> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Glob syntax

> Use glob wildcard patterns such as *, ?, and brackets to match and filter values in Cortex XCOR queries.

Glob patterns specify sets of filenames with wildcard characters. The most common
wildcards are `*`, `?`, and `[ ... ]`. You can negate any pattern by prefixing it with a
`!`.

<Note>
  Palo Alto Networks Cortex XCOR glob syntax doesn't support using two asterisks where one of
  them is in the middle of a string. For example, `*k8s*staging` isn't valid.
</Note>

<Note>
  Regular expression syntax and glob syntax are not interchangeable. Cortex XCOR
  supports only one of these query matching patterns in
  supported areas of the product. For example,
  [drop rules](/control/shaping/shape-metrics/rules/drop-rules#create-a-drop-rule) support glob
  syntax, whereas [recording rules](/control/shaping/shape-metrics/rules/recording) support
  regular expression syntax.
</Note>

| Wildcard | Description | Example | Matches | Doesn't match |
| :- | :- | :- | :- | :- |
| `*` | Matches any number of any characters, including none. | `Law\*`<br />`\*Law\*`<br />`L\*aw` | `Law`, `Laws`, or `Lawyer`<br />`Law`, `GrokLaw`, or `Lawyer`<br />`Law` or `Laaw` | `GrokLaw`, `La`, or `aw`<br />`La` or `aw`<br />`La` or `Laws` |
| `?` | Matches any single character. | `?at` | `Cat`, `cat`, `Bat`, or `bat` | `at` |
| `[abc]` | Matches one character given in the bracket. | `\[CB]at` | `Cat` or `Bat` | `cat`, `bat`, or `CBat` |
| `[a-z]` | Matches one character from the (locale-dependent) range given in the bracket. | `Letter\[0-9]` | `Letter0`, `Letter1`, `Letter2`, up to `Letter9` | `Letters`, `Letter`, or `Letter10` |
| `{a,b}` | Matches one word given in the braces. | `\{pass,word}` | `pass`, `word` | `password`, `passing` |

*Table sourced from [Wikipedia](https://en.wikipedia.org/wiki/Glob_\(programming\)).*

For more pattern matching specifics, see the
[Glob primer](https://github.com/isaacs/node-glob#glob-primer).


## Related topics

- [Drop rules](/control/shaping/shape-metrics/rules/drop-rules.md)
- [Regular expressions](/investigate/querying/regular-expressions.md)
- [Search and query metrics](/investigate/querying/metrics.md)
- [Analyze live traffic metrics](/investigate/analyze/telemetry-analyzer.md)
- [Derived labels](/investigate/querying/metrics/derived-telemetry/derived-labels.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.