# Super-long wildcard query (must be a better way!)

**URL:** <https://discuss.elastic.co/t/super-long-wildcard-query-must-be-a-better-way/312605>\
**Category:** Elasticsearch\
**Created:** [August 22, 2022, 10:42am UTC](https://discuss.elastic.co/t/super-long-wildcard-query-must-be-a-better-way/312605 "2022-08-22T10:42:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Richie\_Jarvis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richie_jarvis/32/40706_2.png) [@Richie\_Jarvis](https://discuss.elastic.co/u/Richie_Jarvis)\
**Post date:** [August 22, 2022, 10:42am UTC](https://discuss.elastic.co/t/super-long-wildcard-query-must-be-a-better-way/312605/1 "2022-08-22T10:42:43Z")

</div>

Hi All,

I am playing with some flight data at the moment, and wanted to view the Eastbourne Airshow data I have captured with my aerial & dump1090 integration. To this end, I want to exclude all commercial flights from the dataset, but, well, there are 5400(ish) ICAO 3-letter airline codes registered atm.

I constructed the following query:

```auto
{"query":{"bool": {"should": [
{"wildcard":{"aircraft.flight":"AAA*"}},
{"wildcard":{"aircraft.flight":"AAB*"}},
{"wildcard":{"aircraft.flight":"AAC*"}},
{"wildcard":{"aircraft.flight":"AAD*"}},
{"wildcard":{"aircraft.flight":"AAF*"}},
{"wildcard":{"aircraft.flight":"AAG*"}},
{"wildcard":{"aircraft.flight":"AAH*"}},
{"wildcard":{"aircraft.flight":"AAI*"}},
{"wildcard":{"aircraft.flight":"AAJ*"}},
{"wildcard":{"aircraft.flight":"AAK*"}},
{"wildcard":{"aircraft.flight":"AAL*"}},
{"wildcard":{"aircraft.flight":"AAM*"}},
{"wildcard":{"aircraft.flight":"AAO*"}},
{"wildcard":{"aircraft.flight":"AAP*"}},
**snipped for brevity**
{"wildcard":{"aircraft.flight":"ZZM*"}}
]}}}

```

Doing a quick ciggy packet calc, there are 17576 combinations (A-Z^3), so using an exclude isn't going to be more efficient.

How on earth should I break this down into a meaningful dataset and exclude with ES?

Additional: i want to exclude anything which is [A-Z][A-Z][A-Z] then some numbers - although (awkwardly) some airlines then use letters afters too ☹ Like NZE1234A...

Cheers,

Richie

---

<div class="post-metadata">

**Author:** ![Richie\_Jarvis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richie_jarvis/32/40706_2.png) [@Richie\_Jarvis](https://discuss.elastic.co/u/Richie_Jarvis)\
**Post date:** [August 22, 2022, 11:35am UTC](https://discuss.elastic.co/t/super-long-wildcard-query-must-be-a-better-way/312605/2 "2022-08-22T11:35:41Z")

</div>

In the end I decided to just go with the best I could:

```auto
{
  "query": {
    "regexp": {
      "aircraft.flight.keyword": "[A-Z]{3}[0-9]{1}.*"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2022, 11:36am UTC](https://discuss.elastic.co/t/super-long-wildcard-query-must-be-a-better-way/312605/3 "2022-09-19T11:36:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
