# Query string with wildcards not working as (I) expect

**URL:** <https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541>\
**Category:** Elasticsearch\
**Created:** [October 7, 2011, 8:16pm UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541 "2011-10-07T20:16:59Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hakan\_Lindestaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakan_lindestaf/32/3107_2.png) [@Hakan\_Lindestaf](https://discuss.elastic.co/u/Hakan_Lindestaf)\
**Post date:** [October 7, 2011, 8:16pm UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/1 "2011-10-07T20:16:59Z")

</div>

Hi,

I have some documents that have a field like this:  
trackingid: Api23-82199996

I would like to query on this, but only on the Api23 part. If possible  
I want to ignore cases (to pick up both api23 and Api23). I tried to  
query this using trackingid:api23\* and trackingid:Api23\* but no result  
is returned. If I try trackingid:Api23-82199996 I get results, but  
only for a full match of course. I realize there is something I'm  
missing, but if anyone can help me understand or come up with a  
workaround I'd appreciate it.

Here's a link to a ticket I opened for the UI, figured I'd start  
there: [https://logstash.jira.com/browse/LOGSTASH-235](https://logstash.jira.com/browse/LOGSTASH-235)

Thanks,  
/Hakan

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [October 8, 2011, 6:47pm UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/2 "2011-10-08T18:47:47Z")

</div>

trackingId is probably analyzed, so its gets broken down into several terms,  
using this:

# create a sample index

curl -XPUT localhost:9200/test

# see how the text for trackingId get analyzed using the default (standard)

analyzer  
curl -XGET localhost:9200/test/\_analyze -d 'Api23-82199996'

You can see that the text Api23-82199996 gets broken down into two terms,  
Api23, and 82199996 that get indexed. If you want to treat it as a single  
term, you need to define in a mapping that trackingId is not analyzed.

On Fri, Oct 7, 2011 at 10:16 PM, Hakan Lindestaf [hakan@lindestaf.com](mailto:hakan@lindestaf.com)wrote:

> Hi,
> 
> I have some documents that have a field like this:  
> trackingid: Api23-82199996
> 
> I would like to query on this, but only on the Api23 part. If possible  
> I want to ignore cases (to pick up both api23 and Api23). I tried to  
> query this using trackingid:api23\* and trackingid:Api23\* but no result  
> is returned. If I try trackingid:Api23-82199996 I get results, but  
> only for a full match of course. I realize there is something I'm  
> missing, but if anyone can help me understand or come up with a  
> workaround I'd appreciate it.
> 
> Here's a link to a ticket I opened for the UI, figured I'd start  
> there: [Jira](https://logstash.jira.com/browse/LOGSTASH-235)
> 
> Thanks,  
> /Hakan

---

<div class="post-metadata">

**Author:** ![Hakan\_Lindestaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakan_lindestaf/32/3107_2.png) [@Hakan\_Lindestaf](https://discuss.elastic.co/u/Hakan_Lindestaf)\
**Post date:** [October 11, 2011, 6:01pm UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/3 "2011-10-11T18:01:59Z")

</div>

Shay,

thanks a lot, you were right, it was analyzed. However, I changed it (and killed my indices), checked my metadata and it's not analyzed, but if the content in the field in Api23 (vs api23) then the wildcard query doesn't work. What am I missing? I tried both upper and lower case search query, but it seems to be dependent on the content in the document, which is weird to me.

Thanks,  
/Hakan

On Oct 8, 2011, at 11:47 AM, Shay Banon wrote:

