# Wildcard index pattern matching non-system indices, 7.10.2 edition

**URL:** https://discuss.elastic.co/t/wildcard-index-pattern-matching-non-system-indices-7-10-2-edition/263934
**Category:** Kibana
**Created:** [February 10, 2021, 9:02pm UTC](https://discuss.elastic.co/t/wildcard-index-pattern-matching-non-system-indices-7-10-2-edition/263934 "2021-02-10T21:02:02Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)
#### Post date: [February 10, 2021, 9:02pm UTC](https://discuss.elastic.co/t/wildcard-index-pattern-matching-non-system-indices-7-10-2-edition/263934/1 "2021-02-10T21:02:02Z")

</div>

> [@Index pattern matching all non-system indices](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413/1):
>
> We would like to have an index pattern matching all of these, but discovered that `*` also matches the system indices.

Allegedly in Kibana 7.10.2 this pattern is supposed to match only user indices:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c171ea7e18da6a5cf8fd4631d09aa029efa79376.png)

but it's definitely picking up fields from system indices:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/1/f1a95c4be810d1a98339e36a52f94d8b07eaecf2.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d2009a9bc3297eb208361e7b369ed6feaf6ea634.png)

Is this _supposed_ to work now in 7+ or do we need to keep using [this workaround](https://discuss.elastic.co/t/index-pattern-matching-all-non-system-indices/110413)?

---

<div class="post-metadata">

### Author: ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)
#### Post date: [February 11, 2021, 11:37pm UTC](https://discuss.elastic.co/t/wildcard-index-pattern-matching-non-system-indices-7-10-2-edition/263934/2 "2021-02-11T23:37:11Z")

</div>

Hi Michael. Using the index alias is one way to resolve this. But you can also create a new index pattern and specify multiple patterns separated by commas (e.g. metricbeat-_,auditbeat-_).

---

<div class="post-metadata">

### Author: ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)
#### Post date: [March 4, 2021, 7:23pm UTC](https://discuss.elastic.co/t/wildcard-index-pattern-matching-non-system-indices-7-10-2-edition/263934/3 "2021-03-04T19:23:37Z")

</div>

That would work OK if all the names are known in advance.

The frustrating thing about this is that Kibana has this option:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e990261e9a0ad9d6176654b66b8a6794693ef8ca.png)  
which just doesn't seem to be functional.

---

<div class="post-metadata">

### Author: ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)
#### Post date: [March 4, 2021, 9:11pm UTC](https://discuss.elastic.co/t/wildcard-index-pattern-matching-non-system-indices-7-10-2-edition/263934/4 "2021-03-04T21:11:14Z")

</div>

Hi Michael,

Today I learned something new. [We can ignore indices using a minus sign](https://www.elastic.co/guide/en/kibana/current/index-patterns.html#settings-create-pattern). System indices are prefixed with a `.`. So we should be able to ignore those indices using an index pattern like this: `*,-.*`.

---

<div class="post-metadata">

### Author: ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)
#### Post date: [March 9, 2021, 5:30pm UTC](https://discuss.elastic.co/t/wildcard-index-pattern-matching-non-system-indices-7-10-2-edition/263934/5 "2021-03-09T17:30:12Z")

</div>

But this workaround shouldn't be necessary since those are system/hidden indices?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 6, 2021, 5:30pm UTC](https://discuss.elastic.co/t/wildcard-index-pattern-matching-non-system-indices-7-10-2-edition/263934/6 "2021-04-06T17:30:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
