# Wildcard search in field doesn't work as expected

**URL:** <https://discuss.elastic.co/t/wildcard-search-in-field-doesnt-work-as-expected/289365>\
**Category:** Kibana\
**Created:** [November 16, 2021, 8:26pm UTC](https://discuss.elastic.co/t/wildcard-search-in-field-doesnt-work-as-expected/289365 "2021-11-16T20:26:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lchan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lchan/32/90857_2.png) [@lchan](https://discuss.elastic.co/u/lchan)\
**Post date:** [November 16, 2021, 8:26pm UTC](https://discuss.elastic.co/t/wildcard-search-in-field-doesnt-work-as-expected/289365/1 "2021-11-16T20:26:40Z")

</div>

Hi all,

I am on 7.13.1 on ElasticCloud. I mapped hostname via Logstash with syslog but for some reason the KQL search doesn't come out right. What am I doing wrong?

search:  
hostname: cr1-ams1

Result:  
cr1-ams1  
cr2-ams1  
ams1-foo  
ams1-bar

search:  
hostname: cr1\*ams1

Result:  
None

```auto
  grok {
    match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
    }

```

---

<div class="post-metadata">

**Author:** ![brianseeders](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brianseeders/32/84831_2.png) [@brianseeders](https://discuss.elastic.co/u/brianseeders)\
**Post date:** [November 22, 2021, 9:44pm UTC](https://discuss.elastic.co/t/wildcard-search-in-field-doesnt-work-as-expected/289365/3 "2021-11-22T21:44:47Z")

</div>

Hey @lchan,

If you search `hostname: "cr1-ams1"` with the quotes, you should only see entries with the hostname matching exactly `cr1-ams1`.

As for the wildcard, check this documentation: [Kibana Query Language | Kibana Guide [7.15] | Elastic](https://www.elastic.co/guide/en/kibana/7.15/kuery-query.html#_wildcard_queries)

Wildcards can only be used to specify a search prefix, i.e. they only work if they are the last character in the search string. For example, `cr1*` would match everything that begins with `cr1`.

Let me know if this helps.

Brian

---

<div class="post-metadata">

**Author:** ![lchan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lchan/32/90857_2.png) [@lchan](https://discuss.elastic.co/u/lchan)\
**Post date:** [November 23, 2021, 9:14pm UTC](https://discuss.elastic.co/t/wildcard-search-in-field-doesnt-work-as-expected/289365/4 "2021-11-23T21:14:42Z")

</div>

Hi @brianseeders ,

I fixed the issue by adding . keyword to the field. I was told it is required to add . keyword in order to perform wildcard search such as `cr*ams1`

Leo

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2021, 9:15pm UTC](https://discuss.elastic.co/t/wildcard-search-in-field-doesnt-work-as-expected/289365/5 "2021-12-21T21:15:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
