# Kibana alerting not matching wildcard AND condition

**URL:** <https://discuss.elastic.co/t/kibana-alerting-not-matching-wildcard-and-condition/256580>\
**Category:** Kibana\
**Created:** [November 24, 2020, 10:46pm UTC](https://discuss.elastic.co/t/kibana-alerting-not-matching-wildcard-and-condition/256580 "2020-11-24T22:46:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chris\_Clifton](https://avatars.discourse-cdn.com/v4/letter/c/82dd89/32.png) [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)\
**Post date:** [November 24, 2020, 10:46pm UTC](https://discuss.elastic.co/t/kibana-alerting-not-matching-wildcard-and-condition/256580/1 "2020-11-24T22:46:57Z")

</div>

Hi, trying to determine why a field isn't matching wildcard searches in our log data in Kibana alerting. We're on the elastic cloud stack, v7.9.2.  
We need to add an AND condition for this particular log search and with \* added for the NOT pmanqa text, the search is still matching log entries with awscloudwatch.logstream matching pmanqa\*. Wondering what we need to add (double quotes, escape or different wildcard matching?) so log entries with awscloudwatch.logstream matching pmanqa don't trigger this alert. Screen caps attached, thanks.

 ![kibana-alerts-pmanqa-AND-2](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f80e214995a01cd811686a2876b987a0c29087bf.png) ![kibana-alert-pmanqa-AND-condition](https://us1.discourse-cdn.com/elastic/original/3X/0/7/0783f863af4dda76297444e1299c045918619bc2.jpeg)

---

<div class="post-metadata">

**Author:** ![Kerry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kerry/32/40330_2.png) [@Kerry](https://discuss.elastic.co/u/Kerry)\
**Post date:** [November 26, 2020, 11:33am UTC](https://discuss.elastic.co/t/kibana-alerting-not-matching-wildcard-and-condition/256580/2 "2020-11-26T11:33:31Z")

</div>

Hi,

> the search is still matching log entries with awscloudwatch.logstream matching pmanqa\*. Wondering what we need to add (double quotes, escape or different wildcard matching?)

I expect the confusion here is arising from the expectation of wildcard functionality. This isn't currently supported but we do have a ticket here: https://github.com/elastic/kibana/issues/74130.

There is documentation [here](https://www.elastic.co/guide/en/observability/current/logs-threshold-alert.html#fields-comparators-logs) on which Elasticsearch query types map to which comparators.

There are also some example queries [here](https://www.elastic.co/guide/en/observability/current/logs-threshold-alert.html#es-queries) which show how alerts are translated into Elasticsearch queries. The queries do vary from Discover, so this can be useful to see.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2020, 11:33am UTC](https://discuss.elastic.co/t/kibana-alerting-not-matching-wildcard-and-condition/256580/3 "2020-12-24T11:33:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
