# KQL Query with wildcard and space not working (with wildcard type)

**URL:** <https://discuss.elastic.co/t/kql-query-with-wildcard-and-space-not-working-with-wildcard-type/267237>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [March 15, 2021, 9:23am UTC](https://discuss.elastic.co/t/kql-query-with-wildcard-and-space-not-working-with-wildcard-type/267237 "2021-03-15T09:23:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sebastien\_Taniere](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastien_taniere/32/59265_2.png) [@Sebastien\_Taniere](https://discuss.elastic.co/u/Sebastien_Taniere)\
**Post date:** [March 15, 2021, 9:23am UTC](https://discuss.elastic.co/t/kql-query-with-wildcard-and-space-not-working-with-wildcard-type/267237/1 "2021-03-15T09:23:01Z")

</div>

Hello,  
I used a wildcard field in my index mapping in order to be able to use wilcard in my logs.

Now, I try to select some lines in my logs which begins with "Request finished"

1. message:Request\*  
it is working but there are too much results for me

2. message:Request finished\* or message:"Request finished\*" or message:Request finished or message:Request?finished\*  
=\> expand your time range... 😢

3. message:Request\ finished\*  
the only way I find is to deactivating KQL and using this Lucene syntax

Do you see a way to search it easilly trought KQL ? 🧐

Exemple of message I want to match :

> Request finished HTTP/1.1 GET [http://staging-wmsdevplatform.fmlogistic.fr:5000/api/Size/GetSupportQuantity?activityCode=SDO&depositCode=ECR&supportNumber=336042896110201330](http://staging-wmsdevplatform.fmlogistic.fr:5000/api/Size/GetSupportQuantity?activityCode=SDO&depositCode=ECR&supportNumber=336042896110201330) application/json - - 404 0 - 17.1080ms

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [March 16, 2021, 11:41pm UTC](https://discuss.elastic.co/t/kql-query-with-wildcard-and-space-not-working-with-wildcard-type/267237/2 "2021-03-16T23:41:07Z")

</div>

I found KQL not to work well with wildcards. Never managed to make it work as I expect it.  
I use query DSL (filter)?

```auto
{
  "query": {
    "wildcard": {
      "message": {
        "value": "ki*y",
        "boost": 1.0,
        "rewrite": "constant_score"
      }
    }
  }
}

```

> **[Wildcard query | Elasticsearch Reference \[7.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-wildcard-query.html)**

Another option is a scripted field.  
If you can create another field pre-indexing, that is even better.

---

<div class="post-metadata">

**Author:** ![Sebastien\_Taniere](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastien_taniere/32/59265_2.png) [@Sebastien\_Taniere](https://discuss.elastic.co/u/Sebastien_Taniere)\
**Post date:** [March 22, 2021, 2:00pm UTC](https://discuss.elastic.co/t/kql-query-with-wildcard-and-space-not-working-with-wildcard-type/267237/3 "2021-03-22T14:00:08Z")

</div>

Thank you for your answer AClerk,

the fact is that I searched for a KQL syntax in order to use it easilly trough kibana.  
My team will not use any \_query api but only kibana querybar

Perhaps I will change elastic mapping and transform my field :

> ```
> "message": {
> "type": "wildcard"
> },
> 
> ```

into

> ```
> "message" : {
> "type" : "text",
> "fields" : {
> "keyword" : {
> "ignore_above" : 256,
> "type" : "keyword"
> }
> }
> }
> 
> ```

But I does not achieve to find which impact it will have on my data in term of search performance & database size

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [March 22, 2021, 11:57pm UTC](https://discuss.elastic.co/t/kql-query-with-wildcard-and-space-not-working-with-wildcard-type/267237/4 "2021-03-22T23:57:29Z")

</div>

> [@Sebastien\_Taniere](#):
>
> My team will not use any \_query api but only kibana querybar

You can predefine a filter and your team can just enable/disable it.

I am not sure of the impact to your cluster after the change.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 11:58pm UTC](https://discuss.elastic.co/t/kql-query-with-wildcard-and-space-not-working-with-wildcard-type/267237/5 "2021-04-19T23:58:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
