# Wildcard Queries Vs Query\_string Queries

**URL:** <https://discuss.elastic.co/t/wildcard-queries-vs-query-string-queries/322692>\
**Category:** Elasticsearch\
**Created:** [January 9, 2023, 1:07am UTC](https://discuss.elastic.co/t/wildcard-queries-vs-query-string-queries/322692 "2023-01-09T01:07:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sheharyar\_Khalid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sheharyar_khalid/32/112227_2.png) [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Post date:** [January 9, 2023, 1:07am UTC](https://discuss.elastic.co/t/wildcard-queries-vs-query-string-queries/322692/1 "2023-01-09T01:07:26Z")

</div>

Hello,

I am looking for wildcard matching of events on log data in elasticsearch. For example i want to match IP addresses in my data but I only know the ending address (i want to match to 192.100.1.1 but i search for \*.1.1).

I wanted to know if there is any **difference** (logically or implementation wise) if I am using **query string query**

```auto

{"bool": {"must" : [{"query_string": {"query": "*something"}},{"match": {"message.type": "RECORD_EVENT"}}]}})

```

Or if I am using **wildcard query**

```auto
{"bool": {"must" : [{"wildcard": {"_all": "*something"}},{"match": {"message.type": 
"RECORD_EVENT"}}]}})

```

Also, is there any way to speed up such queries? (I am using the default analyzer and tokenizer)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 9, 2023, 5:21am UTC](https://discuss.elastic.co/t/wildcard-queries-vs-query-string-queries/322692/2 "2023-01-09T05:21:39Z")

</div>

> [@Sheharyar\_Khalid](#):
>
> I wanted to know if there is any **difference** (logically or implementation wise) if I am using **query string query**

I do not know of differences in implementation, but in both cases you will be looking for terms based on leading wildcard, and leading wildcard queries are the most expensive and inefficient type of query in Elasticsearch.

> [@Sheharyar\_Khalid](#):
>
> Also, is there any way to speed up such queries? (I am using the default analyzer and tokenizer)

The only way I am aware of to speed it up is is to change your mappings and start using the [wildcard field type](https://www.elastic.co/guide/en/elasticsearch/reference/8.5/keyword.html#wildcard-field-type), especially if you have a large field or high cardinality.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2023, 5:22am UTC](https://discuss.elastic.co/t/wildcard-queries-vs-query-string-queries/322692/3 "2023-02-06T05:22:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
