# Why does this simple search in Kibana work?

**URL:** <https://discuss.elastic.co/t/why-does-this-simple-search-in-kibana-work/382435>\
**Category:** Kibana\
**Created:** [October 6, 2025, 9:30am UTC](https://discuss.elastic.co/t/why-does-this-simple-search-in-kibana-work/382435 "2025-10-06T09:30:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![smm](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@smm](https://discuss.elastic.co/u/smm)\
**Post date:** [October 6, 2025, 9:30am UTC](https://discuss.elastic.co/t/why-does-this-simple-search-in-kibana-work/382435/1 "2025-10-06T09:30:11Z")

</div>

Hi there,

I defined this simple test document:

`POST /logs-stefano/_doc?pipeline=syslog_deduplication`  
`{`  
`"@timestamp": "2025-10-06T09:00:00Z",`  
`"host": "SERVER-A",`  
`"message": "date=2025-05-02 time=10:38:00 devname=SERVER-A severity=info msg='Test syslog message nr 1'",`  
`"severity": "info",`  
`"facility": "local7",`  
`"NEU": "Zusatzfeld"`  
`}`

In Kibana 8.18.6 I search like this:  
**severity: i\*fo**  
and get as result what I defined above - 1 document.

My question:

Kibana shows for this single result document under ‘Document’ → ‘Table’ the type _keyword_ for the severity field.

But why does it not show the type t for _text_? In the json view there is no such .keyword field for it. By the way I can use a wildcard in this field and get a result.

cheers!

\*\*Attachments  
\*\*

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7d2aa553de49bd8b6080cd373e5148e2f2a1c90a.png)

```json
{
  "_index": "logs-stefano",
  "_id": "6OWj7yIs9qQdYdBSMcMdaA==",
  "_version": 1,
  "_source": {
    "severity": "info",
    "@timestamp": "2025-10-06T09:00:00Z",
    "host": "SERVER-A",
    "message": "date=2025-05-02 time=10:38:00 devname=SERVER-A severity=info msg='Test syslog message nr 1'",
    "facility": "local7",
    "NEU": "Zusatzfeld"
  },
  "fields": {
    "severity": [
      "info"
    ],
    "@timestamp": [
      "2025-10-06T09:00:00.000Z"
    ],
    "NEU.keyword": [
      "Zusatzfeld"
    ],
    "host": [
      "SERVER-A"
    ],
    "message": [
      "date=2025-05-02 time=10:38:00 devname=SERVER-A severity=info msg='Test syslog message nr 1'"
    ],
    "facility": [
      "local7"
    ],
    "NEU": [
      "Zusatzfeld"
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [October 6, 2025, 10:53am UTC](https://discuss.elastic.co/t/why-does-this-simple-search-in-kibana-work/382435/4 "2025-10-06T10:53:05Z")

</div>

Can I suggest you combine your various posts into one post (use edit feature) delete the others, and think about writing a clearer question. Maybe with a screenshot?

Please also share the mapping for the index, see below.

When I create the document you shared, the fields (al of them) get defined as text with a field.keyword subfield. Obviously I also don't know whats in your syslog\_deduplication pipeline.

```auto
GET /logs-test/_mapping
{
  "logs-test": {
    "mappings": {
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "NEU": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "facility": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "host": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "message": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "severity": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![smm](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@smm](https://discuss.elastic.co/u/smm)\
**Post date:** [October 7, 2025, 4:54am UTC](https://discuss.elastic.co/t/why-does-this-simple-search-in-kibana-work/382435/5 "2025-10-07T04:54:49Z")

</div>

Hi Kevin,

good points! …and thank you for testing it on your side.

Here are my results regarding the mapping:

```json
GET /logs-stefano/_mapping

{
  "logs-stefano": {
    "mappings": {
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "NEU": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "facility": {
          "type": "keyword"
        },
        "host": {
          "type": "keyword"
        },
        "message": {
          "type": "text"
        },
        "severity": {
          "type": "keyword"
        }
      }
    }
  }
}

```

Looking at the mapping: severity is only of type ‘keyword’. But then why can I use a wildcard search in a keyword type field? I thought this is not possible.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10b44fa177df1545bfe831a29c380ad12c92aeb2.png)

kind regards  
Stefano

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [October 7, 2025, 6:56am UTC](https://discuss.elastic.co/t/why-does-this-simple-search-in-kibana-work/382435/6 "2025-10-07T06:56:58Z")

</div>

Hello @smm

As you are searching it via Kibana (KQL) so it is able to fetch the record.

If we check the query executed by using inspect in Kibana it uses wildcard :

```auto
{
  "query": {
    "bool": {
      "must": [
        {
          "wildcard": {
            "agent.name": {
              "value": "j*va"
            }
          }
        }
      ]
    }
  }
}

```

If we execute the query via DSL it will not fetch records which is as per expectation of keyword field :

```auto
POST .ds-logs-apm.error-default-2025.09.18-000055/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "term": {
            "agent.name": "j*va"
          }
        }
      ]
    }
  }
}

No records

```

Thanks!!
