# Kibana Search Query Syntax wildcard wierdness

**URL:** <https://discuss.elastic.co/t/kibana-search-query-syntax-wildcard-wierdness/34622>\
**Category:** Kibana\
**Created:** [November 15, 2015, 5:41pm UTC](https://discuss.elastic.co/t/kibana-search-query-syntax-wildcard-wierdness/34622 "2015-11-15T17:41:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![TodayandTomorrow](https://avatars.discourse-cdn.com/v4/letter/t/9dc877/32.png) [@TodayandTomorrow](https://discuss.elastic.co/u/TodayandTomorrow)\
**Post date:** [November 15, 2015, 5:41pm UTC](https://discuss.elastic.co/t/kibana-search-query-syntax-wildcard-wierdness/34622/1 "2015-11-15T17:41:26Z")

</div>

I have a document that has the variable name "name". One document has name:"Subject.doc" if I search using name: Subject\* I do not get the document returned but if I search name:"_ubject_doc I get the document returned.

Also if I search without specifying the "name" field using "Subject\*" the document is returned.

Anyone know why this is the case?

Document:  
{  
"\_index": "_snip_",  
"\_type": "sample",  
"\_id": "AVEIvh2i8JHC1nGQQ41E",  
"\_score": null,  
"\_source": {  
"name": "Subject.doc",  
_snip_  
}

Mapping:  
"name": {"type": "string", "index": "not\_analyzed", "stored": True, "doc\_values": "True"}

Kibana 4.1.1  
Build 7489

Elasticsearch v1.7.1:  
"version" : {  
"number" : "1.7.1",  
"build\_hash" : "b88f43fc40b0bcd7f173a1f9ee2e97816de80b19",  
"build\_timestamp" : "2015-07-29T09:54:16Z",  
"build\_snapshot" : false,  
"lucene\_version" : "4.10.4"

---

<div class="post-metadata">

**Author:** ![GlenRSmith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glenrsmith/32/44925_2.png) [@GlenRSmith](https://discuss.elastic.co/u/GlenRSmith)\
**Post date:** [November 15, 2015, 6:49pm UTC](https://discuss.elastic.co/t/kibana-search-query-syntax-wildcard-wierdness/34622/2 "2015-11-15T18:49:46Z")

</div>

I believe what's happening here is that Kibana is performing a [query string query](https://www.elastic.co/guide/en/elasticsearch/reference/1.7/query-dsl-query-string-query.html#_wildcards), and, with a wildcard:

> Wildcarded terms are not analyzed by default — they are lowercased (lowercase\_expanded\_terms defaults to true) but no further analysis is done, mainly because it is impossible to accurately analyze a word that is missing some of its letters.

Hence, when you provide the search string `Subject*`, the documents are scanned for "name" field values that begin with "subject", followed by anything, and that doesn't actually match the sample documents. However, when you provide the search string `*ubject*doc`, the scan is for "name" field values that have the exact substring "ubject" preceded by anything (which could be "s", "S", or anything else), followed by anything, and ending with the substring "doc". This evaluation _does_ match the "Subject.doc" string in your sample doc.

As noted in the documentation, you can set `lowercase_expanded_terms` to false, and that should make your first search match.

---

<div class="post-metadata">

**Author:** ![TodayandTomorrow](https://avatars.discourse-cdn.com/v4/letter/t/9dc877/32.png) [@TodayandTomorrow](https://discuss.elastic.co/u/TodayandTomorrow)\
**Post date:** [November 15, 2015, 6:53pm UTC](https://discuss.elastic.co/t/kibana-search-query-syntax-wildcard-wierdness/34622/3 "2015-11-15T18:53:17Z")

</div>

Thank you this is what is happening!

I changed "query:queryString:options" in Kibana settings to include "lowercase\_expanded\_terms" set to True and it works as I initially thought it should and name: Subject\* returns the document. Now "query:queryString:options" is "{ "analyze\_wildcard": true, "lowercase\_expanded\_terms": false }"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:09pm UTC](https://discuss.elastic.co/t/kibana-search-query-syntax-wildcard-wierdness/34622/4 "2017-07-06T14:09:02Z")

</div>


