# Problem in Elasticsearch Wildcard filtered Query

**URL:** https://discuss.elastic.co/t/problem-in-elasticsearch-wildcard-filtered-query/96718
**Category:** Elasticsearch
**Created:** [August 11, 2017, 7:35am UTC](https://discuss.elastic.co/t/problem-in-elasticsearch-wildcard-filtered-query/96718 "2017-08-11T07:35:40Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![shaktigupta200](https://avatars.discourse-cdn.com/v4/letter/s/b4bc9f/32.png) [@shaktigupta200](https://discuss.elastic.co/u/shaktigupta200)
#### Post date: [August 11, 2017, 7:35am UTC](https://discuss.elastic.co/t/problem-in-elasticsearch-wildcard-filtered-query/96718/1 "2017-08-11T07:35:41Z")

</div>

Hi all,

I am trying to write elasticsearch wildcard filtered query for aggregation and below is what I have written. It is working fine but taking so long sometime more than a minute. But if I am searching through kibana results are coming instantly within few seconds. Also CPU load on data node gets higher when running the elastic query but not happening with kibana search.

Elasticsearch query-  
{  
"query": {  
"bool" : {  
"must" : [  
{ "wildcard" : { "request\_url.raw" : "_server_status\*" } }  
,{ "range" : { "@timestamp" : { "from" : "now-1800s", "to" : "now-0s" } } }  
]  
}  
},  
"aggs" : {  
"level" : {  
"terms" : {  
"field" : "response",  
"size" : 300000  
}  
}  
}  
}

Kibana Query:  
_request\_url.raw : serverstatus\*_

Is there a way I can optimize elasticsearch this query like kibana using in background?

---

<div class="post-metadata">

### Author: ![shaktigupta200](https://avatars.discourse-cdn.com/v4/letter/s/b4bc9f/32.png) [@shaktigupta200](https://discuss.elastic.co/u/shaktigupta200)
#### Post date: [August 11, 2017, 7:51am UTC](https://discuss.elastic.co/t/problem-in-elasticsearch-wildcard-filtered-query/96718/2 "2017-08-11T07:51:47Z")

</div>

@danielmitterdorfer @fcza @issiaka @Allwyn @forloop @dadoonet @warkolm

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [August 11, 2017, 8:05am UTC](https://discuss.elastic.co/t/problem-in-elasticsearch-wildcard-filtered-query/96718/3 "2017-08-11T08:05:35Z")

</div>

Please read

> [@About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21):
>
> The heart of the free and open Elastic Stack Elasticsearch is a distributed, RESTful search and analytics engine capable of addressing a growing number of use cases. As the heart of the Elastic Stack, it centrally stores your data for lightning fast search, fine‑tuned relevancy, and powerful analytics that scale with ease. warning PLEASE READ THIS SECTION IF IT'S YOUR FIRST POST Some useful links: [elasticsearch reference guide](http://www.elastic.co/guide/en/elasticsearch/reference/current/index.html)[elasticsearch user guide](http://www.elastic.co/guide/en/elasticsearch/guide/current/index.html)[elasticsearch plugins](https://www.elastic.co/guide/en/elasticsearch/plugins/current/index.html)[elasticsearch cl…](https://www.elastic.co/guide/en/elasticsearch/client/index.html)

Specifically the "be patient" part.

Don't ping people like this unless there are already participating in this thread. It breaks the code of conduct IMO.

---

<div class="post-metadata">

### Author: ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)
#### Post date: [August 11, 2017, 9:11am UTC](https://discuss.elastic.co/t/problem-in-elasticsearch-wildcard-filtered-query/96718/4 "2017-08-11T09:11:08Z")

</div>

A couple of recommendations:

1. Move the `range` query to a `bool` query `filter` clause. The query is a predicate so does not require scoring
2. Instead of asking for 300,000 terms in the aggregation, consider using [partitions](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-terms-aggregation.html#_filtering_values_with_partitions) to return the results over several responses.

If you want exactly the same query as Kibana, then you could also get it in the `Request` tab

 ![14](https://us1.discourse-cdn.com/elastic/original/3X/0/2/02c29bb7d85f045debeb18d2aec6ef27e8f3d822.png)

---

<div class="post-metadata">

### Author: ![shaktigupta200](https://avatars.discourse-cdn.com/v4/letter/s/b4bc9f/32.png) [@shaktigupta200](https://discuss.elastic.co/u/shaktigupta200)
#### Post date: [August 11, 2017, 9:33am UTC](https://discuss.elastic.co/t/problem-in-elasticsearch-wildcard-filtered-query/96718/5 "2017-08-11T09:33:36Z")

</div>

@dadoonet Pardon me. I tagged few people thinking it would attract their kind attention towards my problem and could help me solving the problem. Also I was not aware of the code of conduct. Anyway thanks for the suggestion.

---

<div class="post-metadata">

### Author: ![shaktigupta200](https://avatars.discourse-cdn.com/v4/letter/s/b4bc9f/32.png) [@shaktigupta200](https://discuss.elastic.co/u/shaktigupta200)
#### Post date: [August 11, 2017, 9:36am UTC](https://discuss.elastic.co/t/problem-in-elasticsearch-wildcard-filtered-query/96718/6 "2017-08-11T09:36:16Z")

</div>

Thank you for your help. I think this will solve my problem. I was unaware that it is possible to see the query in kibana background.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 8, 2017, 9:36am UTC](https://discuss.elastic.co/t/problem-in-elasticsearch-wildcard-filtered-query/96718/7 "2017-09-08T09:36:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
