# Include/Exclude Pattern syntax

**URL:** <https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823>\
**Category:** Kibana\
**Created:** [February 28, 2017, 4:30pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823 "2017-02-28T16:30:36Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Post date:** [February 28, 2017, 4:30pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/1 "2017-02-28T16:30:37Z")

</div>

I've been reading some post regarding include and exclude patterns and i'm still not sure what the correct syntax is.

Is there a single syntax to these pattern options or is it based on the field your searching for a pattern on? I've tried RegEx and the visual throws errors. Even tried  
Lucene query format ([http://www.lucenetutorial.com/lucene-query-syntax.html](http://www.lucenetutorial.com/lucene-query-syntax.html)) - still get errors.

here is the error i keep getting: Error: [parsing\_exception] Expected [START\_OBJECT] under [size], but got a [VALUE\_NUMBER] in [3], with { line=1 & col=427 }

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 28, 2017, 4:55pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/2 "2017-02-28T16:55:14Z")

</div>

@cisaksen Are you getting this error when using the Include/Exclude options highlighted below?

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/c3c5894d9aa4ff856a22f3d4742ab4d34eb5ed52.png)

---

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Post date:** [February 28, 2017, 5:07pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/3 "2017-02-28T17:07:06Z")

</div>

yes no matter what i put in it.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 28, 2017, 5:08pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/4 "2017-02-28T17:08:29Z")

</div>

@cisaksen - If you're running version 5.2.0 or 5.2.1 of Elasticsearch, this is a known issue. The Include/Exclude syntax that Kibana uses was accidentally removed when it should have been deprecated. If you upgrade Elasticsearch to 5.2.2, this is resolved.

---

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Post date:** [March 1, 2017, 9:03pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/5 "2017-03-01T21:03:47Z")

</div>

Ok so if it's been deprecated should I even bother to use it ? or is something else going to replace it ?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 1, 2017, 11:56pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/6 "2017-03-01T23:56:42Z")

</div>

@cisaksen Feel free to keep using it, we'll be upgrading Kibana to use the new syntax with 6.0 so you won't have to worry about anything. It just requires you to use 5.2.2 of Elasticsearch for the time being.

---

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Post date:** [March 2, 2017, 1:03pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/7 "2017-03-02T13:03:30Z")

</div>

Ok - I will keep trying it out. Question: What is the syntax that i should use ?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 2, 2017, 1:55pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/8 "2017-03-02T13:55:42Z")

</div>

@cisaksen The Include/Exclude fields are used for the terms aggregation that is passed to Elasticsearch and it's the same as the [Regular Expression Syntax](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-regexp-query.html#regexp-syntax)

---

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Post date:** [March 2, 2017, 2:14pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/9 "2017-03-02T14:14:53Z")

</div>

ok thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2017, 2:15pm UTC](https://discuss.elastic.co/t/include-exclude-pattern-syntax/76823/10 "2017-03-30T14:15:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