> trackingId is probably analyzed, so its gets broken down into several terms, using this:
> 
> # create a sample index
> 
> curl -XPUT localhost:9200/test
> 
> # see how the text for trackingId get analyzed using the default (standard) analyzer
> 
> curl -XGET localhost:9200/test/\_analyze -d 'Api23-82199996'
> 
> You can see that the text Api23-82199996 gets broken down into two terms, Api23, and 82199996 that get indexed. If you want to treat it as a single term, you need to define in a mapping that trackingId is not analyzed.
> 
> On Fri, Oct 7, 2011 at 10:16 PM, Hakan Lindestaf [hakan@lindestaf.com](mailto:hakan@lindestaf.com) wrote:  
> Hi,
> 
> I have some documents that have a field like this:  
> trackingid: Api23-82199996
> 
> I would like to query on this, but only on the Api23 part. If possible  
> I want to ignore cases (to pick up both api23 and Api23). I tried to  
> query this using trackingid:api23\* and trackingid:Api23\* but no result  
> is returned. If I try trackingid:Api23-82199996 I get results, but  
> only for a full match of course. I realize there is something I'm  
> missing, but if anyone can help me understand or come up with a  
> workaround I'd appreciate it.
> 
> Here's a link to a ticket I opened for the UI, figured I'd start  
> there: [[LOGSTASH-235] - logstash.jira.com](https://logstash.jira.com/browse/LOGSTASH-235)
> 
> Thanks,  
> /Hakan

---

<div class="post-metadata">

**Author:** ![Jamshid](https://avatars.discourse-cdn.com/v4/letter/j/ecd19e/32.png) [@Jamshid](https://discuss.elastic.co/u/Jamshid)\
**Post date:** [October 12, 2011, 7:01pm UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/4 "2011-10-12T19:01:10Z")

</div>

So you're using the "keyword" analyzer now? You probably have to set  
lowercase\_expanded\_terms=false.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

--Jamshid

On Oct 11, 1:01 pm, Hakan Lindestaf [ha...@lindestaf.com](mailto:ha...@lindestaf.com) wrote:

> Shay,
> 
> thanks a lot, you were right, it was analyzed. However, I changed it (and killed my indices), checked my metadata and it's not analyzed, but if the content in the field in Api23 (vs api23) then the wildcard query doesn't work. What am I missing? I tried both upper and lower case search query, but it seems to be dependent on the content in the document, which is weird to me.
> 
> Thanks,  
> /Hakan
> 
> On Oct 8, 2011, at 11:47 AM, Shay Banon wrote:
> 
> > trackingId is probably analyzed, so its gets broken down into several terms, using this:
> 
> > # create a sample index
> > 
> > curl -XPUT localhost:9200/test
> 
> > # see how the text for trackingId get analyzed using the default (standard) analyzer
> > 
> > curl -XGET localhost:9200/test/\_analyze -d 'Api23-82199996'
> 
> > You can see that the text Api23-82199996 gets broken down into two terms, Api23, and 82199996 that get indexed. If you want to treat it as a single term, you need to define in a mapping that trackingId is not analyzed.
> 
> > On Fri, Oct 7, 2011 at 10:16 PM, Hakan Lindestaf [ha...@lindestaf.com](mailto:ha...@lindestaf.com) wrote:  
> > Hi,
> 
> > I have some documents that have a field like this:  
> > trackingid: Api23-82199996
> 
> > I would like to query on this, but only on the Api23 part. If possible  
> > I want to ignore cases (to pick up both api23 and Api23). I tried to  
> > query this using trackingid:api23\* and trackingid:Api23\* but no result  
> > is returned. If I try trackingid:Api23-82199996 I get results, but  
> > only for a full match of course. I realize there is something I'm  
> > missing, but if anyone can help me understand or come up with a  
> > workaround I'd appreciate it.
> 
> > Here's a link to a ticket I opened for the UI, figured I'd start  
> > there:[[LOGSTASH-235] - logstash.jira.com](https://logstash.jira.com/browse/LOGSTASH-235)
> 
> > Thanks,  
> > /Hakan

---

<div class="post-metadata">

**Author:** ![Hakan\_Lindestaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakan_lindestaf/32/3107_2.png) [@Hakan\_Lindestaf](https://discuss.elastic.co/u/Hakan_Lindestaf)\
**Post date:** [October 12, 2011, 11:27pm UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/5 "2011-10-12T23:27:00Z")

</div>

The problem is that I'm using Logstash as the UI (and I've been told it's using the Java API client to access ES). So I can't see what the real search parameter is unfortunately.  
However when I do searches I can guess what it does.  
If my data looks like this:  
api12-xxxxyyyy

then any of these searches bring back the same result:  
api12\*  
Api12\*  
API12\*

However if the data looks like this:  
Api12-xxxxyyyy

then none of the combinations above bring back any results (only the full exact match works).

