# Elasticsearch TERM regex aggregation

**URL:** <https://discuss.elastic.co/t/elasticsearch-term-regex-aggregation/75046>\
**Category:** Elasticsearch\
**Created:** [February 14, 2017, 2:18pm UTC](https://discuss.elastic.co/t/elasticsearch-term-regex-aggregation/75046 "2017-02-14T14:18:32Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![seallison](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@seallison](https://discuss.elastic.co/u/seallison)\
**Post date:** [February 14, 2017, 2:18pm UTC](https://discuss.elastic.co/t/elasticsearch-term-regex-aggregation/75046/1 "2017-02-14T14:18:32Z")

</div>

I'm migrating an application from Elasticsearch 1.7.5 to 2.4.4. One of the last issues I've encountered is [flags are no longer supported](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/breaking_20_aggregation_changes.html#_including_excluding_terms). In the examples below, I'm trying to aggregate on a field to find tag values that start with "ja" (case insensitive). Is there an equivalent way to express this query from 1.7.5 in 2.4.4?

```
{
  "size": 0,
  "aggregations" : {
    "tags" : {
      "terms" : {
        "field" : "tags.value_unanalyzed",
        "size" : 25,
        "order" : [ {
          "_count" : "desc"
        }, {
          "_term" : "asc"
        } ],
        "include" : {
          "pattern" : "^\\Qja\\E.*$",
          "flags" : 2
        }
      }
    }
  }
}

```

The only thing I've come up with in 2.4.4 is this:

```
{
  "size": 0,
  "aggregations" : {
    "tags" : {
      "terms" : {
        "field" : "tags.value_unanalyzed",
        "size" : 25,
        "order" : [ {
          "_count" : "desc"
        }, {
          "_term" : "asc"
        } ],
        "include" : "(JA|ja|Ja|jA).*"
      }
    }
  }
}

```

While this aggregation "does the job," it becomes expensive and slow very quickly. Is there another way I can express this query to get the equivalent case-insensitive starts-with behavior on a TERM aggregation from 1.7.5?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2017, 2:18pm UTC](https://discuss.elastic.co/t/elasticsearch-term-regex-aggregation/75046/2 "2017-03-14T14:18:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
