OK figured it. missed Lucene at the end
{
"index": "1cf03af0-037a-11e9-beef-5f4114182e77",
"highlightAll": true,
"version": true,
"query": {
"query_string": {
"fields": [
"process.cwd.keyword",
"auditd.data.name.keyword",
"auditd.paths.name.keyword",
"file.path.keyword",
"auditd.summary.object.primary.keyword"
],
"query": "\\/PTC\\/*\\/code\\/*",
"analyzer": "keyword",
"analyze_wildcard": true
},
"language": "lucene"
},
"filter": []
}