# No results found / wildcard via Query Bar

**URL:** <https://discuss.elastic.co/t/no-results-found-wildcard-via-query-bar/117275>\
**Category:** Kibana\
**Created:** [January 26, 2018, 10:52pm UTC](https://discuss.elastic.co/t/no-results-found-wildcard-via-query-bar/117275 "2018-01-26T22:52:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 26, 2018, 10:52pm UTC](https://discuss.elastic.co/t/no-results-found-wildcard-via-query-bar/117275/1 "2018-01-26T22:52:30Z")

</div>

I'm using Query bar (at the top of Kibana) to search like this:

> bin: 123456\*

I get a lot of hits, however when I add filter; `bin` -\> `is` -\> `123456*`, I get `0` hits (No results found), `bin` field contains 6 OR 7 numbers and I'd like to include 6 AND 7 numbers results into my filter.

Please advise.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [January 26, 2018, 11:15pm UTC](https://discuss.elastic.co/t/no-results-found-wildcard-via-query-bar/117275/2 "2018-01-26T23:15:34Z")

</div>

I'm confused if you're putting `bin -> is -> 123456*` in the query bar just like that?

If `bin` is a number data type, you could just do `bin:>123456` and it would get results that are greater than that.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 27, 2018, 1:02am UTC](https://discuss.elastic.co/t/no-results-found-wildcard-via-query-bar/117275/3 "2018-01-27T01:02:58Z")

</div>

I apologize for confusion, let me try to put it in a different way:

search #1:

- I put `bin: 123456*` into Query Bar - got plenty of results

search #2:

- I tried to create a filter to accomplish same as method #1 by `Add a filter` (_UNDER_ Query Bar), then in `Filter` drop down select `bin` followed by `is` as operator and for value I entered `123456*` and got no results.

* * *

`bin` field is a keyword type field that contains following bins: 123456, 1234560, 1234561, 1234562 ... 1234569 (in different documents of course) and I'd like to capture all of them without specifying each (using operator `is one of`).

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [January 29, 2018, 8:29pm UTC](https://discuss.elastic.co/t/no-results-found-wildcard-via-query-bar/117275/4 "2018-01-29T20:29:23Z")

</div>

When you select a keyword to filter on, Kibana tries to give you a list of keywords to select from and then creates a query to match phrase. Apparently you can still edit it and add a wildcard.

```auto
{
  "query": {
    "match": {
      "extension.raw": {
        "query": "jpg",
        "type": "phrase"
      }
    }
  }
}

```

But according to this page, (go to the very bottom of the page in the box) you can't use wildcards in a phrase match query.  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-match-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-match-query.html)  
Actually, you can use wildcards but they're either ignored completely or they are trying to match the literal string `123456*` with an asterisk in it.

Compare that with the query you get if you put the query in the query bar;

```auto
"query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "query": "extension:jp*",
            "analyze_wildcard": true,
            "default_field": "*"
          }
        },
    },

```

So you could edit the filter and change from the phase query to a regular query so that wildcards are used.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 31, 2018, 5:41pm UTC](https://discuss.elastic.co/t/no-results-found-wildcard-via-query-bar/117275/5 "2018-01-31T17:41:37Z")

</div>

I couldn't get wildcard to work through Query bar and if I understand correctly, it's simply not possible to do (to me, wildcard is "a must", apparently not).

however, maybe [Query String Query | Elasticsearch Reference | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#_wildcards) is an answer?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2018, 5:41pm UTC](https://discuss.elastic.co/t/no-results-found-wildcard-via-query-bar/117275/6 "2018-02-28T17:41:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
