# Wildcards and mapping in query\_string query

**URL:** <https://discuss.elastic.co/t/wildcards-and-mapping-in-query-string-query/140709>\
**Category:** Elasticsearch\
**Created:** [July 19, 2018, 11:09am UTC](https://discuss.elastic.co/t/wildcards-and-mapping-in-query-string-query/140709 "2018-07-19T11:09:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![chaloulo](https://avatars.discourse-cdn.com/v4/letter/c/e9bcb4/32.png) [@chaloulo](https://discuss.elastic.co/u/chaloulo)\
**Post date:** [July 19, 2018, 11:09am UTC](https://discuss.elastic.co/t/wildcards-and-mapping-in-query-string-query/140709/1 "2018-07-19T11:09:25Z")

</div>

Hello,

I have a case where I use wildcards in the query\_string query. I am seeing a behaviour that I can't explain.  
I create simple index like the following:

```
curl -x "" -k -XPUT 'localhost:9200/wildcardtest' -d '{
  "mappings": {
    "tweet": {
      "properties": {
        "message_not_analyzed": {
          "type": "string",
          "index": "not_analyzed"
        },
        "message_analyzed": {
          "type": "string",
          "index": "analyzed"
        }
      }
    }
  }
}'

```

Then I put one document:  
curl -x "" -XPUT localhost:9200/wildcardtest/tweet/1 -d '{  
"message\_not\_analyzed": "M1000",  
"message\_analyzed": "M1000"  
}'

Then I search. The match\_all query matches:  
$ curl -x "" localhost:9200/wildcardtest/\_search -d '{  
\> "query" : {  
\> "match\_all" : {}  
\> }  
\> }'  
{"took":116,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":1,"max\_score":1.0,"hits":[{"\_index":"wildcardtest","\_type":"tweet","\_id":"1","\_score":1.0,"\_source":{  
"message\_not\_analyzed": "M1000",  
"message\_analyzed": "M1000"  
}}]}}

Then I use the query\_string with a wildcard on the analyzed field and it matches:  
curl -x "" localhost:9200/wildcardtest/\_search -d '{  
\> "query" : {  
\> "query\_string" : { "default\_field" : "message\_analyzed", "query" : "M1\*" }  
\> }  
\> }'  
{"took":10,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":1,"max\_score":1.0,"hits":[{"\_index":"wildcardtest","\_type":"tweet","\_id":"1","\_score":1.0,"\_source":{  
"message\_not\_analyzed": "M1000",  
"message\_analyzed": "M1000"  
}}]}}

However when I query in the "message\_analyzed" field with wildcard, it does not match:  
$ curl -x "" localhost:9200/wildcardtest/\_search -d '{  
\> "query" : {  
\> "query\_string" : { "default\_field" : "message\_not\_analyzed", "query" : "M1\*" }  
\> }  
\> }'  
{"took":14,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":[]}}

If I change the query to "M\*", it matches:  
$ curl -x "" localhost:9200/wildcardtest/\_search -d '{  
"query" : {  
"query\_string" : { "default\_field" : "message\_analyzed", "query" : "M\*" }  
}  
}'  
{"took":18,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":1,"max\_score":1.0,"hits":[{"\_index":"wildcardtest","\_type":"tweet","\_id":"1","\_score":1.0,"\_source":{  
"message\_not\_analyzed": "M1000",  
"message\_analyzed": "M1000"  
}}]}}

Can anyone explain the above behaviour?

Best regards,

Klearchos

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 19, 2018, 9:14pm UTC](https://discuss.elastic.co/t/wildcards-and-mapping-in-query-string-query/140709/2 "2018-07-19T21:14:50Z")

</div>

My guess is that the default analyzer has indexed `M1000` to `m` and `1000` probably.

Use the `_analyze` API to understand what is happening behind the scene.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2018, 9:14pm UTC](https://discuss.elastic.co/t/wildcards-and-mapping-in-query-string-query/140709/3 "2018-08-16T21:14:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
