LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

Why is a search with a leading wildcard such as *ing or *error* especially expensive?

Because the index is sorted by the beginning of each term: a known prefix lets the engine jump straight to matching terms, but a leading wildcard forces it to examine every term in the index.

Sorted term list: fail* jumps to a contiguous block, *ing has to check every term

* A known prefix is a jump; a leading wildcard is a full scan. *

An inverted index works like a dictionary's word list. For fail* the engine goes to the spot where terms starting with fail begin and reads until they end, which is quick. For *ing there is no starting spot: any term anywhere might end in "ing", so every term has to be checked. On an index holding billions of log events, that turns a millisecond lookup into a full scan.

The same rule applies in Splunk's advice to search fatal_error rather than *error*, and in SQL, where LIKE 'abc%' can use an index but LIKE '%abc' cannot. The fix is to search a more specific term, or, if suffix searches are needed often, to index the data so that the part you search for becomes its own field.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026