# Wildcard filter on a Windows path

**URL:** <https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035>\
**Category:** Elasticsearch\
**Created:** [December 8, 2020, 6:40pm UTC](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035 "2020-12-08T18:40:26Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 14, 2020, 11:02am UTC](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035/3 "2020-12-14T11:02:51Z")

</div>

Thanks for your answer @forloop

When I use the following in a Kibana KQL query:

`process.working_directory : C:\\WINDOWS\\*`

It does not work, but when I escape the colon:

`process.working_directory : C\:\\WINDOWS\\*`

I'm getting the expected results. But in Elastic detections I cannot work with a query and I need to exclude with a filter based on a combination of process.name and process.working\_directory.

But when I use a filter with a wildcard query, I never seem to get the expected results.

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0f48eb4558d913e603b5dba821623c6b4c3dd722.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/e/ce8307add2c3c448626fd1390dab6e0259c221f0.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/2598d01b97c12471b2a79fe3b1a082a799d2955a.png)

All of the above does not filter on `c:\WINDOWS\*`

So how should I format a wildcard filter containing backslashes, so I can use it in a Kibana filter?

Willem

---

_[View the full topic](https://discuss.elastic.co/t/wildcard-filter-on-a-windows-path/258035)._
