# How to use regex

**URL:** https://discuss.elastic.co/t/how-to-use-regex/231250
**Category:** Elasticsearch
**Created:** [May 6, 2020, 4:19am UTC](https://discuss.elastic.co/t/how-to-use-regex/231250 "2020-05-06T04:19:37Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![user2416](https://avatars.discourse-cdn.com/v4/letter/u/97f17d/32.png) [@user2416](https://discuss.elastic.co/u/user2416)
#### Post date: [May 6, 2020, 4:19am UTC](https://discuss.elastic.co/t/how-to-use-regex/231250/1 "2020-05-06T04:19:38Z")

</div>

Hi,

I am trying to match multiple fileds with multiple values and also trying to match some values using regex. Below is my query. But its not working. Can someone help me with this query.

```auto
{
  "query": {
    "bool": {
      "should": {
        "match": {
          "Records.eventSource": "service"
        }
      },
      "must": {
        "bool": {
          "should": [
            {
              "match": {
                  "regexp":{	
                    "Records.eventName": "List*"	
                   }
                }
            },
            {
              "match": {
                "regexp":{	
                    "Records.eventName": "Get.*"	
                   }
              }
            }
          ]
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

### Author: ![Jack\_Phan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_phan/32/44738_2.png) [@Jack\_Phan](https://discuss.elastic.co/u/Jack_Phan)
#### Post date: [May 6, 2020, 4:21am UTC](https://discuss.elastic.co/t/how-to-use-regex/231250/2 "2020-05-06T04:21:07Z")

</div>

"List\*" is not a proper regex pattern. You might want to try **wildcard** instead.

---

<div class="post-metadata">

### Author: ![user2416](https://avatars.discourse-cdn.com/v4/letter/u/97f17d/32.png) [@user2416](https://discuss.elastic.co/u/user2416)
#### Post date: [May 6, 2020, 4:25am UTC](https://discuss.elastic.co/t/how-to-use-regex/231250/3 "2020-05-06T04:25:05Z")

</div>

@Jack_Phan I tried wildcard also, still its not working. Can I use wildcard inside match?

---

<div class="post-metadata">

### Author: ![Jack\_Phan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_phan/32/44738_2.png) [@Jack\_Phan](https://discuss.elastic.co/u/Jack_Phan)
#### Post date: [May 6, 2020, 4:31am UTC](https://discuss.elastic.co/t/how-to-use-regex/231250/4 "2020-05-06T04:31:16Z")

</div>

> [@user2416](#):
>
> { "query": { "bool": { "should": { "match": { "Records.eventSource": "service" } }, "must": { "bool": { "should": [{ "match": { "regexp":{ "Records.eventName": "List\*" } } }, { "match": { "regexp":{ "Records.eventName": "Get.\*" } } }] } } } } }

I'm afraid not. Can you try to replace **match** by **wildcard** directly.

---

<div class="post-metadata">

### Author: ![user2416](https://avatars.discourse-cdn.com/v4/letter/u/97f17d/32.png) [@user2416](https://discuss.elastic.co/u/user2416)
#### Post date: [May 6, 2020, 5:11am UTC](https://discuss.elastic.co/t/how-to-use-regex/231250/5 "2020-05-06T05:11:53Z")

</div>

@Jack_Phan after removing match filed its working, But when I include range in the query like below its not working. Where should I use range filter inside this query?

```auto
{
  "query": {
      
    "bool": {
      "should": {
          
        "match": {
          "Records.eventSource": "service"
            }  
          },
     
      "must": {
        "bool": {
          "should": [
            {
              "wildcard": {
                    "Records.eventName": "list*"
                   
                }
            },
            {
              "wildcard": {
                    "Records.eventName": "get*"	
                   
              }
            },
{
              "range" : {
                 "@timestamp" : {
                "gte" : "now-1h"
                
            }
        }}
            
          ]
        }
      }
  
     
    }
    
 
  }
}

```

---

<div class="post-metadata">

### Author: ![Jack\_Phan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_phan/32/44738_2.png) [@Jack\_Phan](https://discuss.elastic.co/u/Jack_Phan)
#### Post date: [May 6, 2020, 5:18am UTC](https://discuss.elastic.co/t/how-to-use-regex/231250/8 "2020-05-06T05:18:48Z")

</div>

Try this:

> "query": {  
> "bool": {  
> "must": [  
> {  
> "wildcard": {  
> "Records.eventName": "list\*"  
> }  
> }  
> ],  
> "filter": [  
> {  
> "range": {  
> "@timestamp": {  
> "from": "now-1m"  
> }  
> }  
> }  
> ]  
> }  
> }

---

<div class="post-metadata">

### Author: ![user2416](https://avatars.discourse-cdn.com/v4/letter/u/97f17d/32.png) [@user2416](https://discuss.elastic.co/u/user2416)
#### Post date: [May 6, 2020, 5:19am UTC](https://discuss.elastic.co/t/how-to-use-regex/231250/9 "2020-05-06T05:19:57Z")

</div>

working now. Thanks

---

<div class="post-metadata">

### Author: ![user2416](https://avatars.discourse-cdn.com/v4/letter/u/97f17d/32.png) [@user2416](https://discuss.elastic.co/u/user2416)
#### Post date: [May 6, 2020, 9:46pm UTC](https://discuss.elastic.co/t/how-to-use-regex/231250/10 "2020-05-06T21:46:07Z")

</div>

@Jack_Phan I see that when i add range, Its not applying above filters but its filtering all events in the time range. How can I apply filters and get filtered data during particular time range?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 3, 2020, 9:46pm UTC](https://discuss.elastic.co/t/how-to-use-regex/231250/11 "2020-06-03T21:46:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
