# Query String Regex/WildCard Search

**URL:** <https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845>\
**Category:** Elasticsearch\
**Created:** [January 10, 2022, 5:55am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845 "2022-01-10T05:55:36Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [January 10, 2022, 5:55am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/1 "2022-01-10T05:55:36Z")

</div>

Hi Team,

**Problem Statement**  
Search String - "Hello \* World"  
Expected Output - 1. "Hello First World"  
2. "Hello Second World"

I need results that contain one word in place of \*. I have tried using query string regex and wildcard but it is not giving expected results.  
Can anyone please help?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 10, 2022, 8:52am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/2 "2022-01-10T08:52:43Z")

</div>

Hi,

I wonder if you realize "\*" also matches to spaces.  
It depends on what characters you are using in "words", regex query with "`Hello [!-~] World`" will match to phrases which contain only one word with ASCII characters.

Next time, sharing the results and the expected results will give you a more suitable solution.

---

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [January 10, 2022, 9:16am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/3 "2022-01-10T09:16:57Z")

</div>

Hi Tomo\_M,

I have tried below query

````auto
                    "query_string": {
                      "query": "/Hello (.*?) World/",
                      "fields": ['abc','xyz']
                    }
}```

The regex is correct to match words between **Hello** and **World** but it is not working with query_string and returning 0 results.
````

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 10, 2022, 9:24am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/4 "2022-01-10T09:24:08Z")

</div>

What type of field are you querying on: text, keyword or wildcard?

---

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [January 10, 2022, 9:47am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/5 "2022-01-10T09:47:03Z")

</div>

@Tomo_M I am querying on text fields.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 10, 2022, 10:02am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/6 "2022-01-10T10:02:30Z")

</div>

> [@Sahil5](#):
>
> ```auto
> "query_string": {
> "query": "/Hello (.*?) World/",
> 
> ```

`text` fields split your JSON strings into multiple words in the index (e.g. `hello`, `brave`, `new` and `world`).  
Searches always match what is in the index.  
The above `query_string` regex search is asking for a single word in the index that contains spaces which is not going to exist.  
Perhaps more simply, you need to use a _phrase_ query to find documents with the multiple words `hello` and `world` but near to each other. This can be done using this syntax in query\_string:

```auto
    "query_string": {
      "query": "\"Hello world\"~2"
    }

```

The quotes mean "find these words next to each other" and the ~2 modifier means "with up to two word positions different".

---

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [January 10, 2022, 10:20am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/7 "2022-01-10T10:20:40Z")

</div>

Thanks @Mark_Harwood,

I want to fetch the string that contain atleast 1 word between **Hello** and **World**.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 10, 2022, 11:08am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/8 "2022-01-10T11:08:05Z")

</div>

> I wonder if you realize "\*" also matches to spaces.

This in my first reply was for "regex query" but not for "query\_string query", sorry.

As Mark said, single regex (sandwiched between '/') is matched with single tokens. And it is not able to be used in phrases.

Wildcard searches are also not suppoted within phrases.  
[https://lucene.apache.org/core/2\_9\_4/queryparsersyntax.html](https://lucene.apache.org/core/2_9_4/queryparsersyntax.html)

I'm not sure if it has acceptable performance, one possible way is to use wildcard field and use regex query such as " `Hello [!-~] World` " or " `[hH]ello [!-~] [wW]orld` ". One drawback (or possibly advantage) is that words are not analized and no filters such as stemming doesn't work.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 10, 2022, 11:11am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/9 "2022-01-10T11:11:07Z")

</div>

> [@Sahil5](#):
>
> I want to fetch the string that contain atleast 1 word between **Hello** and **World**.

Did you try?

```auto
    "query": "\"Hello world\"~1"

```

---

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [January 10, 2022, 11:25am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/10 "2022-01-10T11:25:15Z")

</div>

@Mark_Harwood, Yes I have tried the above query and it is also returning me string that contains exact string like this "Hello World".

I need results that contain atleast 1 word between **Hello** and **World**

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 10, 2022, 11:30am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/11 "2022-01-10T11:30:15Z")

</div>

Check out [interval queries](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-intervals-query.html) more complex but more powerful. JSON required....

---

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [January 10, 2022, 11:30am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/12 "2022-01-10T11:30:53Z")

</div>

Hi @Tomo_M ,

Wildcard Field is introduced in elastic 7.9.  
My current elastic version is 5.6.

Is there a way to achieve this scenerio in elastic 5.6 ?

---

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [January 10, 2022, 11:32am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/13 "2022-01-10T11:32:39Z")

</div>

@Mark_Harwood Internal Queries is not available in version 5.6.

Is there a way to achieve this scenerio in elastic 5.6 ?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 10, 2022, 11:57am UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/14 "2022-01-10T11:57:58Z")

</div>

> [@Sahil5](#):
>
> Is there a way to achieve this scenerio in elastic 5.6 ?

See the forerunner, [span queries](https://www.elastic.co/guide/en/elasticsearch/reference/current/span-queries.html)

---

<div class="post-metadata">

**Author:** ![Sahil5](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Post date:** [January 11, 2022, 2:43pm UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/15 "2022-01-11T14:43:13Z")

</div>

Hi @Mark_Harwood,

I have applied a workaround for this scenario.  
Below is the query

```auto
  "query": {
    "bool": {
      "must": [
        {
          "bool": {
            "should": [
              {
                "query_string": {
                  "query": "\"Hello World\"",
                  "fields": [],
                  "phrase_slop": 1
                }
              }
            ]
          }
        },
        {
          "bool": {
            "must_not": [
              {
                "query_string": {
                  "query": "\"Hello World\"",
                  "fields": []
                }
              }
            ]
          }
        }
      ]
    }
  }
}

```

This is working fine, but there is one issue that I am getting.

Suppose there is string = "Hello test World Hello" in an index.  
Then the above query is highlighting **Hello** test **World** and also last **Hello**.  
I do not want to highlight the last **Hello** because it does not contain **World** after phrase\_slop: 1.

Is there any way to handle this scenario?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [January 11, 2022, 10:36pm UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/16 "2022-01-11T22:36:13Z")

</div>

We have several highlighter implementations contributed by different parties over time and they differ in their focus eg speed, accuracy etc.  
I lose track of which are better at respecting phrase match accuracy but it’s worth experimenting with the different types.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2022, 10:36pm UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845/17 "2022-02-08T22:36:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
