# Wildcard filter on a Windows path

**URL:** <https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035>\
**Category:** Elasticsearch\
**Created:** [December 8, 2020, 6:40pm UTC](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035 "2020-12-08T18:40:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 8, 2020, 6:40pm UTC](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/1 "2020-12-08T18:40:27Z")

</div>

Hello,

I'm trying to create a wildcard filter that filters on paths starting with c:\git\*

But:

```
{
  "query": {
    "wildcard": {
      "process.working_directory": {
        "value": "c:\\git\\*"
      }
    }
  }
}

```

is not working. And escaping the ':', as suggested in [Wildcard query with a file path - Search for c:\users\public\*](https://discuss.elastic.co/t/wildcard-query-with-a-file-path-search-for-c-users-public/150384) results in:

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/e/be406ac8db49487161efb8f7ce2e395efa5bcae4.png)

How should I handle this?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [December 14, 2020, 7:00am UTC](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/2 "2020-12-14T07:00:47Z")

</div>

I don't think the colon needs to be escaped in the query DSL value. It needs to be escaped in the linked topic because `:` is part of the Lucene query parser syntax which separates a target `field` from the search term.

When you say "is not working", does

- the query DSL not return the expected results?
- an error occur in Elasticsearch?

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 14, 2020, 11:02am UTC](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/3 "2020-12-14T11:02:51Z")

</div>

Thanks for your answer @forloop

When I use the following in a Kibana KQL query:

`process.working_directory : C:\\WINDOWS\\*`

It does not work, but when I escape the colon:

`process.working_directory : C\:\\WINDOWS\\*`

I'm getting the expected results. But in Elastic detections I cannot work with a query and I need to exclude with a filter based on a combination of process.name and process.working\_directory.

But when I use a filter with a wildcard query, I never seem to get the expected results.

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0f48eb4558d913e603b5dba821623c6b4c3dd722.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/e/ce8307add2c3c448626fd1390dab6e0259c221f0.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/2598d01b97c12471b2a79fe3b1a082a799d2955a.png)

All of the above does not filter on `c:\WINDOWS\*`

So how should I format a wildcard filter containing backslashes, so I can use it in a Kibana filter?

Willem

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [January 2, 2021, 3:48pm UTC](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/4 "2021-01-02T15:48:17Z")

</div>

_(autoclose-prevention)_

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2021, 3:48pm UTC](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/5 "2021-01-30T15:48:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
