# Looking for way to search for wildcard with space characters. Does KQL have character escaping?

**URL:** <https://discuss.elastic.co/t/looking-for-way-to-search-for-wildcard-with-space-characters-does-kql-have-character-escaping/309250>\
**Category:** Kibana\
**Created:** [July 9, 2022, 1:57pm UTC](https://discuss.elastic.co/t/looking-for-way-to-search-for-wildcard-with-space-characters-does-kql-have-character-escaping/309250 "2022-07-09T13:57:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![megaksa](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@megaksa](https://discuss.elastic.co/u/megaksa)\
**Post date:** [July 9, 2022, 1:57pm UTC](https://discuss.elastic.co/t/looking-for-way-to-search-for-wildcard-with-space-characters-does-kql-have-character-escaping/309250/1 "2022-07-09T13:57:50Z")

</div>

Basically, I have log strings that I wanted to keep as a wildcard type to be able to search for exact substrings with either wildcard query `*abc*` or with regex `/.*abc.*/`. The problem is that ` Observability → Logs` doesn't support Lucene, and KQL doesn't seem to support character escaping. So to search e.g. for phrase "first iteration" I either has to user Discover and search for `*first\ iteration*` or for `/.*first iteration.*/`  
As a side note: it would be way more convenient if there was an option to invert regex anchoring. I.e. to add `.*` to the side if it is not present, and to remove if `.*` is present. Most of the search strings over wildcard `message` field are done like `*some\ stuff*` right now. Exact search for `"some stuff"` substring would be very convenient.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2022, 1:58pm UTC](https://discuss.elastic.co/t/looking-for-way-to-search-for-wildcard-with-space-characters-does-kql-have-character-escaping/309250/2 "2022-08-06T13:58:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
