# Wildacard (.\*) is not giving as expected result

**URL:** <https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230>\
**Category:** Kibana\
**Created:** [January 5, 2018, 7:45am UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230 "2018-01-05T07:45:27Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![saravanan\_kutty](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@saravanan\_kutty](https://discuss.elastic.co/u/saravanan_kutty)\
**Post date:** [January 5, 2018, 7:45am UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/1 "2018-01-05T07:45:28Z")

</div>

Recently i used hostname: ".\*" which doesnt give any result surprisingly, since two weeks back it was working perfect.

is there anything i am missing here and i need to have work around for it.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 8, 2018, 11:31am UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/2 "2018-01-08T11:31:27Z")

</div>

Hi @saravanan_kutty,

the [wildcards](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#_wildcards) as used in your query are not regular expression patterns. As such, the query would match all hostnames that start with a dot. Is that your intention?

---

<div class="post-metadata">

**Author:** ![saravanan\_kutty](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@saravanan\_kutty](https://discuss.elastic.co/u/saravanan_kutty)\
**Post date:** [January 8, 2018, 1:47pm UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/3 "2018-01-08T13:47:36Z")

</div>

for eg: application: "myapplication" AND hostname: (".\*")-\> list all the host under "myapplication"

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 8, 2018, 3:15pm UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/4 "2018-01-08T15:15:18Z")

</div>

`.*` here means "match all hostnames that start with a `.`" assuming that field was indexed as a keyword. Otherwise the analyzer would probably remove the `.` as punctuation.

Maybe you can give us an example of one or two documents that you want to filter for?

---

<div class="post-metadata">

**Author:** ![saravanan\_kutty](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@saravanan\_kutty](https://discuss.elastic.co/u/saravanan_kutty)\
**Post date:** [January 9, 2018, 8:38am UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/5 "2018-01-09T08:38:11Z")

</div>

we have indexed the hostname,application as keyword.

{  
"query": {  
"match": {  
"hostname": {  
"query": ".\*",  
"type": "phrase"  
}  
}  
}  
}

{  
"query": {  
"match": {  
"clustername": {  
"query": "mycluster",  
"type": "phrase"  
}  
}  
}  
}

we just wanna know how to filter all hostname irrespective of what it start with specific cluster.

---

<div class="post-metadata">

**Author:** ![saravanan\_kutty](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@saravanan\_kutty](https://discuss.elastic.co/u/saravanan_kutty)\
**Post date:** [January 11, 2018, 5:49am UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/6 "2018-01-11T05:49:32Z")

</div>

@weltenwort did i answered your question.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 15, 2018, 4:09pm UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/7 "2018-01-15T16:09:15Z")

</div>

If you don't want to use a field `hostname` as a filtering criterion, you can just not mention it in the query. So assuming you have keyword fields `hostname`, `clustername` and `applicationname`, you should be able to query them using simple queries like this: `clustername:cluster1 AND (applicationname:application1 OR applicationname:application2)`.

Sorry if I still don't understand you correctly. Maybe a sample of the documents would make it clearer to me.

---

<div class="post-metadata">

**Author:** ![saravanan\_kutty](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@saravanan\_kutty](https://discuss.elastic.co/u/saravanan_kutty)\
**Post date:** [January 17, 2018, 7:56am UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/8 "2018-01-17T07:56:48Z")

</div>

@weltenwort  
We are programmatically handle the kibana url, so building a generic Kibana URL there we will be having assigning values to a variable for keyword. For few keyword we don’t have value to assign to variable.

Here is the challenge to assign a value to variable for keyword which doesn’t have a value, we can’t have null value to it. A month back this url is working when we used to give (“.\*”) as value for which there is no value. I Wonder all of the sudden this is not working

 ![kibana](https://us1.discourse-cdn.com/elastic/original/3X/7/7/771c4be8bd8993eb148f2b15cc3324fe452841fd.JPG)

Now we need to find Work around for this wildcard.

---

<div class="post-metadata">

**Author:** ![saravanan\_kutty](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@saravanan\_kutty](https://discuss.elastic.co/u/saravanan_kutty)\
**Post date:** [January 31, 2018, 11:21am UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/9 "2018-01-31T11:21:46Z")

</div>

@weltenwort got any clues?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2018, 11:21am UTC](https://discuss.elastic.co/t/wildacard-is-not-giving-as-expected-result/114230/10 "2018-02-28T11:21:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