I also verified this with other (non\_analyzed) fields. If the content has upper case characters then the wildcard search doesn't seem to work.

/Hakan

On Oct 12, 2011, at 12:01 PM, Jamshid wrote:

> So you're using the "keyword" analyzer now? You probably have to set  
> lowercase\_expanded\_terms=false.
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/query-string-query.html)
> 
> --Jamshid
> 
> On Oct 11, 1:01 pm, Hakan Lindestaf [ha...@lindestaf.com](mailto:ha...@lindestaf.com) wrote:
> 
> > Shay,
> > 
> > thanks a lot, you were right, it was analyzed. However, I changed it (and killed my indices), checked my metadata and it's not analyzed, but if the content in the field in Api23 (vs api23) then the wildcard query doesn't work. What am I missing? I tried both upper and lower case search query, but it seems to be dependent on the content in the document, which is weird to me.
> > 
> > Thanks,  
> > /Hakan
> > 
> > On Oct 8, 2011, at 11:47 AM, Shay Banon wrote:
> > 
> > > trackingId is probably analyzed, so its gets broken down into several terms, using this:
> > 
> > > # create a sample index
> > > 
> > > curl -XPUT localhost:9200/test
> > 
> > > # see how the text for trackingId get analyzed using the default (standard) analyzer
> > > 
> > > curl -XGET localhost:9200/test/\_analyze -d 'Api23-82199996'
> > 
> > > You can see that the text Api23-82199996 gets broken down into two terms, Api23, and 82199996 that get indexed. If you want to treat it as a single term, you need to define in a mapping that trackingId is not analyzed.
> > 
> > > On Fri, Oct 7, 2011 at 10:16 PM, Hakan Lindestaf [ha...@lindestaf.com](mailto:ha...@lindestaf.com) wrote:  
> > > Hi,
> > 
> > > I have some documents that have a field like this:  
> > > trackingid: Api23-82199996
> > 
> > > I would like to query on this, but only on the Api23 part. If possible  
> > > I want to ignore cases (to pick up both api23 and Api23). I tried to  
> > > query this using trackingid:api23\* and trackingid:Api23\* but no result  
> > > is returned. If I try trackingid:Api23-82199996 I get results, but  
> > > only for a full match of course. I realize there is something I'm  
> > > missing, but if anyone can help me understand or come up with a  
> > > workaround I'd appreciate it.
> > 
> > > Here's a link to a ticket I opened for the UI, figured I'd start  
> > > there:[[LOGSTASH-235] - logstash.jira.com](https://logstash.jira.com/browse/LOGSTASH-235)
> > 
> > > Thanks,  
> > > /Hakan

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 13, 2011, 4:53am UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/6 "2011-10-13T04:53:13Z")

</div>

You should use a keyword analyzer with lowercase filter.  
Define your own analyzer (keylowercase) and apply it to your field.

Then, when the user enter a search term, lowercase it.

That's the way I do it

HTH  
David 😉

Le 13 oct. 2011 à 01:27, Hakan Lindestaf [hakan@lindestaf.com](mailto:hakan@lindestaf.com) a écrit :

