# Kibana 3 - Wildcard query with key/value pair

**URL:** <https://discuss.elastic.co/t/kibana-3-wildcard-query-with-key-value-pair/1426>\
**Category:** Kibana\
**Created:** [May 27, 2015, 9:24pm UTC](https://discuss.elastic.co/t/kibana-3-wildcard-query-with-key-value-pair/1426 "2015-05-27T21:24:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![brianorwig](https://avatars.discourse-cdn.com/v4/letter/b/ce7236/32.png) [@brianorwig](https://discuss.elastic.co/u/brianorwig)\
**Post date:** [May 27, 2015, 9:24pm UTC](https://discuss.elastic.co/t/kibana-3-wildcard-query-with-key-value-pair/1426/1 "2015-05-27T21:24:25Z")

</div>

I have a log file that contains a message field that contains XML data in it.

```
message=<XML......>

```

I am trying to do a wildcard search within that data for a key/value pair (key="value") and I am having some issues. We don't want to index all of the data in the XML data, but there is often a case where we need to search for specific data within the XML.

I started with this:

```
message:*key="value"*

```

This will return anything that matches key or value, but not both together. So I get way more results than I want.

I tried putting it into a regex:

```
message:*(key)\s?=\s*("value"|'value')*

```

So right now the only way I have been able to come close is with something like this:

```
message:*value* AND message:*key*

```

However this will still return other entries that do not match exactly what I want. For example if the following were present it would be returned as a match

```
  foo=value
  key=bar

```

Thanks for any help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:18pm UTC](https://discuss.elastic.co/t/kibana-3-wildcard-query-with-key-value-pair/1426/2 "2017-07-06T14:18:58Z")

</div>


