# Elastic search - filter on a field based on the length of that field's contents

**URL:** <https://discuss.elastic.co/t/elastic-search-filter-on-a-field-based-on-the-length-of-that-fields-contents/295883>\
**Category:** Elasticsearch\
**Created:** [January 31, 2022, 10:16pm UTC](https://discuss.elastic.co/t/elastic-search-filter-on-a-field-based-on-the-length-of-that-fields-contents/295883 "2022-01-31T22:16:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![drwiremore](https://avatars.discourse-cdn.com/v4/letter/d/22d042/32.png) [@drwiremore](https://discuss.elastic.co/u/drwiremore)\
**Post date:** [January 31, 2022, 10:16pm UTC](https://discuss.elastic.co/t/elastic-search-filter-on-a-field-based-on-the-length-of-that-fields-contents/295883/1 "2022-01-31T22:16:05Z")

</div>

Thought this would be easy. I'm searching a data index of data-awsch\*:ls-aws-cloudtrail\* based on event.type that is not one of start, access, info. This is working as intended, but the output is huge.

Rather than filter by user.name exclude, exclude, exclude --- I'd prefer to filter (or create a smaller output) based on the length of the user.name returned. Specifically, I want to return only those events where the user.name \<=6 characters; and conversely when the user.name \> 6 characters.

I'm not finding a way to parse the user.name field based on the length of the content.

Question: How does one search or filter for user.name with \<= 6 characters?

Thank you dr.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 31, 2022, 11:30pm UTC](https://discuss.elastic.co/t/elastic-search-filter-on-a-field-based-on-the-length-of-that-fields-contents/295883/2 "2022-01-31T23:30:39Z")

</div>

Well, I was just looking at regex queries, so `^.{0,6}$` should match anything 6 or less.

If your max field size were known, say 999, this should match anything over 6: `^.{7,999}$`

I don't know if this is a good way or not, performance may be terrible...

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 1, 2022, 1:56am UTC](https://discuss.elastic.co/t/elastic-search-filter-on-a-field-based-on-the-length-of-that-fields-contents/295883/3 "2022-02-01T01:56:52Z")

</div>

Another option is using ingest pipeline with script processor to create new field to save information of the length.

---

<div class="post-metadata">

**Author:** ![drwiremore](https://avatars.discourse-cdn.com/v4/letter/d/22d042/32.png) [@drwiremore](https://discuss.elastic.co/u/drwiremore)\
**Post date:** [February 1, 2022, 2:47am UTC](https://discuss.elastic.co/t/elastic-search-filter-on-a-field-based-on-the-length-of-that-fields-contents/295883/4 "2022-02-01T02:47:42Z")

</div>

regex queries, so `^.{0,6}$` should match anything 6 or less.

Sounds like it would work.

Given we have the dataset and the field name, how can I use that as a filter. Offering the filter option so I don’t have to pull a fresh search.

Can you give me an example with context?

And - Thank you.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [February 1, 2022, 3:02pm UTC](https://discuss.elastic.co/t/elastic-search-filter-on-a-field-based-on-the-length-of-that-fields-contents/295883/5 "2022-02-01T15:02:16Z")

</div>

I use the python dsl, so you'll have to translate, here is an example that uses regex, I changeda working regex expression to this example (and sanatized), but it's not tested.

```auto
s = Search(using=es, index = 'filebeat-*') \
        .query("match", event_id="RECEIVE") \
        .query("regexp", **{"recipient_address" : {"value": "^.{0,6}$"}})

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2022, 3:02pm UTC](https://discuss.elastic.co/t/elastic-search-filter-on-a-field-based-on-the-length-of-that-fields-contents/295883/6 "2022-03-01T15:02:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
