# Elastic Search Regex are not working as expected

**URL:** <https://discuss.elastic.co/t/elastic-search-regex-are-not-working-as-expected/364651>\
**Category:** Elasticsearch\
**Created:** [August 9, 2024, 7:12am UTC](https://discuss.elastic.co/t/elastic-search-regex-are-not-working-as-expected/364651 "2024-08-09T07:12:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akesh\_Jadhav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akesh_jadhav/32/121839_2.png) [@Akesh\_Jadhav](https://discuss.elastic.co/u/Akesh_Jadhav)\
**Post date:** [August 9, 2024, 7:12am UTC](https://discuss.elastic.co/t/elastic-search-regex-are-not-working-as-expected/364651/1 "2024-08-09T07:12:38Z")

</div>

have go the problem in making Elasticsearch regex work. I have a document that looks like this:

{"content": "My name is Akesh Jadhav."}

I have tried the following regex "Akesh\sJadhav" to match the Akesh Jadhav with the regex query. I use a keyword field but this regex doesn't work. Can you suggest me correct regex to get my result and one thing I want to perform this search with regex only.

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [August 9, 2024, 3:27pm UTC](https://discuss.elastic.co/t/elastic-search-regex-are-not-working-as-expected/364651/2 "2024-08-09T15:27:41Z")

</div>

Hi @Akesh_Jadhav

Did you use [regex query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-regexp-query.html)?  
I recommend this [doc (regex sintax)](https://www.elastic.co/guide/en/elasticsearch/reference/current/regexp-syntax.html) too.

---

<div class="post-metadata">

**Author:** ![rutuja](https://avatars.discourse-cdn.com/v4/letter/r/a183cd/32.png) [@rutuja](https://discuss.elastic.co/u/rutuja)\
**Post date:** [August 10, 2024, 1:14pm UTC](https://discuss.elastic.co/t/elastic-search-regex-are-not-working-as-expected/364651/3 "2024-08-10T13:14:01Z")

</div>

Yes, Using regex query for single space in between the word,  
POST 481046270\_mails/\_search  
{ "query": { "bool": { "must": [{ "term": { "isEmbedded": { "value": false } } }, { "bool": { "should": [ { "regexp": { "hTMLBody.not\_analyzed": { "value": "malicious\sip" } } }] } } ] } } }

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 12, 2024, 2:16am UTC](https://discuss.elastic.co/t/elastic-search-regex-are-not-working-as-expected/364651/4 "2024-08-12T02:16:54Z")

</div>

> [@rutuja](#):
>
> { "regexp": { "hTMLBody.not\_analyzed": { "value": "malicious\sip" } } }

If you are embedding the `\` inside JSON then you need to escape it, otherwise the JSON parser will treat `\s` as `s`

`{ "regexp": { "hTMLBody.not_analyzed": { "value": "malicious\\sip" } } }`

---

<div class="post-metadata">

**Author:** ![Akesh\_Jadhav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akesh_jadhav/32/121839_2.png) [@Akesh\_Jadhav](https://discuss.elastic.co/u/Akesh_Jadhav)\
**Post date:** [August 12, 2024, 3:31am UTC](https://discuss.elastic.co/t/elastic-search-regex-are-not-working-as-expected/364651/5 "2024-08-12T03:31:47Z")

</div>

Hi, we have already tried this approach but are still not getting results.

 ![Untitled](https://us1.discourse-cdn.com/elastic/original/3X/9/d/9dbc6df85bc04a91a3be7fb3f6baf4af47b115db.png)

this is my data

and my query is

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 12, 2024, 5:02am UTC](https://discuss.elastic.co/t/elastic-search-regex-are-not-working-as-expected/364651/6 "2024-08-12T05:02:38Z")

</div>

The `regexp` query matches terms, not substrings.

If you want to find `malicious ip` anywhere in the `hTMLBody.not_analyzed` field, then you need  
`{ "regexp": { "hTMLBody.not_analyzed": { "value": ".*malicious\\sip.*" } } }`

Note that this will be quite slow.
