# Check pattern in scripted field

**URL:** <https://discuss.elastic.co/t/check-pattern-in-scripted-field/276158>\
**Category:** Elasticsearch\
**Tags:** painless\
**Created:** [June 16, 2021, 3:34pm UTC](https://discuss.elastic.co/t/check-pattern-in-scripted-field/276158 "2021-06-16T15:34:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![goncalobsantos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/goncalobsantos/32/50118_2.png) [@goncalobsantos](https://discuss.elastic.co/u/goncalobsantos)\
**Post date:** [June 16, 2021, 3:34pm UTC](https://discuss.elastic.co/t/check-pattern-in-scripted-field/276158/1 "2021-06-16T15:34:05Z")

</div>

I have a field "a" that sometimes gets values that satisfy the following pattern: "AAA\_BBB\_CCC\_DDD".

The relevant feature of this pattern is the occurrence of the four underscores "\_". The lenght of the A's, B's, C's and D's may vary.

I'm trying to define a scripted field that provides a certain output when the value of field "a" satisfies this pattern (i.e. contains four underscores). The problem is that I'm not describing the pattern correctly.

My idea is:

```auto
def c =""; 
def b = doc['a.keyword'].value;
def first = b.indexOf('_');
if (doc['a.keyword'].value=='*_*_*_*') 
{c = b.substring(0,first);}
else {c = 0;}
return c

```

This scripted field now outputs 0 for all entries and this shouldn't be the case. The condition`(doc['a.keyword'].value=='*_*_*_*')` is never satisfied, which implies that the relevant pattern is not being well described by `'*_*_*_*'`.

Any ideas or suggestions on how to do this?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![angelo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelo/32/61325_2.png) [@angelo](https://discuss.elastic.co/u/angelo)\
**Post date:** [June 16, 2021, 9:03pm UTC](https://discuss.elastic.co/t/check-pattern-in-scripted-field/276158/2 "2021-06-16T21:03:18Z")

</div>

If you are trying to check against a regex style pattern, the syntax is incorrect and should be something like: `if (doc['a.keyword'].value ==~ /\w+_\w+_\w+_\w+/)`

---

<div class="post-metadata">

**Author:** ![goncalobsantos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/goncalobsantos/32/50118_2.png) [@goncalobsantos](https://discuss.elastic.co/u/goncalobsantos)\
**Post date:** [June 17, 2021, 6:56am UTC](https://discuss.elastic.co/t/check-pattern-in-scripted-field/276158/3 "2021-06-17T06:56:49Z")

</div>

Thank you, Angelo!

In my case, regexes are disabled. Is there a way to check for patterns, without enabling regexes?

---

<div class="post-metadata">

**Author:** ![angelo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelo/32/61325_2.png) [@angelo](https://discuss.elastic.co/u/angelo)\
**Post date:** [June 23, 2021, 2:12am UTC](https://discuss.elastic.co/t/check-pattern-in-scripted-field/276158/4 "2021-06-23T02:12:57Z")

</div>

Not that I'm aware of, also given that you are using `*`'s in your example, also implies that you want to use regex's so you would have to enable support for that. Otherwise you might have to work around it by splitting, count the number of values and decide if that meets your need and take the first ...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2021, 2:13am UTC](https://discuss.elastic.co/t/check-pattern-in-scripted-field/276158/5 "2021-07-21T02:13:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
