search string the source of /var/log/messages does not return results. Hopefully my explanation is clear.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 18, 2018, 2:58pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952/6 "2018-03-18T14:58:48Z")

</div>

The `source` field is a keyword, which means it's not searched by default when no field is specified. Isn't searching with `source:"/var/log/messages"` an acceptable solution?

If not, I think a solution would be to modify the Elasticsearch mapping template and add an equivalent text field by using [copy to](https://www.elastic.co/guide/en/elasticsearch/reference/current/copy-to.html).

The approximate process for that would be:

```auto
GET /_template/filebeat-6.2.2

<edit the template file>

PUT /_template/filebeat-6.2.2
{
 <modified template>
}

```

Note that the template applies only index creation, so the modified template will be applied only when a new index is template.

Also, note that we encode the version in the template name, which means you'll have to do this on each upgrade.

We do hope to make this process easier with a feature in Beats (basically specified which fields should be copied to a text field), but it's not currently available.

---

<div class="post-metadata">

**Author:** ![Wanderer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wanderer/32/55140_2.png) [@Wanderer](https://discuss.elastic.co/u/Wanderer)\
**Post date:** [March 18, 2018, 3:13pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952/7 "2018-03-18T15:13:45Z")

</div>

Let me explain the use case - We pull logs from many log file sources via the filebeat.yml and simply want to type the text word we are after. Example: We want to find all instances of the text "user" in all log files. If I do that now with using the system module all the log files will be searched except syslog since it is using the system module? Do I understand this correctly?

Would it just be simpler to then use the filebeat.yml to point to /var/log/messages instead of using the module?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [March 18, 2018, 8:04pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952/8 "2018-03-18T20:04:22Z")

</div>

Ah, I realised we have a bug in the module. The message field would make more sense as a `text` here: [https://github.com/elastic/beats/blob/master/filebeat/module/system/syslog/\_meta/fields.yml#L18-L20](https://github.com/elastic/beats/blob/master/filebeat/module/system/syslog/_meta/fields.yml#L18-L20)

I'll open a PR to fix it.

In the mean time, you can use a normal input/prospector instead of the module to workaround, you just lose the parsed program name, pid, etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2018, 8:04pm UTC](https://discuss.elastic.co/t/cannot-search-var-log-messages-without-wildcard-before-string/123952/9 "2018-04-15T20:04:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
