# How to filter a specific field and how to filter on a wildcard field such as \`/cars/\*\`?

**URL:** <https://discuss.elastic.co/t/how-to-filter-a-specific-field-and-how-to-filter-on-a-wildcard-field-such-as-cars/53249>\
**Category:** Elasticsearch\
**Created:** [June 19, 2016, 10:19pm UTC](https://discuss.elastic.co/t/how-to-filter-a-specific-field-and-how-to-filter-on-a-wildcard-field-such-as-cars/53249 "2016-06-19T22:19:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fikse](https://avatars.discourse-cdn.com/v4/letter/f/c0e974/32.png) [@fikse](https://discuss.elastic.co/u/fikse)\
**Post date:** [June 19, 2016, 10:19pm UTC](https://discuss.elastic.co/t/how-to-filter-a-specific-field-and-how-to-filter-on-a-wildcard-field-such-as-cars/53249/1 "2016-06-19T22:19:17Z")

</div>

I have this index:

```auto
{
  "_index": "logstash-2015.12.15",
  "_type": "logs",
  "_id": "AVVVW_wekW28kZ0eUiUh",
  "_version": 1,
  "_score": 1,
  "_source": {
    "message": "127.0.0.1 - - [15/Dec/2015:18:50:15 -0500] "GET /cars/123 HTTP/1.1" 200 172 "-" "-"",
    "@version": "1",
    "@timestamp": "2015-12-15T23:50:15.000Z",
    "type": "log",
    "host": "abc123.local",
    "remote_ip": "127.0.0.1",
    "user_name": "-",
    "time": "15/Dec/2015:18:50:15 -0500",
    "request_action": "GET",
    "request": "/cars/123",
    "http_version": "1.1",
    "response": "502",
    "bytes": "172",
    "referrer": "-",
    "agent": "-",
    "user_agent": {
      "name": "Other",
      "os": "Other",
      "os_name": "Other",
      "device": "Other"
    }
  }
}

```

I am using the elasticsearch javascript client, and I'm trying to search for all instances of requests to `/cars`, but first I'm trying to match the index above before trying to match all:

```auto
    es.search({
      analyzeWildcard: true,
      index: 'logstash-*',
      type: 'log',
      body: {
        query: {
          bool: {
            must: [
              { match: { request_action: "GET" } }
            ],
            filter: [
              { term: { request: "/cars/123" } }
            ]
          }
        }
      }
    }).then(function(results) {
      debugger;

```

Here's what I get:

```auto
> results
{ took: 47,
  timed_out: false,
  _shards: { total: 740, successful: 740, failed: 0 },
  hits: { total: 0, max_score: null, hits: [] } }

```

I even tried this:

```auto
  // first example query
  es.search({
    index: 'logstash-*',
    q: "request:cars"
  })

```

and this:

```auto
  // second example query
  es.search({
    index: 'logstash-*',
    q: "request:cars/123"
  })

```

These queries do return results, however, they are weighted results:

```auto
{ took: 30,
  timed_out: false,
  _shards: { total: 740, successful: 740, failed: 0 },
  hits:
   { total: 26,
     max_score: 3.6100698,
     hits:
      [[Object],
        [Object],
        [Object],
        [Object],
        [Object],
        [Object],
        [Object],
        [Object],
        [Object],
        [Object] ] } }

```

The request field has a mapping type of `not_analyzed`. How do I query for a specific field and then how would I query for something like `/cars/*`?

---

<div class="post-metadata">

**Author:** ![mainec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mainec/32/5557_2.png) [@mainec](https://discuss.elastic.co/u/mainec)\
**Post date:** [June 20, 2016, 8:02am UTC](https://discuss.elastic.co/t/how-to-filter-a-specific-field-and-how-to-filter-on-a-wildcard-field-such-as-cars/53249/2 "2016-06-20T08:02:53Z")

</div>

First off: I'm not sure what's going wrong in your term query. As for the rest of the question:

> [@fikse](#):
>
> how would I query for something like /cars/\*?

For something like this you'd need a wildcard query: [Wildcard query | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-wildcard-query.html)

Also what ES version are you running? Queries and filters have been merged, see here: [Better query execution coming to Elasticsearch 2.0 | Elastic Blog](https://www.elastic.co/blog/better-query-execution-coming-elasticsearch-2-0)

Hope this helps,  
Isabel

---

<div class="post-metadata">

**Author:** ![fikse](https://avatars.discourse-cdn.com/v4/letter/f/c0e974/32.png) [@fikse](https://discuss.elastic.co/u/fikse)\
**Post date:** [June 20, 2016, 4:27pm UTC](https://discuss.elastic.co/t/how-to-filter-a-specific-field-and-how-to-filter-on-a-wildcard-field-such-as-cars/53249/3 "2016-06-20T16:27:33Z")

</div>

Hi Isabel, thank you for responding.  
I'm using elasticsearch 2.3.3, and I can't seem to filter out only the results I want. I've been trying and trying, and I've even simplified the queries to start looking for requests to `/robots.txt` but I only get similar matches, not actual matches.

The requests now look like this:

```auto
body = new Bodybuilder().query('match', 'request_action', 'GET')
                        .filter('term', 'request', '/robots.txt')
                        .aggregation('terms', 'request')
                        .build()
es.search(body)

```

---

<div class="post-metadata">

**Author:** ![fikse](https://avatars.discourse-cdn.com/v4/letter/f/c0e974/32.png) [@fikse](https://discuss.elastic.co/u/fikse)\
**Post date:** [June 20, 2016, 4:46pm UTC](https://discuss.elastic.co/t/how-to-filter-a-specific-field-and-how-to-filter-on-a-wildcard-field-such-as-cars/53249/4 "2016-06-20T16:46:02Z")

</div>

@mainec I figured out the issue:  
The type was `logs` not `log`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:42pm UTC](https://discuss.elastic.co/t/how-to-filter-a-specific-field-and-how-to-filter-on-a-wildcard-field-such-as-cars/53249/5 "2017-07-05T22:42:08Z")

</div>


