# Are Elasticsearch regular expressions PRCE comatible?

**URL:** https://discuss.elastic.co/t/are-elasticsearch-regular-expressions-prce-comatible/155793
**Category:** Kibana
**Created:** [November 7, 2018, 8:55pm UTC](https://discuss.elastic.co/t/are-elasticsearch-regular-expressions-prce-comatible/155793 "2018-11-07T20:55:17Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![solarwinds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/solarwinds/32/37390_2.png) [@solarwinds](https://discuss.elastic.co/u/solarwinds)
#### Post date: [November 7, 2018, 8:55pm UTC](https://discuss.elastic.co/t/are-elasticsearch-regular-expressions-prce-comatible/155793/1 "2018-11-07T20:55:17Z")

</div>

Hi all,

I am using ElasticStack to monitor various process including Java processes. In this particular case, I am searching for Kafka process.

Using [online regex tester](https://regex101.com/r/96b53M/1), I am able to get a match, but my regex never gets hit when querying data in Kibana. Document with full path is already present in ES.

Is such behavior specific to Kibana or Elasticsearch (Lucene query syntax)?

Thanks,

---

<div class="post-metadata">

### Author: ![solarwinds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/solarwinds/32/37390_2.png) [@solarwinds](https://discuss.elastic.co/u/solarwinds)
#### Post date: [November 7, 2018, 9:02pm UTC](https://discuss.elastic.co/t/are-elasticsearch-regular-expressions-prce-comatible/155793/2 "2018-11-07T21:02:28Z")

</div>

Sorry. It looks like that I have posted my question in wrong topic. Can some one please move it to Kibana?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [November 7, 2018, 9:03pm UTC](https://discuss.elastic.co/t/are-elasticsearch-regular-expressions-prce-comatible/155793/3 "2018-11-07T21:03:08Z")

</div>

As [per the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/query-dsl-regexp-query.html#regexp-syntax) they are not Perl-compatible.

---

<div class="post-metadata">

### Author: ![solarwinds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/solarwinds/32/37390_2.png) [@solarwinds](https://discuss.elastic.co/u/solarwinds)
#### Post date: [November 7, 2018, 9:11pm UTC](https://discuss.elastic.co/t/are-elasticsearch-regular-expressions-prce-comatible/155793/4 "2018-11-07T21:11:09Z")

</div>

Hello Christian. That was quick, I have spent at least one hour going through the exact documentation. So, basically, I should stick with Lucene documentation regarding the regular expressions.

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [November 7, 2018, 9:13pm UTC](https://discuss.elastic.co/t/are-elasticsearch-regular-expressions-prce-comatible/155793/5 "2018-11-07T21:13:07Z")

</div>

I believe so. Be aware however that using regular expression searches can be very slow and scale badly. It would be a lot faster if you could parse out parts you know are going to be interested in at index time.

---

<div class="post-metadata">

### Author: ![solarwinds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/solarwinds/32/37390_2.png) [@solarwinds](https://discuss.elastic.co/u/solarwinds)
#### Post date: [November 7, 2018, 9:21pm UTC](https://discuss.elastic.co/t/are-elasticsearch-regular-expressions-prce-comatible/155793/6 "2018-11-07T21:21:29Z")

</div>

Yes, I was afraid of that. Both parts, Lucene and slow queries.

To be honest, I am not sure what do you mean under, "parse out parts". I am already filtering the documents in following way:

beat.hostname: "some.hostname" AND system.process.name: java AND system.process.cmdline: myregex\_query\_that\_doesnt\_work.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 5, 2018, 9:21pm UTC](https://discuss.elastic.co/t/are-elasticsearch-regular-expressions-prce-comatible/155793/7 "2018-12-05T21:21:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
