# ES|QL RLIKE

**URL:** <https://discuss.elastic.co/t/es-ql-rlike/382831>\
**Category:** Kibana\
**Created:** [October 20, 2025, 9:24am UTC](https://discuss.elastic.co/t/es-ql-rlike/382831 "2025-10-20T09:24:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Balu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balu/32/37569_2.png) [@Balu](https://discuss.elastic.co/u/Balu)\
**Post date:** [October 20, 2025, 9:24am UTC](https://discuss.elastic.co/t/es-ql-rlike/382831/1 "2025-10-20T09:24:57Z")

</div>

We are a little confused here, playing with ES|QL and RLIKE in Discover:.

This one works and returns paths like `\\?\C:\Windows\CSC\v2.0.6\namespace\example.com\DFS\Homes\User\Downloads\evil.exe`

```auto
| WHERE file.path RLIKE ".*\\DFS.Homes.*"

```

Moving the backslashes to the back suddenly returns no results anymore?

```auto
| WHERE file.path RLIKE ".*DFS.Homes\\.*"

```

Even worse, adding more than one “double backslash” returns an error?

```auto
| WHERE file.path RLIKE ".*\\DFS\\Homes.*"

[esql] > Couldn't parse Elasticsearch ES|QL query. Check your query and try again. Error: line 2:9: Invalid regex pattern for RLIKE [.*\DFS\Homes.*]: [invalid character class \72]

```

Doing something like this still returns the same results as the first one even though there's too many slashes:

```auto
| WHERE file.path RLIKE ".*\\\\\\DFS.Homes.*"

```

Yet, adding more then returns no results again.

```auto
| WHERE file.path RLIKE ".*\\\\\\\\DFS.Homes.*"

```

Maybe we are just tired, but this doesn’t make sense to us?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [October 20, 2025, 1:03pm UTC](https://discuss.elastic.co/t/es-ql-rlike/382831/2 "2025-10-20T13:03:29Z")

</div>

Hello @Balu

While reviewing this i found below information if it can be helpful

```auto
FROM test-rlike
| WHERE file.path RLIKE ".*\\\\DFS\\\\Homes.*"
| KEEP file.path

```

#### 

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/0/b0ebe387d468384ac86b041a4ab691ed10cefc8f.png)

#### Below information via LLM :

1. **Regex Layer**

To match a literal backslash (`\`) in a regex, you must escape it:

- `\\` in regex = match one literal `\`

#### 2. **JSON Layer**

In JSON strings (like the body of your ES|QL query), a backslash is also an escape character. So to represent a single backslash in JSON, you write:

- `\\` in JSON = one literal `\`

#### 3. **Combined Effect**

To match a literal backslash in a regex **inside JSON** , you need:

- `\\\\` in JSON = `\\` in regex = match one `\`

So, to match the path `C:\DFS\Homes`, you need:

sql

```auto
RLIKE ".*\\\\DFS\\\\Homes.*"

```

Each `\\\\` becomes `\\` in regex, which matches a literal `\`.

Thanks!!

---

<div class="post-metadata">

**Author:** ![Balu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balu/32/37569_2.png) [@Balu](https://discuss.elastic.co/u/Balu)\
**Post date:** [October 20, 2025, 1:24pm UTC](https://discuss.elastic.co/t/es-ql-rlike/382831/3 "2025-10-20T13:24:18Z")

</div>

I was not aware that the string is processed as JSON. This explains a lot.
