# How to filter out strings starting with any from a list of strings

**URL:** <https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948>\
**Category:** Elasticsearch\
**Created:** [August 2, 2023, 2:18pm UTC](https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948 "2023-08-02T14:18:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![michael\_c\_michael](https://avatars.discourse-cdn.com/v4/letter/m/ecccb3/32.png) [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Post date:** [August 2, 2023, 2:18pm UTC](https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948/1 "2023-08-02T14:18:33Z")

</div>

Hi, I'm wanting to filter out strings starting with a number of characters. I've been able to solve this using a DSL query. Let me provide the example first:

```auto
# Cleanup
DELETE discuss-338708

# Create an index
PUT discus-338708
{
  "mappings": {
    "properties": {
      "ts": {"type": "date"},
      "entityID": { "type": "keyword"}
    }
  }
}

# Add some data
POST discuss-338708/_bulk
{ "index": {}}
{ "ts": "2023-07-19T12:42:55+0200", "entityID": "1.1.225.0.5.0.0"}
{ "index": {}}
{ "ts": "2023-07-19T12:22:55+0200", "entityID": "2.10.225.1.7.1.0"}
{ "index": {}}
{ "ts": "2023-07-19T12:12:55+0200", "entityID": "0.0.0.0.0.0.0"}
{ "index": {}}
{ "ts": "2023-07-19T12:02:55+0200", "entityID": "1.1.225.28.25.0.0"}
{ "index": {}}
{ "ts": "2023-07-19T11:52:55+0200", "entityID": "2.10.225.1.7.1.0"}
{ "index": {}}
{ "ts": "2023-07-19T11:42:55+0200", "entityID": "5.2.225.0.1.0.0"}
{ "index": {}}
{ "ts": "2023-07-19T11:32:55+0200"}
{ "index": {}}
{ "ts": "2023-07-19T11:22:55+0200"}

```

I solve this by using the following DSL query, but I could only find the way to filter for a single starting prefix:

```auto
{
  "query": {
    "prefix": {
      "entityType.keyword": {
        "value": "1"
      }
    }
  }
}

```

So, I'm wondering how I could do this in KQL, or as a runtime field. I am also wondering how I would be able to filter _out_ , say, strings ["0", "2"]. I'm sorry if this is in the documentation but I was not be able to find a suitable page describing my questions.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2023, 2:19pm UTC](https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948/2 "2023-08-30T14:19:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
