# Field names starting with \`\_\`(underscore) are not matched with \* wildcard

**URL:** <https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254>\
**Category:** Elasticsearch\
**Created:** [February 27, 2020, 2:26pm UTC](https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254 "2020-02-27T14:26:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hexer338](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hexer338/32/47413_2.png) [@hexer338](https://discuss.elastic.co/u/hexer338)\
**Post date:** [February 27, 2020, 2:26pm UTC](https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254/1 "2020-02-27T14:26:30Z")

</div>

Hi,

`*` wildcard does not match fields starting with `_` in the query\_string query.

Example:

Create Index with simple mapping:

```auto
{
    "mappings": {
        "properties": {
            "_a": {
                "type": "keyword"
            }
        }
    }
}

```

When query:

```auto
{
   "query": {
      "query_string": {
         "query": "value",
         "fields": [
            "*"
         ]
      }
   }
}

```

It does not match the document. However this query works:

```auto
{
   "query": {
      "query_string": {
         "query": "value",
         "fields": [
            "_*"
         ]
      }
   }
}

```

Is this behavior expected ?  
I didn't find any documentation to avoid field names starting with `_`.

Thanks,  
Ravi Teja Meka

---

<div class="post-metadata">

**Author:** ![hexer338](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hexer338/32/47413_2.png) [@hexer338](https://discuss.elastic.co/u/hexer338)\
**Post date:** [March 2, 2020, 6:39am UTC](https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254/2 "2020-03-02T06:39:49Z")

</div>

Hi, As per documentation for `default_field` in `query_string` query (Ref: [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html)):

```auto
Defaults to the index.query.default_field index setting, which has a default value of *. The * value extracts all fields that are eligible to term queries and filters the metadata fields. All extracted fields are then combined to build a query if no prefix is specified.

```

And by this:

```auto
https://github.com/elastic/elasticsearch/blob/e0b3ea041671e7600e8a1b76491f91041940a386/server/src/main/java/org/elasticsearch/index/search/QueryParserHelper.java#L148

```

Does this mean that fields starting with `_` are considered as metadata fields ?

Should Users not index fields starting with `_` ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 2, 2020, 6:54am UTC](https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254/3 "2020-03-02T06:54:34Z")

</div>

We are using indeed \_ prefix for metadata fields like `_index`, `_id`, ...

So I'd not use this prefix.

---

<div class="post-metadata">

**Author:** ![hexer338](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hexer338/32/47413_2.png) [@hexer338](https://discuss.elastic.co/u/hexer338)\
**Post date:** [March 2, 2020, 8:56am UTC](https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254/4 "2020-03-02T08:56:30Z")

</div>

Thanks @dadoonet .  
But for our use case, it seems it is unavoidable to index field names starting with underscore.

As alternate approach, we are thinking to wrap all the user defined fields in a top-level `object` field. Like:

```auto
PUT sample_index
{
    "mappings": {
        "properties": {
            "user_defined": {
                "type": "object",
                "properties": {
                    "_a": {
                        "type": "date"
                    },
                    "_b": {
                        "type": "keyword"
                    }
                }
            }
        }
    }
}

```

I see that `user_defined.*` is matching `_` prefix fields also.

```auto
{
   "query": {
      "query_string": {
         "query": "value",
         "lenient": true,
         "fields": [
            "user_defined.*"
         ]
      }
   }
}

```

Do you think we can go ahead with this approach?  
Do you see any query/index related limitations ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 2, 2020, 9:18am UTC](https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254/5 "2020-03-02T09:18:36Z")

</div>

> [@hexer338](#):
>
> But for our use case, it seems it is unavoidable to index field names starting with underscore.

Why this?

Another approach could be using the ingest rename processor to rename at index time your field names if there is no solution to control this from your application...

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 2, 2020, 9:18am UTC](https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254/6 "2020-03-02T09:18:56Z")

</div>

> [@hexer338](#):
>
> Do you think we can go ahead with this approach?  
> Do you see any query/index related limitations ?

That could work indeed.

---

<div class="post-metadata">

**Author:** ![hexer338](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hexer338/32/47413_2.png) [@hexer338](https://discuss.elastic.co/u/hexer338)\
**Post date:** [March 2, 2020, 9:30am UTC](https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254/7 "2020-03-02T09:30:49Z")

</div>

Thanks !  
In our application, we allow users to define any field name starting with an alphabet. And due to application constraints we can only use `_` prefix fields as application's generated/calculated fields.  
And these fields should participate in full text search.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2020, 9:30am UTC](https://discuss.elastic.co/t/field-names-starting-with-underscore-are-not-matched-with-wildcard/221254/8 "2020-03-30T09:30:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
