Hi @dulanism!!
With this link in docs there is a statement below that points to Elastic version 2… since we are on Elastic 7 we should likely update the link and maybe check to make sure the statement is still relevant while we are at it!
Also note that message
, full_message
, and source
are the only fields that are being analyzed by default.While wildcard searches (using *
and ?
) work on all indexed fields, analyzed fields will behave a little bit different.See wildcard and regexp queries for details.
Found on page: