# Searching in Logs using wildcards does not work

**URL:** <https://discuss.elastic.co/t/searching-in-logs-using-wildcards-does-not-work/284846>\
**Category:** Elasticsearch\
**Created:** [September 22, 2021, 10:21am UTC](https://discuss.elastic.co/t/searching-in-logs-using-wildcards-does-not-work/284846 "2021-09-22T10:21:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Glenn\_Glashagen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glenn_glashagen/32/78407_2.png) [@Glenn\_Glashagen](https://discuss.elastic.co/u/Glenn_Glashagen)\
**Post date:** [September 22, 2021, 10:21am UTC](https://discuss.elastic.co/t/searching-in-logs-using-wildcards-does-not-work/284846/1 "2021-09-22T10:21:57Z")

</div>

Hey all,

I'm trying to search for a logline within the Logtailing tab(part of the Observer features):  
`read 24FPS, detection 24FPS, track 24FPS (0)`  
I can find this logline by using the query: `message: track` however, if I use the search: `message: *FPS` or any other combination of wildcards it does not work.  
If I do the same within `Discover` which I think also uses KQL the wildcard search is working.

Funnily enough (within Logs) the following wildcard search seems to work somewhat: `message:track*` since it also yields the log line:  
(Tracker - lsp\_tracker.on\_finished\_lsp)

I'm really confused if wildcard search is working in the Logtailing tab or not. To me the behavior is extremely fuzzy. Does anyone have an idea on when and how it works?  
I have already read through this: [Wildcard query not working as expected - #2 by Joe\_Fleming](https://discuss.elastic.co/t/wildcard-query-not-working-as-expected/84447/2)

all the best,  
Glenn

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2021, 10:22am UTC](https://discuss.elastic.co/t/searching-in-logs-using-wildcards-does-not-work/284846/2 "2021-10-20T10:22:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
