# Exclude/NOT Query or Filter With Wildcard

**URL:** <https://discuss.elastic.co/t/exclude-not-query-or-filter-with-wildcard/198782>\
**Category:** Kibana\
**Created:** [September 9, 2019, 8:24pm UTC](https://discuss.elastic.co/t/exclude-not-query-or-filter-with-wildcard/198782 "2019-09-09T20:24:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![TManson](https://avatars.discourse-cdn.com/v4/letter/t/a5b964/32.png) [@TManson](https://discuss.elastic.co/u/TManson)\
**Post date:** [September 9, 2019, 8:24pm UTC](https://discuss.elastic.co/t/exclude-not-query-or-filter-with-wildcard/198782/1 "2019-09-09T20:24:09Z")

</div>

I am trying to create a saved search that excludes certain root domains in DNS queries. For example, if I don't want to see any hits on any of Google's subdomains, I create a query like "NOT query: "\*.google.com." However, I can still see subdomains when this query is applied.

I have tried to edit the DSL myself in a few ways, but even if I create a query with the "Edit Filter" tool, and then go into the DSL and just add a "\*." to the beginning of the "query:" option, Kibana tells me there is an error (several errors). I did some research on DSL and tried to write a query from scratch like the below, and it blew up in the same fashion:

{  
"query": {  
"must\_not": {  
"query": "\*.google.com",  
"analyze\_wildcard": true  
}  
}  
}

The user in the following URL had a similar issue, but doesn't appear to have been able to resolve it.

> [@NOT filter using a wildcard](https://discuss.elastic.co/t/not-filter-using-a-wildcard/144184):
>
> Hello, I am unable to get what should be a simple filter in place to work. I have been researching the wildcard element in elasticsearch and grasp the concept when running a query. What I am unable to get working is a basic filter to exclude certain dns queries in our logs. See the basic logic below: NOT query \*.google.com Keep in mind, query in this sense is a field name as part of a dns request. Can someone please help?

I am running 6.7.2 at the moment. Does anyone see an obvious flaw in what I'm doing?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 10, 2019, 5:58am UTC](https://discuss.elastic.co/t/exclude-not-query-or-filter-with-wildcard/198782/2 "2019-09-10T05:58:19Z")

</div>

Leading wildcard query is one of the most inefficient, if not THE most inefficient, query you can write in Elasticsearch, so is likely to scale and perform badly. I would instead recommend extracting and storing the domain in a separate field at index time and instead filter on this as this will be MUCH more efficient.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2019, 5:58am UTC](https://discuss.elastic.co/t/exclude-not-query-or-filter-with-wildcard/198782/3 "2019-10-08T05:58:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
