# Wildcard Search

**URL:** <https://community.graylog.org/t/wildcard-search/22161>\
**Category:** Graylog Central (peer support)\
**Created:** [December 23, 2021, 8:50am UTC](https://community.graylog.org/t/wildcard-search/22161 "2021-12-23T08:50:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![juris](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/juris/32/5920_2.png) [@juris](https://community.graylog.org/u/juris)\
**Post date:** [December 23, 2021, 8:50am UTC](https://community.graylog.org/t/wildcard-search/22161/1 "2021-12-23T08:50:52Z")

</div>

Trying to search with trailing wildcards in Graylog 4.2.4 and it does not work.

We have source fields like “app-12345-12345”  
So searching for “source:app\-12345\-12345” is ok  
searching for “source:app\-12345\-???” is ok  
but “source:app\-12345\-.\*” gives no results at all.

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [December 23, 2021, 12:18pm UTC](https://community.graylog.org/t/wildcard-search/22161/2 "2021-12-23T12:18:20Z")

</div>

There is a formatting tool for the forum `</>` that helps when posting code - usng that and putting in your queries:

```auto
"app-12345-12345"
"source:app\-12345\-12345"
"source:app\-12345\-???" 
"source:app\-12345\-.*"

```

I see in the last one you have a dot before the asterisk… regex style. You can remove the dot or you can change the search to be regex by bracketing it with `/` to denote regex… like so:

`source:/app\-12345\-.*/`

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [December 31, 2021, 12:20am UTC](https://community.graylog.org/t/wildcard-search/22161/3 "2021-12-31T00:20:58Z")

</div>

Note that leading wildcards are disabled to avoid excessive memory consumption! You can enable them in your Graylog configuration file:

`allow_leading_wildcard_searches = true`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 14, 2022, 12:21am UTC](https://community.graylog.org/t/wildcard-search/22161/4 "2022-01-14T00:21:54Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
