# What's the recommended method for checking if a string is part of a field?

**URL:** <https://discuss.elastic.co/t/whats-the-recommended-method-for-checking-if-a-string-is-part-of-a-field/354266>\
**Category:** Elasticsearch\
**Created:** [February 27, 2024, 7:46pm UTC](https://discuss.elastic.co/t/whats-the-recommended-method-for-checking-if-a-string-is-part-of-a-field/354266 "2024-02-27T19:46:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![favoca](https://avatars.discourse-cdn.com/v4/letter/f/5daacb/32.png) [@favoca](https://discuss.elastic.co/u/favoca)\
**Post date:** [February 27, 2024, 7:46pm UTC](https://discuss.elastic.co/t/whats-the-recommended-method-for-checking-if-a-string-is-part-of-a-field/354266/1 "2024-02-27T19:46:49Z")

</div>

My research mainly pointed me towards two or three solutions.  
Firstly, using wildcards:

```auto
{
  "query": {
    "wildcard": {
      "name": "*searchTerm*"
    }
  }
}

```

However, the drawback is that wildcards can be slow.

Secondly, the option to use a query string:

```auto
{  
   "query":{  
      "query_string":{  
         "default_field":"name",
         "query":"*searchTerm*"
      }
   }
}

```

This method also seems slow, possibly due to the leading wildcard.

I believe there's a third way involving the use of an n-gram tokenizer and match query, by setting the minimum to 3 and the maximum to a larger number.

```auto
"match": {
      "name": "searchTerm"
    }

```

Will this approach work? In this case, does the searchTerm also go through the analyzer? If yes, is there any way to prevent this? I don't want to return results where the name fields are equal to "sear" just because the searchTerm has been tokenized.

What's the recommended approach? Am I overlooking something? Ideally, the query should:  
a) Be search performant.  
b) Allow for easy toggling between case sensitivity and insensitivity.

---

<div class="post-metadata">

**Author:** ![favoca](https://avatars.discourse-cdn.com/v4/letter/f/5daacb/32.png) [@favoca](https://discuss.elastic.co/u/favoca)\
**Post date:** [March 4, 2024, 10:01pm UTC](https://discuss.elastic.co/t/whats-the-recommended-method-for-checking-if-a-string-is-part-of-a-field/354266/2 "2024-03-04T22:01:44Z")

</div>

bump

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2024, 10:02pm UTC](https://discuss.elastic.co/t/whats-the-recommended-method-for-checking-if-a-string-is-part-of-a-field/354266/3 "2024-04-01T22:02:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
