# Elasticsearch Query

**URL:** <https://discuss.elastic.co/t/elasticsearch-query/347768>\
**Category:** Elasticsearch\
**Tags:** eql-elastic-query-language\
**Created:** [November 22, 2023, 4:32pm UTC](https://discuss.elastic.co/t/elasticsearch-query/347768 "2023-11-22T16:32:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Brian-cf1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Post date:** [November 22, 2023, 4:32pm UTC](https://discuss.elastic.co/t/elasticsearch-query/347768/1 "2023-11-22T16:32:43Z")

</div>

How do i exclude multiple keywords from a field ?

I need the following logic but its not letting me include 2 wild cards

```auto
      "must_not": [
        {
           "wildcard": {
      "error.message": {
        "value": "*headers*"
      }
    },
           "wildcard": {
      "error.message": {
        "value": "*refused*"
      }
    }

```

Code currently at

```auto

"query": {
    
    "bool": {
      "must": [
        {
          "term": {
            "monitor.status": {
              "value": "down"
            }
          }
        }
      ],
      "must_not": [
        {
           "wildcard": {
      "error.message": {
        "value": "*headers*"
      }
    }
        }
      ], 
      "filter": [
        {
        
          "range": {
            "@timestamp": {
              "from": "now-7d"
            }
          }
        }
      ]
    }
  },

```

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [November 23, 2023, 10:23am UTC](https://discuss.elastic.co/t/elasticsearch-query/347768/2 "2023-11-23T10:23:25Z")

</div>

Hi @Brian-cf1,

Which version of Elasticsearch are you using? Are you receiving a particular error in your prior query.

I managed to get the below working on 8.11:

```auto
GET test_index/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "term": {
            "monitor.status": {
              "value": "down"
            }
          }
        }
      ],
      "must_not": [
        {
          "wildcard": {
            "error.message": {
              "value": "*headers*"
            }
          }
        },
        {
          "wildcard": {
            "error.message": {
              "value": "*refused*"
            }
          }
        }
      ],
      "filter": [
        {
          "range": {
            "@timestamp": {
              "from": "now-7d"
            }
          }
        }
      ]
    }
  }
}

```

Just be wary when using wildcard queries starting with `*` are not recommended as they can slow your query down, [as covered in the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/query-dsl-wildcard-query.html).

---

<div class="post-metadata">

**Author:** ![Brian-cf1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Post date:** [November 30, 2023, 2:31pm UTC](https://discuss.elastic.co/t/elasticsearch-query/347768/3 "2023-11-30T14:31:28Z")

</div>

This is how i found to exclude multiple strings

```auto
GET heartbeat-*/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "term": {
            "monitor.status": {
              "value": "down"
            }
          }
        }
      ],
      "must_not": [
           {
          "query_string" : {
            "query" : "**refused* OR *header* OR *timeout* OR *missing* OR *401*",
            "default_field" : "error.message"
          }
           }
        ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Brian-cf1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Post date:** [November 30, 2023, 2:41pm UTC](https://discuss.elastic.co/t/elasticsearch-query/347768/4 "2023-11-30T14:41:57Z")

</div>

> [@carly.richmond](#):
>
> n using wildca

I was on 7.17 , maybe thats why it didnt work, it said duplicate wildcard fields , but i found a way!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2023, 2:42pm UTC](https://discuss.elastic.co/t/elasticsearch-query/347768/5 "2023-12-28T14:42:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