> The problem is that I'm using Logstash as the UI (and I've been told it's using the Java API client to access ES). So I can't see what the real search parameter is unfortunately.  
> However when I do searches I can guess what it does.  
> If my data looks like this:  
> api12-xxxxyyyy
> 
> then any of these searches bring back the same result:  
> api12\*  
> Api12\*  
> API12\*
> 
> However if the data looks like this:  
> Api12-xxxxyyyy
> 
> then none of the combinations above bring back any results (only the full exact match works).
> 
> I also verified this with other (non\_analyzed) fields. If the content has upper case characters then the wildcard search doesn't seem to work.
> 
> /Hakan
> 
> On Oct 12, 2011, at 12:01 PM, Jamshid wrote:
> 
> > So you're using the "keyword" analyzer now? You probably have to set  
> > lowercase\_expanded\_terms=false.
> > 
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/query-string-query.html)
> > 
> > --Jamshid
> > 
> > On Oct 11, 1:01 pm, Hakan Lindestaf [ha...@lindestaf.com](mailto:ha...@lindestaf.com) wrote:
> > 
> > > Shay,
> > > 
> > > thanks a lot, you were right, it was analyzed. However, I changed it (and killed my indices), checked my metadata and it's not analyzed, but if the content in the field in Api23 (vs api23) then the wildcard query doesn't work. What am I missing? I tried both upper and lower case search query, but it seems to be dependent on the content in the document, which is weird to me.
> > > 
> > > Thanks,  
> > > /Hakan
> > > 
> > > On Oct 8, 2011, at 11:47 AM, Shay Banon wrote:
> > > 
> > > > trackingId is probably analyzed, so its gets broken down into several terms, using this:
> > > 
> > > > # create a sample index
> > > > 
> > > > curl -XPUT localhost:9200/test
> > > 
> > > > # see how the text for trackingId get analyzed using the default (standard) analyzer
> > > > 
> > > > curl -XGET localhost:9200/test/\_analyze -d 'Api23-82199996'
> > > 
> > > > You can see that the text Api23-82199996 gets broken down into two terms, Api23, and 82199996 that get indexed. If you want to treat it as a single term, you need to define in a mapping that trackingId is not analyzed.
> > > 
> > > > On Fri, Oct 7, 2011 at 10:16 PM, Hakan Lindestaf [ha...@lindestaf.com](mailto:ha...@lindestaf.com) wrote:  
> > > > Hi,
> > > 
> > > > I have some documents that have a field like this:  
> > > > trackingid: Api23-82199996
> > > 
> > > > I would like to query on this, but only on the Api23 part. If possible  
> > > > I want to ignore cases (to pick up both api23 and Api23). I tried to  
> > > > query this using trackingid:api23\* and trackingid:Api23\* but no result  
> > > > is returned. If I try trackingid:Api23-82199996 I get results, but  
> > > > only for a full match of course. I realize there is something I'm  
> > > > missing, but if anyone can help me understand or come up with a  
> > > > workaround I'd appreciate it.
> > > 
> > > > Here's a link to a ticket I opened for the UI, figured I'd start  
> > > > there:[[LOGSTASH-235] - logstash.jira.com](https://logstash.jira.com/browse/LOGSTASH-235)
> > > 
> > > > Thanks,  
> > > > /Hakan

---

<div class="post-metadata">

**Author:** ![Hakan\_Lindestaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakan_lindestaf/32/3107_2.png) [@Hakan\_Lindestaf](https://discuss.elastic.co/u/Hakan_Lindestaf)\
**Post date:** [October 13, 2011, 4:08pm UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/7 "2011-10-13T16:08:35Z")

</div>

Ahhh, now I understand. That makes sense and it solved my problem. I think the search query was automatically (by the Logstash UI) made lower case, so with the default analyzer it didn't pick up the lower case search terms. With this change it all works! Thanks a lot!

/Hakan

On Oct 12, 2011, at 9:53 PM, David Pilato wrote:

