# 'query\_string' does not return records when using wildcard since 8.9 (wilcard query does)

**URL:** https://discuss.elastic.co/t/query-string-does-not-return-records-when-using-wildcard-since-8-9-wilcard-query-does/355481
**Category:** Elasticsearch
**Created:** [March 15, 2024, 12:43pm UTC](https://discuss.elastic.co/t/query-string-does-not-return-records-when-using-wildcard-since-8-9-wilcard-query-does/355481 "2024-03-15T12:43:16Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![pawel.kupka-trojak](https://avatars.discourse-cdn.com/v4/letter/p/779978/32.png) [@pawel.kupka-trojak](https://discuss.elastic.co/u/pawel.kupka-trojak)
#### Post date: [March 15, 2024, 12:43pm UTC](https://discuss.elastic.co/t/query-string-does-not-return-records-when-using-wildcard-since-8-9-wilcard-query-does/355481/1 "2024-03-15T12:43:16Z")

</div>

Hi,

We are testing server upgrade to 8.12.2 and we found that some of our queries stopped to works. We use 'query\_string' with wildcard to search for user requested data. I have prepared some test data to show the challange we meet.

Lets assume we have index definition like this:

```auto
PUT test
{
  "settings": {
    "index": {
      "number_of_shards": "1",
      "number_of_replicas": "1",
      "analysis": {
        "filter": {
          "appendZeros": {
            "type": "pattern_replace",
            "pattern": "^(a?)(\\d+)(\\D{3})?$",
            "replacement": "$1$2\u006100$3 $1$2$3"
          },
          "appendZero": {
            "type": "pattern_replace",
            "pattern": "^(a?)(\\d+a\\d)(\\D{3})?$",
            "replacement": "$1$20$3 $1$2$3"
          },
          "divideToken": {
            "type": "pattern_capture",
            "preserve_original": false,
            "patterns": [
              "(\\S+) (\\S+)"
            ]
          }
        },
        "analyzer": {
          "currencyAnalyzer": {
            "type": "custom",
            "tokenizer": "keyword",
            "char_filter": [
              "replaceSpecialCharacters"
            ],
            "filter": [
              "lowercase",
              "appendZeros",
              "appendZero",
              "divideToken"
            ]
          },
          "textAnalyzer": {
            "type": "custom",
            "tokenizer": "standard",
            "char_filter": [
              "replaceSpecialCharacters"
            ],
            "filter": [
              "lowercase"
            ]
          }
        },
        "char_filter": {
          "replaceSpecialCharacters": {
            "type": "mapping",
            "mappings": [
              ".=>\u0061",
              ",=>\u0061"
            ]
          }
        },
        "normalizer": {
          "lowercaseNormalizer": {
            "type": "custom",
            "filter": [
              "lowercase"
            ]
          }
        }
      }
    }
  },
  "mappings": {
    "dynamic": false,
    "properties": {
      "amount": {
        "properties": {
          "amount": {
            "type": "scaled_float",
            "scaling_factor": 100,
            "copy_to": "amountValue"
          },
          "currency": {
            "type": "keyword",
            "copy_to": "amountValue"
          }
        }
      },
      "amountValue": {
        "type": "text",
        "analyzer": "currencyAnalyzer",
        "store": false
      }
    }
  }
}

```

Lets put in some data:

```auto
put test/_doc/1
{
  "amount":{
    "amount":123.45,
    "currency": "USD"
  }
}

put test/_doc/2
{
  "amount":{
    "amount":123.4,
    "currency": "EUR"
  }
}

```

Now query the data using wildcard:

```auto
post test/_search
{
  "query":{
    "wildcard": {
      "amountValue":{
        "value": "123a4*"
      }
    }
  }
}

```

As a result we got: "hits": { "total": { **"value": 2** , .... }}

Now lets run query\_string:

```auto
post test/_search
{
  "query":{
    "query_string": {
      "fields": ["amountValue"], 
      "query": "123a4*"
    }
  }
}

```

This time we got: "hits": {"total": { **"value": 0** , ...}}

We tested earlier versions of Elasticserver and this behaviour started to appear since 8.9.

Now lets check tokens from documents we inserted:

```auto
post test/_analyze
{
  "text":"123,4 123.45",
  "field": "amountValue"
}

```

And we've got

```auto
      "token": "123a4",
      "token": "123a45",

```

And that is what we are looking for in a query\_string. So why does query do not return the requested data? Is it some kind of a bug or my index settings are badly defined?

Any advice would be greatly appreciated as we are fighting with this for a some time.

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 15, 2024, 8:10pm UTC](https://discuss.elastic.co/t/query-string-does-not-return-records-when-using-wildcard-since-8-9-wilcard-query-does/355481/2 "2024-03-15T20:10:23Z")

</div>

I would set store: true for the amountValue field to see how it's actually generated by the copy\_to function.

But anyway, to solve this, I'd use an ingest pipeline and set the field using the 2 other fields. So you have a better control on how data is copied.

---

<div class="post-metadata">

### Author: ![pawel.kupka-trojak](https://avatars.discourse-cdn.com/v4/letter/p/779978/32.png) [@pawel.kupka-trojak](https://discuss.elastic.co/u/pawel.kupka-trojak)
#### Post date: [March 19, 2024, 1:38pm UTC](https://discuss.elastic.co/t/query-string-does-not-return-records-when-using-wildcard-since-8-9-wilcard-query-does/355481/3 "2024-03-19T13:38:54Z")

</div>

Thanks for your answer.

But copy\_to function works as intended. The problem exists even when i add data directly to this field (field store changed to true).

```auto
put test/_doc/4
{
  "amountValue":"123.4"
}

```

query\_string still returns no rows.

I called:

```auto
post /test/_termvectors/1
{
  "fields" : ["amountValue"]
}

```

and received:

```auto
  "term_vectors": {
    "amountValue": {
      "field_statistics": {
        "sum_doc_freq": 11,
        "doc_count": 5,
        "sum_ttf": 11
      },
      "terms": {
        "123a45": {
          "term_freq": 1,
          "tokens": [
            {
              "position": 101,
              "start_offset": 4,
              "end_offset": 10
            }
          ]
        },
        "usd": {
          "term_freq": 1,
          "tokens": [
            {
              "position": 0,
              "start_offset": 0,
              "end_offset": 3
            }
          ]
        }
      }
    }
  }

```

All leads to conclusion, that query\_string works differently than wildcard query, but still don't know why.

As for now i found a workaround to this problem, i simply add standard analyzer to query\_string

```auto
post test/_search
{
  "query":{
    "query_string": {
      "fields": ["amountValue"], 
      "query": "123a4*",
      "analyzer": "standard"
    }
  }
}

```

and voila: "hits": {" **total**": {"value": **2**...}

My question is still to answer: why wildcard query words differently to query\_string for the same index, data and query?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 16, 2024, 1:39pm UTC](https://discuss.elastic.co/t/query-string-does-not-return-records-when-using-wildcard-since-8-9-wilcard-query-does/355481/4 "2024-04-16T13:39:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
