Company
Date Published
Author
Mark Harwood
Word count
2515
Language
-
Hacker News points
None

Summary

Elasticsearch 7.9 introduces a new "wildcard" field type designed to enhance the efficiency of finding patterns within string values, particularly beneficial for indexing and searching logs and security data. This field type simplifies search expressions and indexing processes, offering faster searches and reduced disk usage without altering query syntax. Unlike traditional text and keyword fields, the wildcard field excels in partial matches and infix searches while eliminating size limitations and improving performance for high-cardinality fields. It employs an "n-gram" indexing method and binary doc value store to quickly narrow down search candidates, making it a suitable replacement for keyword fields in certain scenarios. The new field type is expected to be integrated into the Elastic Common Schema, potentially offering faster search capabilities in future updates without requiring changes to client applications.