# Wildcard \* is not working on the kibana discover search

**URL:** <https://discuss.elastic.co/t/wildcard-is-not-working-on-the-kibana-discover-search/58751>\
**Category:** Kibana\
**Created:** [August 23, 2016, 10:01pm UTC](https://discuss.elastic.co/t/wildcard-is-not-working-on-the-kibana-discover-search/58751 "2016-08-23T22:01:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nanshan](https://avatars.discourse-cdn.com/v4/letter/n/858c86/32.png) [@nanshan](https://discuss.elastic.co/u/nanshan)\
**Post date:** [August 23, 2016, 10:01pm UTC](https://discuss.elastic.co/t/wildcard-is-not-working-on-the-kibana-discover-search/58751/1 "2016-08-23T22:01:26Z")

</div>

for example: `source: "/var/log/containers/greyhound-segment*.log"`, using kibana 4.

Anyone is experiencing the same frustrating issue\>?

I also noticed this error on the Kibana page  
`This field is present in your elasticsearch mapping but not in any documents in the search results. You may still be able to visualize or search on it.`

Does it relate to the issue ?

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [August 24, 2016, 3:06pm UTC](https://discuss.elastic.co/t/wildcard-is-not-working-on-the-kibana-discover-search/58751/2 "2016-08-24T15:06:32Z")

</div>

Hi Nanshan,

If you are on the Discover tab and you only have `*` in the query bar, then you get results?

And on the left panel in Discover you have a field named "source" in the field list?

If you check on the Settings tab, click on your index pattern, and then it will show the list of fields. You can type `source` in the filter bar to more quickly find the field if there's a lot.  
Do you see a field named `_source` and one named `source`?  
And if you do have one named `source` is it `analyzed` and `indexed` or just `indexed`?

If you only have `_source` shown, then you would just put `/var/log/containers/greyhound-segment*.log` in the query bar (not the `source:` part and no double-quotes).

If you do have a `source` field and it's analyzed, it would have split that log file path into individual fields on the slashes. So in that case you could try searching for `source: /var/log/containers/greyhound-segment*.log` it will return every doc where source contains `var` or `log` or `containers` or `greyhound-segment*.log`.

If you really need to search on the full path, you would need an unanalyzed field like source.raw (maybe you saw that in your field list for this index?).

Here's a link to a page that explains it very well;

> **[Elasticsearch/Kibana Queries - In Depth Tutorial](https://www.timroes.de/2016/05/29/elasticsearch-kibana-queries-in-depth-tutorial/#using-json-in-the-kibana-search)**
>
> This tutorial explains how to write and understand Kibana and Elasticsearch queries
> in depth and how the mapping of Elastichsearch influences these queries.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![nanshan](https://avatars.discourse-cdn.com/v4/letter/n/858c86/32.png) [@nanshan](https://discuss.elastic.co/u/nanshan)\
**Post date:** [August 24, 2016, 7:44pm UTC](https://discuss.elastic.co/t/wildcard-is-not-working-on-the-kibana-discover-search/58751/3 "2016-08-24T19:44:23Z")

</div>

Thanks for explaining, Lee.

I noticed if I search `source: "/var/log/containers/greyhound-segment\*" , it can work

I am wondering what is wrong by adding `.log` at the end

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:40pm UTC](https://discuss.elastic.co/t/wildcard-is-not-working-on-the-kibana-discover-search/58751/4 "2017-07-06T13:40:23Z")

</div>


