# How elasticsearch supports regex search and its performance

**URL:** https://discuss.elastic.co/t/how-elasticsearch-supports-regex-search-and-its-performance/12033
**Category:** Elasticsearch
**Created:** [May 20, 2013, 6:22am UTC](https://discuss.elastic.co/t/how-elasticsearch-supports-regex-search-and-its-performance/12033 "2013-05-20T06:22:51Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Wenbin\_Li](https://avatars.discourse-cdn.com/v4/letter/w/5e9695/32.png) [@Wenbin\_Li](https://discuss.elastic.co/u/Wenbin_Li)
#### Post date: [May 20, 2013, 6:22am UTC](https://discuss.elastic.co/t/how-elasticsearch-supports-regex-search-and-its-performance/12033/1 "2013-05-20T06:22:51Z")

</div>

Hi,

I want to use elasticsearch to index large amount log data and search using  
regex.  
So I want to know how elasticsearch support the regex search for millions  
of raw data.  
I think it could not be matching all the records one by one for the  
performance, so is there any information for this question?

Thanks for any suggestion.  
-Wenbin

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![Boaz\_Leskes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/boaz_leskes/32/723_2.png) [@Boaz\_Leskes](https://discuss.elastic.co/u/Boaz_Leskes)
#### Post date: [May 22, 2013, 1:19pm UTC](https://discuss.elastic.co/t/how-elasticsearch-supports-regex-search-and-its-performance/12033/2 "2013-05-22T13:19:48Z")

</div>

Hi Wenbin,

Elasticsearch uses lucene's RegexpQuery for this. As of version 0.90 of ES  
(using Lucene 4.3) it is executed using an constructed automaton which  
makes it much faster. You can read more here:

> **[Lucene's FuzzyQuery is 100 times faster in 4.0](https://blog.mikemccandless.com/2011/03/lucenes-fuzzyquery-is-100-times-faster.html)**
>
> There are many exciting improvements in Lucene's eventual 4.0 (trunk) release, but the awesome speedup to FuzzyQuery really stands out, not...

or

[http://lucene.apache.org/core/4\_2\_0/core/org/apache/lucene/search/RegexpQuery.html](http://lucene.apache.org/core/4_2_0/core/org/apache/lucene/search/RegexpQuery.html)

Cheers,  
Boaz  
On Monday, May 20, 2013 8:22:51 AM UTC+2, Wenbin Li wrote:

> Hi,
> 
> I want to use elasticsearch to index large amount log data and search  
> using regex.  
> So I want to know how elasticsearch support the regex search for millions  
> of raw data.  
> I think it could not be matching all the records one by one for the  
> performance, so is there any information for this question?
> 
> Thanks for any suggestion.  
> -Wenbin

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)
#### Post date: [May 23, 2013, 10:31am UTC](https://discuss.elastic.co/t/how-elasticsearch-supports-regex-search-and-its-performance/12033/3 "2013-05-23T10:31:35Z")

</div>

Hi Wenbin

Note that the performance of regexes drops off rapidly the shorter the  
prefix.

So "foobar.\*" will be fast, but ".\*foobar" won't...

clint

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 2:35am UTC](https://discuss.elastic.co/t/how-elasticsearch-supports-regex-search-and-its-performance/12033/4 "2017-07-06T02:35:09Z")

</div>


