Hi @dulanism!! 
With this link in docs there is a statement below that points to Elastic version 2… since we are on Elastic 7 we should likely update the link and maybe check to make sure the statement is still relevant while we are at it!
Also note that message , full_message , and source are the only fields that are being analyzed by default.While wildcard searches (using * and ? ) work on all indexed fields, analyzed fields will behave a little bit different.See wildcard and regexp queries for details.
Found on page: