# Searching question

**URL:** <https://community.graylog.org/t/searching-question/2917>\
**Category:** Graylog Central (peer support)\
**Created:** [October 25, 2017, 9:00pm UTC](https://community.graylog.org/t/searching-question/2917 "2017-10-25T21:00:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mantil](https://avatars.discourse-cdn.com/v4/letter/m/ecd19e/32.png) [@Mantil](https://community.graylog.org/u/Mantil)\
**Post date:** [October 25, 2017, 9:00pm UTC](https://community.graylog.org/t/searching-question/2917/1 "2017-10-25T21:00:05Z")

</div>

Have a quick search question. Having trouble matching anything with a wildcard after a specific string in a field. Here is an example that works.

```
cs-host:nmvtis.ssy.local AND cs-uri-stem:\/api\/vin\/VHR\/99999999\/2D4GP43LX5R341187

```

I haven’t been able to get a trailing wildcard to work at all in this context. Is this not allowed?

```
cs-host:nmvtis.ssy.local AND cs-uri-stem:\/api\/vin\/VHR\/99999999\/2D4GP43LX5R34118*

```

I feel like I’m missing something terribly simple here as I feel I have had successful widcard searches previously against other fields.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [October 26, 2017, 6:53am UTC](https://community.graylog.org/t/searching-question/2917/2 "2017-10-26T06:53:42Z")

</div>

The way you can query fields depends on how which tokenizer and which analyzer have been used when indexing the message.

[https://www.elastic.co/guide/en/elasticsearch/reference/5.6/analysis-analyzers.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/analysis-analyzers.html)  
[https://www.elastic.co/guide/en/elasticsearch/guide/current/analysis-intro.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/analysis-intro.html)  
[https://www.elastic.co/guide/en/elasticsearch/guide/current/configuring-analyzers.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/configuring-analyzers.html)

---

<div class="post-metadata">

**Author:** ![Mantil](https://avatars.discourse-cdn.com/v4/letter/m/ecd19e/32.png) [@Mantil](https://community.graylog.org/u/Mantil)\
**Post date:** [October 26, 2017, 6:49pm UTC](https://community.graylog.org/t/searching-question/2917/3 "2017-10-26T18:49:31Z")

</div>

Thank you for the Reply Jochen. I’ll take a look at these. I’m guilty of looking first at Graylog documentation and forget too quickly that elasticsearch documentation may have my answers.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [November 9, 2017, 6:50pm UTC](https://community.graylog.org/t/searching-question/2917/4 "2017-11-09T18:50:09Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
