# QueryString vs multiple wildcards

**URL:** <https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382>\
**Category:** Elasticsearch\
**Created:** [June 6, 2023, 9:05pm UTC](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382 "2023-06-06T21:05:41Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ortiga\_Abdo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ortiga_abdo/32/121924_2.png) [@Ortiga\_Abdo](https://discuss.elastic.co/u/Ortiga_Abdo)\
**Post date:** [June 6, 2023, 9:05pm UTC](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382/1 "2023-06-06T21:05:41Z")

</div>

I can't find any documentations that talks about queries and their performance/comparison

I'm wondering which is better performance/faster multiple wildcard filter or a string\_query?

```auto
"query": {
    "bool" : {
      "must" : [
        {
          "query_string" : {
            "query" : "*val1* OR *val2*",
            "default_field" : "field",
            "fields" : [],
            "type" : "best_fields",
            "default_operator" : "or",
            "max_determinized_states" : 10000,
            "enable_position_increments" : true,
            "fuzziness" : "AUTO",
            "fuzzy_prefix_length" : 0,
            "fuzzy_max_expansions" : 50,
            "phrase_slop" : 0,
            "escape" : false,
            "auto_generate_synonyms_phrase_query" : true,
            "fuzzy_transpositions" : true,
            "boost" : 1.0
          }
        }
      ],
      "adjust_pure_negative" : true,
      "boost" : 1.0
    }
  }

```

or

```auto
"query": {
    "bool" : {
      "filter" : [
        {
          "bool" : {
            "should" : [
              {
                "wildcard" : {
                  "field" : {
                    "wildcard" : "*val1*",
                    "boost" : 1.0
                  }
                }
              },
              {
                "wildcard" : {
                  "field" : {
                    "wildcard" : "*val2*",
                    "boost" : 1.0
                  }
                }
              }
            ],
            "adjust_pure_negative" : true,
            "boost" : 1.0
          }
        }
      ],
      "adjust_pure_negative" : true,
      "boost" : 1.0
    }
  }

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 7, 2023, 6:51am UTC](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382/2 "2023-06-07T06:51:00Z")

</div>

What is the type of the field field?

---

<div class="post-metadata">

**Author:** ![Ortiga\_Abdo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ortiga_abdo/32/121924_2.png) [@Ortiga\_Abdo](https://discuss.elastic.co/u/Ortiga_Abdo)\
**Post date:** [June 7, 2023, 7:16am UTC](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382/3 "2023-06-07T07:16:57Z")

</div>

2 cases, one text and the other keyword.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 7, 2023, 8:58am UTC](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382/4 "2023-06-07T08:58:40Z")

</div>

It will be super slow whichever query you use.

What is your use case?

Have a look at [Keyword type family | Elasticsearch Guide [8.8] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html#wildcard-field-type)

---

<div class="post-metadata">

**Author:** ![Ortiga\_Abdo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ortiga_abdo/32/121924_2.png) [@Ortiga\_Abdo](https://discuss.elastic.co/u/Ortiga_Abdo)\
**Post date:** [June 7, 2023, 5:50pm UTC](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382/5 "2023-06-07T17:50:11Z")

</div>

We’re dealing with both cases, same query will run for both text and keyword, still the question is which is better, multiple wildcards or queries\_string?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 7, 2023, 6:23pm UTC](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382/6 "2023-06-07T18:23:01Z")

</div>

Wildcard queries, especially with leading wildcards, are the most inefficient types of queries you can run in Elasticsearch, at least as long as you are not using the new wildcard field type. Both of these queries will perform and scale badly, so what you are asking is which one is least awful. I would recommend you benchmark them and see for yourself as it is likely to depend on the data and cluster specification etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2023, 6:23pm UTC](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382/7 "2023-07-05T18:23:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
