Search queries apply the rules and syntax of regular expressions, syslog-ng does not govern the methods how these queries are interpreted.
Syslog-ng primarily uses POSIX Extended Regular Expressions (ERE).
In some cases if the syslog-ng configuration is done as per the admin guide using "" (double quotes) the filtering won't work as expected.