# How to search Regular expressions in Kibana 7.5

**URL:** <https://discuss.elastic.co/t/how-to-search-regular-expressions-in-kibana-7-5/217644>\
**Category:** Kibana\
**Created:** [February 3, 2020, 3:12pm UTC](https://discuss.elastic.co/t/how-to-search-regular-expressions-in-kibana-7-5/217644 "2020-02-03T15:12:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mosherr](https://avatars.discourse-cdn.com/v4/letter/m/54ee81/32.png) [@mosherr](https://discuss.elastic.co/u/mosherr)\
**Post date:** [February 3, 2020, 3:12pm UTC](https://discuss.elastic.co/t/how-to-search-regular-expressions-in-kibana-7-5/217644/1 "2020-02-03T15:12:48Z")

</div>

Hi all,  
i have Kibana 7.5 version

I'm trying to search for a particular field in REGEX.  
The field is text-type, for example:  
35-1010111\_HFBg  
41-9991234\_ERF  
51-9912234\_FGF  
41-8888234\_ASDFG  
21\_454556\_JHDS  
How do I find all records with 2 digits and with the mark -

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 3, 2020, 6:30pm UTC](https://discuss.elastic.co/t/how-to-search-regular-expressions-in-kibana-7-5/217644/2 "2020-02-03T18:30:16Z")

</div>

Hey @mosherr, you'll want to search against a field which is a [keyword](https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html), not [text](https://www.elastic.co/guide/en/elasticsearch/reference/current/text.html). The `text` field datatype goes through [analysis](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis.html). If you're using the `standard` analyzer (which is the default), it will analyze `35-1010111_HFBg` to the following 2 tokens:

- 35
- 1010111\_hfbg

When using a [regex search](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-regexp-query.html) against a `text` field which has been analyzed, the regex will be run against the individual tokens.

For example, if we use Dev Tools to create the following 2 documents:

```auto
POST moche/_doc
{
  "msg": "35-1010111_HFBg"
}

POST moche/_doc
{
  "msg": "21_454556_JHDS"
}

```

And then try to run a regex search against just `msg`:

```auto
GET moche/_search
{
    "query": {
        "regexp": {
            "msg": {
                "value": "[0-9][0-9]-.*"
            }
        }
    }
}

```

You won't get any results.

However, if we instead run this query against `msg.keyword` which is a `keyword` field (doesn't go through analysis) it works:

```auto
GET moche/_search
{
    "query": {
        "regexp": {
            "msg.keyword": {
                "value": "[0-9][0-9]-.*"
            }
        }
    }
}

```

 ![search-regex](https://us1.discourse-cdn.com/elastic/original/3X/4/6/4674bcd2c7d8e9c538ce3162c527d45360ea9b76.gif)

You can use this regular expression filter in an application like Discover, by editing the Query DSL directly:

 ![discover-regex](https://us1.discourse-cdn.com/elastic/original/3X/1/5/1544e4175688fb255218e5204fad9c8df5877184.gif)

---

<div class="post-metadata">

**Author:** ![mosherr](https://avatars.discourse-cdn.com/v4/letter/m/54ee81/32.png) [@mosherr](https://discuss.elastic.co/u/mosherr)\
**Post date:** [February 3, 2020, 7:10pm UTC](https://discuss.elastic.co/t/how-to-search-regular-expressions-in-kibana-7-5/217644/3 "2020-02-03T19:10:38Z")

</div>

Wow !!!  
Thank you very much!  
You're the best

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 7:10pm UTC](https://discuss.elastic.co/t/how-to-search-regular-expressions-in-kibana-7-5/217644/4 "2020-03-02T19:10:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
