# Kibana partial/substring matches are not working

**URL:** <https://discuss.elastic.co/t/kibana-partial-substring-matches-are-not-working/245844>\
**Category:** Kibana\
**Created:** [August 21, 2020, 2:59am UTC](https://discuss.elastic.co/t/kibana-partial-substring-matches-are-not-working/245844 "2020-08-21T02:59:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rakesh\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_b/32/48128_2.png) [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Post date:** [August 21, 2020, 2:59am UTC](https://discuss.elastic.co/t/kibana-partial-substring-matches-are-not-working/245844/1 "2020-08-21T02:59:16Z")

</div>

Hi,

Setup: `Elasticsearch version 7.6.1`  
field name is log, here is the config in index template:

```auto
        "log": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },

```

1. Partial match doesn't work in KQL and Lucene:  

2. Another question:  
It works if I put a wildcard like this in both KQL and Lucene `log: *RedisConnectionFailureException` but when put double quotes it doesn't work even with a wildcard 

 ![Screen Shot 2020-08-20 at 7.52.24 PM](https://us1.discourse-cdn.com/elastic/original/3X/d/b/dbcb003f539340ad4ca11960d3540e8bc99d4b15.png)

We are trying to do a partial/substring search in Kibana UI but we are not getting any results, it seems to works only with wildcard expressions. Can you please tell us how to enable it OR let us know if we are doing anything wrong?

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [August 24, 2020, 4:28pm UTC](https://discuss.elastic.co/t/kibana-partial-substring-matches-are-not-working/245844/2 "2020-08-24T16:28:08Z")

</div>

I can help you with the syntax and general understanding of what is happening with these queries.

1. It looks like you're expecting partial matches on substrings without whitespace. This is not the default behavior of Elasticsearch, and you need to implement a different [text analysis](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis.html) configuration to get this without wildcards.

2. Wildcards work the way you'd expect, which is that if you have a single token like ` **Production** RedisConnectionFailureException`, then a wildcard can match the missing prefix like `*RedisConnectionFailureException`.

You have already figured out the correct syntax for wildcards. The syntax you used in the last example, without double quotes, is correct for [KQL](https://www.elastic.co/guide/en/kibana/current/kuery-query.html).

I notice that you are multi-mapping this field, so you have both `log` and `log.keyword` fields, but you aren't searching `log.keyword`. You may want to read up on [mapping options](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2020, 4:28pm UTC](https://discuss.elastic.co/t/kibana-partial-substring-matches-are-not-working/245844/3 "2020-09-21T16:28:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