> You should use a keyword analyzer with lowercase filter.  
> Define your own analyzer (keylowercase) and apply it to your field.
> 
> Then, when the user enter a search term, lowercase it.
> 
> That's the way I do it
> 
> HTH  
> David 😉
> 
> Le 13 oct. 2011 à 01:27, Hakan Lindestaf [hakan@lindestaf.com](mailto:hakan@lindestaf.com) a écrit :
> 
> > The problem is that I'm using Logstash as the UI (and I've been told it's using the Java API client to access ES). So I can't see what the real search parameter is unfortunately.  
> > However when I do searches I can guess what it does.  
> > If my data looks like this:  
> > api12-xxxxyyyy
> > 
> > then any of these searches bring back the same result:  
> > api12\*  
> > Api12\*  
> > API12\*
> > 
> > However if the data looks like this:  
> > Api12-xxxxyyyy
> > 
> > then none of the combinations above bring back any results (only the full exact match works).
> > 
> > I also verified this with other (non\_analyzed) fields. If the content has upper case characters then the wildcard search doesn't seem to work.
> > 
> > /Hakan
> > 
> > On Oct 12, 2011, at 12:01 PM, Jamshid wrote:
> > 
> > > So you're using the "keyword" analyzer now? You probably have to set  
> > > lowercase\_expanded\_terms=false.
> > > 
> > > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/query-string-query.html)
> > > 
> > > --Jamshid
> > > 
> > > On Oct 11, 1:01 pm, Hakan Lindestaf [ha...@lindestaf.com](mailto:ha...@lindestaf.com) wrote:
> > > 
> > > > Shay,
> > > > 
> > > > thanks a lot, you were right, it was analyzed. However, I changed it (and killed my indices), checked my metadata and it's not analyzed, but if the content in the field in Api23 (vs api23) then the wildcard query doesn't work. What am I missing? I tried both upper and lower case search query, but it seems to be dependent on the content in the document, which is weird to me.
> > > > 
> > > > Thanks,  
> > > > /Hakan
> > > > 
> > > > On Oct 8, 2011, at 11:47 AM, Shay Banon wrote:
> > > > 
> > > > > trackingId is probably analyzed, so its gets broken down into several terms, using this:
> > > > 
> > > > > # create a sample index
> > > > > 
> > > > > curl -XPUT localhost:9200/test
> > > > 
> > > > > # see how the text for trackingId get analyzed using the default (standard) analyzer
> > > > > 
> > > > > curl -XGET localhost:9200/test/\_analyze -d 'Api23-82199996'
> > > > 
> > > > > You can see that the text Api23-82199996 gets broken down into two terms, Api23, and 82199996 that get indexed. If you want to treat it as a single term, you need to define in a mapping that trackingId is not analyzed.
> > > > 
> > > > > On Fri, Oct 7, 2011 at 10:16 PM, Hakan Lindestaf [ha...@lindestaf.com](mailto:ha...@lindestaf.com) wrote:  
> > > > > Hi,
> > > > 
> > > > > I have some documents that have a field like this:  
> > > > > trackingid: Api23-82199996
> > > > 
> > > > > I would like to query on this, but only on the Api23 part. If possible  
> > > > > I want to ignore cases (to pick up both api23 and Api23). I tried to  
> > > > > query this using trackingid:api23\* and trackingid:Api23\* but no result  
> > > > > is returned. If I try trackingid:Api23-82199996 I get results, but  
> > > > > only for a full match of course. I realize there is something I'm  
> > > > > missing, but if anyone can help me understand or come up with a  
> > > > > workaround I'd appreciate it.
> > > > 
> > > > > Here's a link to a ticket I opened for the UI, figured I'd start  
> > > > > there:[[LOGSTASH-235] - logstash.jira.com](https://logstash.jira.com/browse/LOGSTASH-235)
> > > > 
> > > > > Thanks,  
> > > > > /Hakan

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [October 14, 2011, 12:17pm UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/8 "2011-10-14T12:17:47Z")

</div>

I think logstash uses the query\_string query to query elasticsearch.  
Wildcard / Prefix queries will automatically be lowercased (since they are  
not analyzed, Lucene tries its "best" to do some sort of common analysis,  
which is lowercasing it). I think you solved your problem, which is mapping  
it as keyword and lowercase, which is the best way to solve it.

On Thu, Oct 13, 2011 at 6:08 PM, Hakan Lindestaf [hakan@lindestaf.com](mailto:hakan@lindestaf.com)wrote:

