# How to search a piece of URI

**URL:** <https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342>\
**Category:** Elasticsearch\
**Created:** [March 23, 2023, 11:27am UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342 "2023-03-23T11:27:27Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![searchwithme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/searchwithme/32/137075_2.png) [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Post date:** [March 23, 2023, 11:27am UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/1 "2023-03-23T11:27:27Z")

</div>

I want to search a piece of URL. I am using the sample weblogs in elasticsearch.

If I analyze the field:

GET /\_analyze  
{  
"analyzer" : "standard",  
"text" : ["[http://nytimes.com/success/kevin-Kregel](http://nytimes.com/success/kevin-Kregel)"]  
}

I get:

{  
"tokens": [  
{  
"token": "http",  
"start\_offset": 0,  
"end\_offset": 4,  
"type": "",  
"position": 0  
},  
{  
"token": "[nytimes.com](http://nytimes.com)",  
"start\_offset": 7,  
"end\_offset": 18,  
"type": "",  
"position": 1  
},  
{  
"token": "success",  
"start\_offset": 19,  
"end\_offset": 26,  
"type": "",  
"position": 2  
},  
{  
"token": "kevin",  
"start\_offset": 27,  
"end\_offset": 32,  
"type": "",  
"position": 3  
},  
{  
"token": "kregel",  
"start\_offset": 33,  
"end\_offset": 39,  
"type": "",  
"position": 4  
}  
]  
}

Now what if I want to search for 'kregel' or 'nytimes'. How do I do this? please help!

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [March 23, 2023, 11:55am UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/2 "2023-03-23T11:55:41Z")

</div>

Hi @searchwithme

You tried to use match query? Look this [doc](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-match-query.html).

---

<div class="post-metadata">

**Author:** ![searchwithme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/searchwithme/32/137075_2.png) [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Post date:** [March 23, 2023, 12:02pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/3 "2023-03-23T12:02:28Z")

</div>

GET /\_search  
{

"query": {  
"match": {  
"message": {  
"query": "nytimes"  
}  
}  
}

}

This is what I get 😑  
{  
"took": 15,  
"timed\_out": false,  
"\_shards": {  
"total": 8,  
"successful": 8,  
"skipped": 0,  
"failed": 0  
},  
"hits": {  
"total": {  
"value": 0,  
"relation": "eq"  
},  
"max\_score": null,  
"hits":   
}  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2023, 12:13pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/4 "2023-03-23T12:13:41Z")

</div>

What is the mapping for that field in your index?

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [March 23, 2023, 12:15pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/5 "2023-03-23T12:15:29Z")

</div>

An option is use [Pattern Tokenizer](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-pattern-tokenizer.html).

```auto
PUT idx_test
{
  "mappings": {
    "properties": {
      "url": {
        "type": "text",
        "analyzer": "my_analyzer"
      }
    }
  },
  "settings": {
    "analysis": {
      "analyzer": {
        "my_analyzer": {
          "tokenizer": "my_tokenizer"
        }
      },
      "tokenizer": {
        "my_tokenizer": {
          "type": "pattern"
        }
      }
    }
  }
}

     
POST idx_test/_doc
{
 "url":"http://nytimes.com/success/kevin-Kregel"
}

GET idx_test/_search
{
  "query": {
    "match": {
      "url": "nytimes"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![searchwithme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/searchwithme/32/137075_2.png) [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Post date:** [March 23, 2023, 12:24pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/7 "2023-03-23T12:24:37Z")

</div>

This is the mapping:

{  
"sample\_data\_logs": {  
"mappings": {  
"properties": {  
"@timestamp": {  
"type": "alias",  
"path": "timestamp"  
},  
"agent": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"bytes": {  
"type": "long"  
},  
"clientip": {  
"type": "ip"  
},  
"event": {  
"properties": {  
"dataset": {  
"type": "keyword"  
}  
}  
},  
"extension": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"geo": {  
"properties": {  
"coordinates": {  
"type": "geo\_point"  
},  
"dest": {  
"type": "keyword"  
},  
"src": {  
"type": "keyword"  
},  
"srcdest": {  
"type": "keyword"  
}  
}  
},  
"host": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"index": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"ip": {  
"type": "ip"  
},  
"machine": {  
"properties": {  
"os": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"ram": {  
"type": "long"  
}  
}  
},  
"memory": {  
"type": "double"  
},  
"message": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"phpmemory": {  
"type": "long"  
},  
"referer": {  
"type": "keyword"  
},  
"request": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"response": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"tags": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"timestamp": {  
"type": "date"  
},  
"url": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"utc\_time": {  
"type": "date"  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![searchwithme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/searchwithme/32/137075_2.png) [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Post date:** [March 23, 2023, 12:30pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/8 "2023-03-23T12:30:59Z")

</div>

wow this worked! you are amazing. thank you!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/9 "2023-03-23T12:31:24Z")

</div>

If you look at the output from the \_analyze API you can see that the standard analyzer creates a token `nytimes.com` and not `nytimes` plus `com`, which is why you do not find anything when searching for just `nytimes`. If you instead searched for `kregel` you should find a match.

---

<div class="post-metadata">

**Author:** ![searchwithme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/searchwithme/32/137075_2.png) [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Post date:** [March 23, 2023, 12:36pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/10 "2023-03-23T12:36:28Z")

</div>

no kregel didn't work either

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2023, 12:36pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342/11 "2023-04-20T12:36:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
