# Search for a substring within a specific field

**URL:** <https://discuss.elastic.co/t/search-for-a-substring-within-a-specific-field/118841>\
**Category:** Kibana\
**Created:** [February 7, 2018, 12:25pm UTC](https://discuss.elastic.co/t/search-for-a-substring-within-a-specific-field/118841 "2018-02-07T12:25:55Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [February 7, 2018, 7:33pm UTC](https://discuss.elastic.co/t/search-for-a-substring-within-a-specific-field/118841/2 "2018-02-07T19:33:42Z")

</div>

hi @ghouston10,

I think the answer is, it depends.

1. In any place you would be using Painless, for example, in Kibana's scripted fields, you can use Regex to do substring matches on a field-value.

See here for an example: [Substring in painless](https://discuss.elastic.co/t/substring-in-painless/88660/3)

1. You can also do prefix-queries with lucene using the wildcard character. So in the Kibana query-bar, you could do something like `url:https*` to search for all https calls. The wildcard query in lucene cannot be put at the start of a string. More info on that here: [https://lucene.apache.org/core/2\_9\_4/queryparsersyntax.html#Terms](https://lucene.apache.org/core/2_9_4/queryparsersyntax.html#Terms)

---

_[View the full topic](https://discuss.elastic.co/t/search-for-a-substring-within-a-specific-field/118841)._
