# Doc\_values and wildcard searches

**URL:** <https://discuss.elastic.co/t/doc-values-and-wildcard-searches/927>\
**Category:** Elasticsearch\
**Created:** [May 19, 2015, 8:20pm UTC](https://discuss.elastic.co/t/doc-values-and-wildcard-searches/927 "2015-05-19T20:20:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![adamskikrzysiek](https://avatars.discourse-cdn.com/v4/letter/a/a6a055/32.png) [@adamskikrzysiek](https://discuss.elastic.co/u/adamskikrzysiek)\
**Post date:** [May 19, 2015, 8:20pm UTC](https://discuss.elastic.co/t/doc-values-and-wildcard-searches/927/1 "2015-05-19T20:20:40Z")

</div>

Hi,

Are wildcard searches supported on not\_analyzed strings with doc\_values enabled?  
I wasn't able to find any info on this in docs. It works just fine for an exact match.

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [May 19, 2015, 8:27pm UTC](https://discuss.elastic.co/t/doc-values-and-wildcard-searches/927/2 "2015-05-19T20:27:04Z")

</div>

Doc values are not relevant here since they are not used for searching, only sorting and aggregations. Wildcard searches are supported on not\_analyzed fields however.

---

<div class="post-metadata">

**Author:** ![adamskikrzysiek](https://avatars.discourse-cdn.com/v4/letter/a/a6a055/32.png) [@adamskikrzysiek](https://discuss.elastic.co/u/adamskikrzysiek)\
**Post date:** [May 20, 2015, 12:00pm UTC](https://discuss.elastic.co/t/doc-values-and-wildcard-searches/927/3 "2015-05-20T12:00:23Z")

</div>

Thanks for claryfication on doc values. You are saying they are supported on not\_analyzed strings. However...

```
      "requestClientApplication" : {
        "type" : "string",
        "index" : "not_analyzed",
        "doc_values" : true

```

}

exact match

```
 curl -XGET 'http://localhost:9200/proxylog/proxylog/_count' -d '
 {
     "query" : {
         "term" : { "requestClientApplication":"Mozilla"}
     }
 }'
{"count": **1615** ,"_shards":{"total":5,"successful":5,"failed":0}}

```

wildcard

```
curl -XGET 'http://localhost:9200/proxylog/proxylog/_count' -d '
{
    "query" : {
        "term" : { "requestClientApplication":"Mozill*"}
    }
}'
{"count": **0** ,"_shards":{"total":5,"successful":5,"failed":0}}

```

Elasticsearch 1.5.1

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [May 20, 2015, 12:15pm UTC](https://discuss.elastic.co/t/doc-values-and-wildcard-searches/927/4 "2015-05-20T12:15:22Z")

</div>

Your second query searches for a term that is exactly "Mozill\*" and does not exist in your index. You would need to use a wildcard query instead: [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-wildcard-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-wildcard-query.html)

---

<div class="post-metadata">

**Author:** ![adamskikrzysiek](https://avatars.discourse-cdn.com/v4/letter/a/a6a055/32.png) [@adamskikrzysiek](https://discuss.elastic.co/u/adamskikrzysiek)\
**Post date:** [May 20, 2015, 12:46pm UTC](https://discuss.elastic.co/t/doc-values-and-wildcard-searches/927/5 "2015-05-20T12:46:49Z")

</div>

Thanks. You are right. The problem is with kibana.  
It turned out I am affected by lowercase\_expanded\_terms. Looking for a way to bypass this.

> <https://github.com/elastic/elasticsearch/issues/9973>
>
> I am seeing inconsistent behavior with wildcard searches that makes no sense. I've created a Play to reproduce the issue I'm...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:13am UTC](https://discuss.elastic.co/t/doc-values-and-wildcard-searches/927/6 "2017-07-06T00:13:03Z")

</div>