> Ahhh, now I understand. That makes sense and it solved my problem. I think  
> the search query was automatically (by the Logstash UI) made lower case, so  
> with the default analyzer it didn't pick up the lower case search terms.  
> With this change it all works! Thanks a lot!
> 
> /Hakan
> 
> On Oct 12, 2011, at 9:53 PM, David Pilato wrote:
> 
> > You should use a keyword analyzer with lowercase filter.  
> > Define your own analyzer (keylowercase) and apply it to your field.
> > 
> > Then, when the user enter a search term, lowercase it.
> > 
> > That's the way I do it
> > 
> > HTH  
> > David 😉
> > 
> > Le 13 oct. 2011 à 01:27, Hakan Lindestaf [hakan@lindestaf.com](mailto:hakan@lindestaf.com) a écrit :
> > 
> > > The problem is that I'm using Logstash as the UI (and I've been told  
> > > it's using the Java API client to access ES). So I can't see what the real  
> > > search parameter is unfortunately.  
> > > However when I do searches I can guess what it does.  
> > > If my data looks like this:  
> > > api12-xxxxyyyy
> > > 
> > > then any of these searches bring back the same result:  
> > > api12\*  
> > > Api12\*  
> > > API12\*
> > > 
> > > However if the data looks like this:  
> > > Api12-xxxxyyyy
> > > 
> > > then none of the combinations above bring back any results (only the  
> > > full exact match works).
> > > 
> > > I also verified this with other (non\_analyzed) fields. If the content  
> > > has upper case characters then the wildcard search doesn't seem to work.
> > > 
> > > /Hakan
> > > 
> > > On Oct 12, 2011, at 12:01 PM, Jamshid wrote:
> > > 
> > > > So you're using the "keyword" analyzer now? You probably have to set  
> > > > lowercase\_expanded\_terms=false.
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/query-string-query.html)
> 
> > > > --Jamshid
> > > > 
> > > > On Oct 11, 1:01 pm, Hakan Lindestaf [ha...@lindestaf.com](mailto:ha...@lindestaf.com) wrote:
> > > > 
> > > > > Shay,
> > > > > 
> > > > > thanks a lot, you were right, it was analyzed. However, I changed it  
> > > > > (and killed my indices), checked my metadata and it's not analyzed, but if  
> > > > > the content in the field in Api23 (vs api23) then the wildcard query doesn't  
> > > > > work. What am I missing? I tried both upper and lower case search query, but  
> > > > > it seems to be dependent on the content in the document, which is weird to  
> > > > > me.
> > > > > 
> > > > > Thanks,  
> > > > > /Hakan
> > > > > 
> > > > > On Oct 8, 2011, at 11:47 AM, Shay Banon wrote:
> > > > > 
> > > > > > trackingId is probably analyzed, so its gets broken down into several  
> > > > > > terms, using this:
> > > > > 
> > > > > > # create a sample index
> > > > > > 
> > > > > > curl -XPUT localhost:9200/test
> > > > > 
> > > > > > # see how the text for trackingId get analyzed using the default
> 
> (standard) analyzer
> 
> > > > > > curl -XGET localhost:9200/test/\_analyze -d 'Api23-82199996'
> > > > > 
> > > > > > You can see that the text Api23-82199996 gets broken down into two  
> > > > > > terms, Api23, and 82199996 that get indexed. If you want to treat it as a  
> > > > > > single term, you need to define in a mapping that trackingId is not  
> > > > > > analyzed.
> > > > > 
> > > > > > On Fri, Oct 7, 2011 at 10:16 PM, Hakan Lindestaf \<  
> > > > > > [ha...@lindestaf.com](mailto:ha...@lindestaf.com)\> wrote:  
> > > > > > Hi,
> > > > > 
> > > > > > I have some documents that have a field like this:  
> > > > > > trackingid: Api23-82199996
> > > > > 
> > > > > > I would like to query on this, but only on the Api23 part. If  
> > > > > > possible  
> > > > > > I want to ignore cases (to pick up both api23 and Api23). I tried to  
> > > > > > query this using trackingid:api23\* and trackingid:Api23\* but no  
> > > > > > result  
> > > > > > is returned. If I try trackingid:Api23-82199996 I get results, but  
> > > > > > only for a full match of course. I realize there is something I'm  
> > > > > > missing, but if anyone can help me understand or come up with a  
> > > > > > workaround I'd appreciate it.
> > > > > 
> > > > > > Here's a link to a ticket I opened for the UI, figured I'd start  
> > > > > > there:[[LOGSTASH-235] - logstash.jira.com](https://logstash.jira.com/browse/LOGSTASH-235)
> > > > > 
> > > > > > Thanks,  
> > > > > > /Hakan

---

<div class="post-metadata">

**Author:** ![Anil\_AR](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@Anil\_AR](https://discuss.elastic.co/u/Anil_AR)\
**Post date:** [May 2, 2012, 9:54pm UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/9 "2012-05-02T21:54:17Z")

</div>

Hi Kimchy,  
I have also the similar issue. For instance we have values like "City of God" and "God". If I start searching for "g\*", I should get get "God" only. Please advice.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:30am UTC](https://discuss.elastic.co/t/query-string-with-wildcards-not-working-as-i-expect/5541/10 "2017-07-06T03:30:14Z")

</div>


