Using Wildcards in field filters

(Bryan Whitmarsh) #1

Ok, I'm a elastic newbie (<8hrs and 100+ usages of "curl -XDELETE 'http://localhost:9200/_all'"...;).
I simply want to create a filter that searches the string content of a specific field (POND_NAME) and returns all records that start with "BABING". I've tried all the flavors of POND_NAME:BABINGTON* possible but none seem to work. What am I doing wrong? This should be simple!

This works:

This Doesn't:

(Anh) #2

Not sure if it has something to do with using wildcard on a not_analyzed field

(Bryan Whitmarsh) #3

I had to set the field as not_analyzed because the multi-name pond names were getting broken up into multiple different ponds. For example "BABINGTON C4" became two ponds "BABINGTON" and "C4"...

(Anh) #5

It may not be the not_analyzed field. I'm curious about this too so I did a test on two fields in my netflow data:


        "include_in_all": true,
        "index": "not_analyzed",
        "type": "string"
        "include_in_all": true,
        "index": "not_analyzed",
        "type": "string"

IPV4_SRC_ADDR contains IP such as,,, etc.
L7_PROTO_NAME contains protocol name such as SSL, HTTP, HTTPS, DNS, SSL.Google

Using wildcard on both fields, I can successfully get result for


which shows me and, but when I run for L7_PROTO_NAME


then no result shows up

I don't know why I got different behaviors with wildcard search on the same field type and not_analyzed?

(Anh) #6

In you case you can either use include_in_all for POND_NAME field and use wildcard search in _all field, or you can use multi fields for POND_NAME

          "index": "analyzed",
          "type": "string",
          "fields": {
            "raw": {
              "index": "not_analyzed",
              "type": "string",

POND_NAMEfor searching and POND_NAME.raw for aggregation

(Bryan Whitmarsh) #7

Thank you! That's going to work for me. I use the "analyzed" POND_NAME field to filter with wildcards and I use the "non-analyzed" field POND_NAME.raw to query by POND NAME.

(system) #8