# Complex regexp

**URL:** https://discuss.elastic.co/t/complex-regexp/251673
**Category:** Elasticsearch
**Created:** [October 11, 2020, 10:30am UTC](https://discuss.elastic.co/t/complex-regexp/251673 "2020-10-11T10:30:13Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![sphawk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sphawk/32/76990_2.png) [@sphawk](https://discuss.elastic.co/u/sphawk)
#### Post date: [October 11, 2020, 10:30am UTC](https://discuss.elastic.co/t/complex-regexp/251673/1 "2020-10-11T10:30:13Z")

</div>

hello everybody,  
i'm new in elasticsearch and i'm creating an internal search engine for my company.  
i'm try to make a query that must returns only files contained in some paths.  
here is my PHP code:

`$params['body']['query']['bool']['should']['regexp']['file'] = "/(000_Public|010_Users|020_Private)/";`

the query should match any file where path is "foo/000\_Public/foo" or "foo/010\_Users/foo" etc.  
i've tried multiple format  
"/(000\_Public|010\_Users|020\_Private)/"  
"._(000\_Public|010\_Users|020\_Private)._"  
"000\_Public"  
"._000\_Public._"

every query return 0 hits  
the full request is:

```auto
{
    "from": 0,
    "size": 10,
    "type": "_doc",
    "body": {
        "sort": {
            "date": "asc"
        },
        "query": {
            "bool": {
                "should": {
                    "regexp": {
                        "file": ".*(000_Public|010_Users|020_Private).*"
                    }
                }
            }
        }
    },
    "index": "allfiles"
}

```

help!

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [October 11, 2020, 10:35am UTC](https://discuss.elastic.co/t/complex-regexp/251673/2 "2020-10-11T10:35:26Z")

</div>

What is the mapping of the `file` field?

---

<div class="post-metadata">

### Author: ![sphawk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sphawk/32/76990_2.png) [@sphawk](https://discuss.elastic.co/u/sphawk)
#### Post date: [October 11, 2020, 10:54am UTC](https://discuss.elastic.co/t/complex-regexp/251673/3 "2020-10-11T10:54:55Z")

</div>

file is the filed with the path and the filename

`'file': '/home/samba/000_Public/file.doc'`

and sorry, i don't know what is a mapping and how to see what is the mapping for this field.

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [October 11, 2020, 10:56am UTC](https://discuss.elastic.co/t/complex-regexp/251673/4 "2020-10-11T10:56:48Z")

</div>

What is the mapping in Elasticsearch for this field? Use the [get mapping API](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/indices-get-field-mapping.html) to find out.

If you have not specified mappings it is likely that you are using dynamic mappings, and in that case `file` is mapped as an analyzed text field on which regexp will not work. Instead try using `file.keyword` and see if that helps.

---

<div class="post-metadata">

### Author: ![sphawk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sphawk/32/76990_2.png) [@sphawk](https://discuss.elastic.co/u/sphawk)
#### Post date: [October 11, 2020, 11:57am UTC](https://discuss.elastic.co/t/complex-regexp/251673/5 "2020-10-11T11:57:22Z")

</div>

```auto
{
    "aperiodici": {
        "mappings": {
            "_doc": {
                "file": {
                    "full_name": "file",
                    "mapping": {
                        "file": {
                            "type": "text",
                            "fields": {
                                "keyword": {
                                    "type": "keyword",
                                    "ignore_above": 256
                                }
                            }
                        }
                    }
                }
            }
        }
    }
}

```

(i like your avatar so much!)

---

<div class="post-metadata">

### Author: ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)
#### Post date: [October 11, 2020, 9:34pm UTC](https://discuss.elastic.co/t/complex-regexp/251673/6 "2020-10-11T21:34:51Z")

</div>

As well as using ‘file.keyword’ as the field name in your query try use ‘.\*’ at the beginning and end of the regex string if you’re only supplying part of the file name in the search

---

<div class="post-metadata">

### Author: ![sphawk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sphawk/32/76990_2.png) [@sphawk](https://discuss.elastic.co/u/sphawk)
#### Post date: [October 12, 2020, 4:17am UTC](https://discuss.elastic.co/t/complex-regexp/251673/7 "2020-10-12T04:17:44Z")

</div>

awesome!  
thank both of you.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 9, 2020, 4:17am UTC](https://discuss.elastic.co/t/complex-regexp/251673/8 "2020-11-09T04:17:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
