# Wildcard search

**URL:** <https://discuss.elastic.co/t/wildcard-search/7550>\
**Category:** Elasticsearch\
**Created:** [May 3, 2012, 1:47pm UTC](https://discuss.elastic.co/t/wildcard-search/7550 "2012-05-03T13:47:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajan](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@ajan](https://discuss.elastic.co/u/ajan)\
**Post date:** [May 3, 2012, 1:47pm UTC](https://discuss.elastic.co/t/wildcard-search/7550/1 "2012-05-03T13:47:08Z")

</div>

curl [http://mysearchhost:9200/test/\_search?q=Identifier:](http://mysearchhost:9200/test/_search?q=Identifier:)_6099d3e1_  
returns successfully with hits, however

curl [http://mysearchhost:9200/test/\_search?q=Identifier:](http://mysearchhost:9200/test/_search?q=Identifier:)_ABC_6099d3e1\*  
does not return any hits

The Identifier value is actually  
tag:mytest:Test::ABCTest-6099d3e1-474a-49e2-bc14-ae816cf719ac

Is it not correct to have multiple "\*" wildcards in the request?

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [May 3, 2012, 10:45pm UTC](https://discuss.elastic.co/t/wildcard-search/7550/2 "2012-05-03T22:45:13Z")

</div>

First of all, you should avoid to use leading wildcards in a query for  
performance reasons.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Second, how is the Identifier field analyzed? Make sure it is not  
analyzed, or you would need to analyzed the wildcard query, which is  
also not recommended.

Is leading wildcards enabled by default in Elasticsearch? It is not in Lucene.

Ivan

On Thu, May 3, 2012 at 6:47 AM, ajan [jan.afzal@gmail.com](mailto:jan.afzal@gmail.com) wrote:

> curl [http://mysearchhost:9200/test/\_search?q=Identifier:\*6099d3e1](http://mysearchhost:9200/test/_search?q=Identifier:*6099d3e1)\*  
> returns successfully with hits, however
> 
> curl [http://mysearchhost:9200/test/\_search?q=Identifier:\*ABC\*6099d3e1](http://mysearchhost:9200/test/_search?q=Identifier:*ABC*6099d3e1)\*  
> does not return any hits
> 
> The Identifier value is actually  
> tag:mytest:Test::ABCTest-6099d3e1-474a-49e2-bc14-ae816cf719ac
> 
> Is it not correct to have multiple "\*" wildcards in the request?

---

<div class="post-metadata">

**Author:** ![ajan](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@ajan](https://discuss.elastic.co/u/ajan)\
**Post date:** [May 10, 2012, 3:32am UTC](https://discuss.elastic.co/t/wildcard-search/7550/3 "2012-05-10T03:32:44Z")

</div>

Thanks for your response Ivan.

I'm in total agreement that one should avoid use of leading wildcards  
in a query, however, how would one stop the use form providing such a  
query?

Second, this and all other fields are analyzed by the default  
analyzer, there is no specific analyzer for these fields.

I'm not sure if leading wildcards in enabled in ES?

Jan

On May 4, 3:45 am, Ivan Brusic [i...@brusic.com](mailto:i...@brusic.com) wrote:

> First of all, you should avoid to use leading wildcards in a query for  
> performance reasons.
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/wildcard-query)...
> 
> Second, how is the Identifier field analyzed? Make sure it is not  
> analyzed, or you would need to analyzed the wildcard query, which is  
> also not recommended.
> 
> Is leading wildcards enabled by default in Elasticsearch? It is not in Lucene.
> 
> Ivan
> 
> On Thu, May 3, 2012 at 6:47 AM, ajan [jan.af...@gmail.com](mailto:jan.af...@gmail.com) wrote:
> 
> > curlhttp://mysearchhost:9200/test/\_search?q=Identifier:_6099d3e1_  
> > returns successfully with hits, however
> 
> > curlhttp://mysearchhost:9200/test/\_search?q=Identifier:_ABC_6099d3e1\*  
> > does not return any hits
> 
> > The Identifier value is actually  
> > tag:mytest:Test::ABCTest-6099d3e1-474a-49e2-bc14-ae816cf719ac
> 
> > Is it not correct to have multiple "\*" wildcards in the request?

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [May 10, 2012, 5:55pm UTC](https://discuss.elastic.co/t/wildcard-search/7550/4 "2012-05-10T17:55:08Z")

</div>

True, sometimes leading wildcard searchers are unavoidable, but I tend  
to use them in diagnostic queries and not a query that is meant to be  
executed several times. Or use ngrams.

Query string queries with wildcards are not analyzed. You can set  
analyze\_wildcard:true, but I am not sure if it is possible via a  
search url.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

However, your fields are not in English (or any other language), so it  
makes sense to not have them analyzed and to use a WildcardQuery.

--  
Ivan

On Wed, May 9, 2012 at 8:32 PM, ajan [jan.afzal@gmail.com](mailto:jan.afzal@gmail.com) wrote:

> Thanks for your response Ivan.
> 
> I'm in total agreement that one should avoid use of leading wildcards  
> in a query, however, how would one stop the use form providing such a  
> query?
> 
> Second, this and all other fields are analyzed by the default  
> analyzer, there is no specific analyzer for these fields.
> 
> I'm not sure if leading wildcards in enabled in ES?
> 
> Jan
> 
> On May 4, 3:45 am, Ivan Brusic [i...@brusic.com](mailto:i...@brusic.com) wrote:
> 
> > First of all, you should avoid to use leading wildcards in a query for  
> > performance reasons.
> > 
> > [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/wildcard-query)...
> > 
> > Second, how is the Identifier field analyzed? Make sure it is not  
> > analyzed, or you would need to analyzed the wildcard query, which is  
> > also not recommended.
> > 
> > Is leading wildcards enabled by default in Elasticsearch? It is not in Lucene.
> > 
> > Ivan
> > 
> > On Thu, May 3, 2012 at 6:47 AM, ajan [jan.af...@gmail.com](mailto:jan.af...@gmail.com) wrote:
> > 
> > > curlhttp://mysearchhost:9200/test/\_search?q=Identifier:_6099d3e1_  
> > > returns successfully with hits, however
> > 
> > > curlhttp://mysearchhost:9200/test/\_search?q=Identifier:_ABC_6099d3e1\*  
> > > does not return any hits
> > 
> > > The Identifier value is actually  
> > > tag:mytest:Test::ABCTest-6099d3e1-474a-49e2-bc14-ae816cf719ac
> > 
> > > Is it not correct to have multiple "\*" wildcards in the request?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:29am UTC](https://discuss.elastic.co/t/wildcard-search/7550/5 "2017-07-06T03:29:24Z")

</div>


