# Applying analyzer in filter elasticsearch

**URL:** <https://discuss.elastic.co/t/applying-analyzer-in-filter-elasticsearch/182598>\
**Category:** Logstash\
**Created:** [May 24, 2019, 9:23am UTC](https://discuss.elastic.co/t/applying-analyzer-in-filter-elasticsearch/182598 "2019-05-24T09:23:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [May 24, 2019, 9:23am UTC](https://discuss.elastic.co/t/applying-analyzer-in-filter-elasticsearch/182598/1 "2019-05-24T09:23:43Z")

</div>

Hello.  
I am attempting to enrich my data with ES lookup when the URL appears in my log line.

> if [url]{  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> index =\> "url\_lookup"  
> query\_template =\> "/etc/logstash/conf.d/query\_templates/url\_matching.json"  
> fields =\> { "url" =\> "matched\_url" }  
> }  
> }

my url\_matching.json  
{  
"query": {  
"query\_string": {  
"query": "url:%{[url]}"  
}  
}  
}

In the URL we have a special characters that we need to escape:

> **[Query string query | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#_reserved_characters)**

Is there a way to use analyzer to do that job for me in this use case?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2019, 9:23am UTC](https://discuss.elastic.co/t/applying-analyzer-in-filter-elasticsearch/182598/2 "2019-06-21T09:23:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
