# "query\_string" Wildcard search with special characters issue

**URL:** <https://discuss.elastic.co/t/query-string-wildcard-search-with-special-characters-issue/254068>\
**Category:** Elasticsearch\
**Created:** [November 2, 2020, 6:20pm UTC](https://discuss.elastic.co/t/query-string-wildcard-search-with-special-characters-issue/254068 "2020-11-02T18:20:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anas1](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@Anas1](https://discuss.elastic.co/u/Anas1)\
**Post date:** [November 2, 2020, 6:20pm UTC](https://discuss.elastic.co/t/query-string-wildcard-search-with-special-characters-issue/254068/1 "2020-11-02T18:20:59Z")

</div>

When searching using a wildcard words, i have an unexpected behavior.  
I'm working on ES 5.6.8.

**To reproduce the issue:**

(Test with Kibana)

**- create the index :**

```auto
    PUT my-index-00001
{
  "mappings": {
      "test": {
        "properties": {
          "name1": {
            "type": "keyword",
            "fields": {
              "analyzed": { 
                "type" : "text",
                "analyzer": "french_analyzer"
  
              }
            }
          }
        }
      }
    },
  "settings": {
    "analysis": {
      "analyzer": {
        "path_analyzer": {
          "tokenizer": "path_tokenizer"
        },
        "french_analyzer": {
          "type": "custom",
          "tokenizer": "standard",
          "filter": ["lowercase", "asciifolding"]
        }
      },
      "tokenizer": {
        "path_tokenizer": {
          "type": "path_hierarchy",
          "delimiter": "/"
        }
      },
      "normalizer": {
        "lowercase_normalizer": {
          "type": "custom",
          "char_filter": [],
          "filter": ["lowercase"]
        }
      }
    }
  }
}

```

**- Insert test data:**

```auto
POST my-index-00001/test
{
  "name1" : "WT1"
}

POST my-index-00001/test
{
  "name1" : "testWT1"
}

POST my-index-00001/test
{
  "name1" : "WT1test"
}

```

**- Make the search:**

```auto
GET my-index-00001/test/_search
{
  "query": {
    "query_string": {
      "query": "WT\\:*",
      "fields": ["name1.analyzed"],
      "default_operator": "AND",
      "analyze_wildcard": true
    }
  }
}

```

As expected, this search returns both results `["name1": "WT:1test", "name1": "WT:1"]`

but the issue is with a prefix wildcard as follow:

```auto
    GET my-index-00001/test/_search
    {
      "query": {
        "query_string": {
          "query": "*WT\\:", 
          "fields": ["name1.analyzed"],
          "default_operator": "AND",
          "analyze_wildcard": true
        }
      }
    }

```

same issue with query "_WT\:_".  
this search does not return any result.

Expected result: documents with `["name1": "WT:1test", "name1": "WT:1", "name1": "testWT:1"]`

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 3, 2020, 3:51pm UTC](https://discuss.elastic.co/t/query-string-wildcard-search-with-special-characters-issue/254068/2 "2020-11-03T15:51:00Z")

</div>

I updated your demo script to 7.9.3. 5.x is not supported anymore.  
I also edited the example to fix it with the right values and simplify a bit the mapping to remove non needed fields.

```auto
DELETE my-index-00001
PUT my-index-00001
{
  "mappings": {
    "properties": {
      "name1": {
        "type": "text",
        "analyzer": "french_analyzer"
      }
    }
  },
  "settings": {
    "analysis": {
      "analyzer": {
        "french_analyzer": {
          "type": "custom",
          "tokenizer": "standard",
          "filter": [
            "lowercase",
            "asciifolding"
          ]
        }
      }
    }
  }
}
POST my-index-00001/_doc
{
  "name1" : "WT:1"
}

POST my-index-00001/_doc
{
  "name1" : "testWT:1"
}

POST my-index-00001/_doc
{
  "name1" : "WT:1test"
}

GET my-index-00001/_search
{
  "query": {
    "query_string": {
      "query": "WT\\:*",
      "fields": ["name1"],
      "default_operator": "AND",
      "analyze_wildcard": true
    }
  }
}

GET my-index-00001/_search
{
  "query": {
    "query_string": {
      "query": "*WT\\:",
      "fields": ["name1"],
      "default_operator": "AND",
      "analyze_wildcard": true
    }
  }
}

```

Now, back to your question. Here is how your documents are indexed behind the scene:

```auto
POST my-index-00001/_analyze
{
  "field": "name1",
  "text": ["WT:1", "testWT:1", "WT:1test"]
}

```

It gives:

```auto
{
  "tokens" : [
    {
      "token" : "wt",
      "start_offset" : 0,
      "end_offset" : 2,
      "type" : "<ALPHANUM>",
      "position" : 0
    },
    {
      "token" : "1",
      "start_offset" : 3,
      "end_offset" : 4,
      "type" : "<NUM>",
      "position" : 1
    },
    {
      "token" : "testwt",
      "start_offset" : 5,
      "end_offset" : 11,
      "type" : "<ALPHANUM>",
      "position" : 102
    },
    {
      "token" : "1",
      "start_offset" : 12,
      "end_offset" : 13,
      "type" : "<NUM>",
      "position" : 103
    },
    {
      "token" : "wt",
      "start_offset" : 14,
      "end_offset" : 16,
      "type" : "<ALPHANUM>",
      "position" : 204
    },
    {
      "token" : "1test",
      "start_offset" : 17,
      "end_offset" : 22,
      "type" : "<ALPHANUM>",
      "position" : 205
    }
  ]
}

```

That's probably not what you want. Instead you should use a keyword data type when searching with wildcards. Which I don't recommend anyway as [per documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-wildcard-query.html):

> Avoid beginning patterns with `*` or `?` . This can increase the iterations needed to find matching terms and slow search performance.

But, here the problem is something else. You should use a query like:

```auto
GET my-index-00001/_search
{
  "query": {
    "match": {
      "name1": "WT\\:*"
    }
  }
}
GET my-index-00001/_search
{
  "query": {
    "match": {
      "name1": "*WT\\:"
    }
  }
}

```

Hope this helps.

---

<div class="post-metadata">

**Author:** ![Anas1](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@Anas1](https://discuss.elastic.co/u/Anas1)\
**Post date:** [November 4, 2020, 9:38am UTC](https://discuss.elastic.co/t/query-string-wildcard-search-with-special-characters-issue/254068/3 "2020-11-04T09:38:56Z")

</div>

> [@dadoonet](#):
>
> recommend

Thank you for your response, but i think that the issue i encounter is about a prefix wildcard as in

```auto
GET my-index-00001/_search
{
  "query": {
    "match": {
      "name1": "*WT*"
    }
  }
}

```

I expected to find with this search term those results : ["WT:1", "testWT:1", "WT:1test"]  
but actually only two of them are returned: ["WT:1", "WT:1test"] and not "testWT:1",  
the prefix wildcard must not return all three results?!

Thank you in advance

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 4, 2020, 10:15am UTC](https://discuss.elastic.co/t/query-string-wildcard-search-with-special-characters-issue/254068/4 "2020-11-04T10:15:10Z")

</div>

Try this one:

```auto
GET my-index-00001/_search
{
  "query": {
    "wildcard": {
      "name1": "*WT*"
    }
  }
}

```

But again, keep in mind that this is not efficient if you are looking for fast response times.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2020, 10:15am UTC](https://discuss.elastic.co/t/query-string-wildcard-search-with-special-characters-issue/254068/5 "2020-12-02T10:15:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
