# Filtering documents in kibana by prefix - inconsistent results

**URL:** <https://discuss.elastic.co/t/filtering-documents-in-kibana-by-prefix-inconsistent-results/36332>\
**Category:** Kibana\
**Created:** [December 4, 2015, 12:46am UTC](https://discuss.elastic.co/t/filtering-documents-in-kibana-by-prefix-inconsistent-results/36332 "2015-12-04T00:46:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fritz](https://avatars.discourse-cdn.com/v4/letter/f/c57346/32.png) [@Fritz](https://discuss.elastic.co/u/Fritz)\
**Post date:** [December 4, 2015, 12:46am UTC](https://discuss.elastic.co/t/filtering-documents-in-kibana-by-prefix-inconsistent-results/36332/1 "2015-12-04T00:46:56Z")

</div>

Hi folks,

I'm playing with building some Kibana dashboards and I noticed a peculiar behavior - when I try to filter documents by very simple prefix queries involving one string field (i.e. field:value\*) some fields can be queried this way, others return no results.  
All queries work if I try to filter by an actual full field value, i.e. field1:value or field2:somestring  
For some fields I get the expected results when I run a prefix query, i.e. field1:val\*  
For other fields I get nothing, i.e. field2:some\* returns no results even as field2:something returns results

The frustrating part is that I haven't been able to figure out what the difference is between the those fields that makes them behave differently. All fields are strings, they are not analyzed and the \_all field is disabled. Prefix queries with similar intent using the Elasticsearch query language on the source data always work as expected.

Any ideas?

Thanks  
Fritz

---

<div class="post-metadata">

**Author:** ![Fritz](https://avatars.discourse-cdn.com/v4/letter/f/c57346/32.png) [@Fritz](https://discuss.elastic.co/u/Fritz)\
**Post date:** [December 4, 2015, 5:40pm UTC](https://discuss.elastic.co/t/filtering-documents-in-kibana-by-prefix-inconsistent-results/36332/2 "2015-12-04T17:40:48Z")

</div>

I figured out what's causing the wildcard queries to break - it's the uppercase letters in the query pattern.

For a field "field" with a value "string\_a", a query like field:strin\* will return results.  
For a value of "strING\_a" (capitalized "ING") the query field:str\* will return results, but the query field:strING\* will return no results. Neither will field:string\*.  
Basically, it looks like only lowercase characters can match each other in the query string and in the value. \* will match any lowercase or uppercase characters, but uppercase characters don't match each other, and a lowercase and uppercase character don't match each other either. Again, this is only in the Lucene flavor used by Kibana queries; Elasticsearch queries do not have this problem.

I found some other questions about this behavior online, but with no answers.  
I don't know what the motivation behind implementing such a behavior was (I assume there's got to be an important technical limitation involved), but to anyone like me who comes from a traditional programming background this is mind-boggling and terribly unintuitive - for the life of me I didn't want to believe that an uppercase character does not match itself.

Are there any workarounds (besides making sure all values you want to use in wildcard queries are lowercase)?

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [December 9, 2015, 4:50am UTC](https://discuss.elastic.co/t/filtering-documents-in-kibana-by-prefix-inconsistent-results/36332/3 "2015-12-09T04:50:20Z")

</div>

Kibana simply passes the query to Elasticsearch, so the issue here is the [Lucene query syntax](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html) and how the [standard analyzer](https://www.elastic.co/guide/en/elasticsearch/reference/1.4/analysis-standard-analyzer.html) within Elasticsearch behaves. By default, all tokens are converted to lower-case, so this is why your upper-case letters fail in queries. You can tweak this by setting "lowercase\_expanded\_terms" to false or using something other than a standard analyzer.

---

<div class="post-metadata">

**Author:** ![Fritz](https://avatars.discourse-cdn.com/v4/letter/f/c57346/32.png) [@Fritz](https://discuss.elastic.co/u/Fritz)\
**Post date:** [December 9, 2015, 6:03pm UTC](https://discuss.elastic.co/t/filtering-documents-in-kibana-by-prefix-inconsistent-results/36332/4 "2015-12-09T18:03:13Z")

</div>

Thanks for following up. Indeed the Lucene query is the issue here. I knew that tokens are lower-cased, however, the surprise was that even if I express the query using lowercase, the match still does not succeed.  
I.e. - for a value "strING\_a" the query "str\*" succeeds, the query "strING\*" fails, but the query "string\*" also fails. If values were tokenized lowercase shouldn't the last query succeed?

Just to close on a potential solution I was looking at - making the prefix of the string value I was going to search for all lowercase solved the problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:06pm UTC](https://discuss.elastic.co/t/filtering-documents-in-kibana-by-prefix-inconsistent-results/36332/5 "2017-07-06T14:06:55Z")

</div>


