# Kibana 5 | apply regex on scripted fields

**URL:** <https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898>\
**Category:** Kibana\
**Created:** [November 22, 2016, 5:14pm UTC](https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898 "2016-11-22T17:14:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerome831361](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerome831361/32/30125_2.png) [@jerome831361](https://discuss.elastic.co/u/jerome831361)\
**Post date:** [November 22, 2016, 5:14pm UTC](https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898/1 "2016-11-22T17:14:26Z")

</div>

Hello,

I'm using Kibana to view my logs.

I have some URLs like this:  
`/myapp/bla/bla/test.shtml;jsessionid=3CF74CA6abht48753DA243C5338222EE.jvmid?show=blaa`

At the moment, I'm using the following regex in logstash to extract the first part of the URL:

`(?'request_noparms'[a-zA-Z0-9_.\/]*(?=\b[\;\?\&]|.*))`

Result: /myapp/bla/bla/test.shtml

I would like to remove the regex from logstash and to apply it into Kibana, by using a scripted field.

Is it possible to do such a thing ?

Thank you for your help.

Best regards

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [November 23, 2016, 4:21pm UTC](https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898/2 "2016-11-23T16:21:32Z")

</div>

Yes it is, if you're using painless you'll have to enable regular expressions which comes with potential performance caveats, see [https://www.elastic.co/guide/en/elasticsearch/reference/master/modules-scripting-painless.html#modules-scripting-painless-regex](https://www.elastic.co/guide/en/elasticsearch/reference/master/modules-scripting-painless.html#modules-scripting-painless-regex).  
Your script would look something like:

```auto
Matcher m = /[a-zA-Z0-9_.\/]*(?=\b[\;\?\&]|.*)/.matcher(doc['my_url_field'].value);
if(m.find()) {
  return m.group();
}
return "";

```

edit: added an empty string return at the bottom to have an explicit output

---

<div class="post-metadata">

**Author:** ![jerome831361](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerome831361/32/30125_2.png) [@jerome831361](https://discuss.elastic.co/u/jerome831361)\
**Post date:** [November 30, 2016, 7:09pm UTC](https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898/3 "2016-11-30T19:09:04Z")

</div>

Hello,

Thank you for your help. It works just great !  
But now I have another issue.

I have created a scripted field "testfield1" with this painless script:

```
Matcher m = /\/(?!.*\/)([a-zA-Z0-9_.]*(?=\b[\;\?\&]|.*))/.matcher(doc['request'].value);
if(m.find()) {
  return m.group(1);
}

```

It works when I add this field into a Kibana vizualisation, but it fails when I try to query the field with this error:

Please see at: [http://pastebin.com/jihnBssg](http://pastebin.com/jihnBssg)

Any idea ?  
Thank you for your help

Best regards  
Jérôme

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [December 5, 2016, 11:48pm UTC](https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898/4 "2016-12-05T23:48:12Z")

</div>

There are several issues related to scripted fields including this one which is fixed in 5.1.0 (NOT RELEASED YET);

> <https://github.com/elastic/kibana/issues/9024>

The larger search result;

> **[elastic/kibana](https://github.com/elastic/kibana/issues?utf8=%E2%9C%93&q=is%3Aissue%20compile%20scripted)**
>
> kibana - :bar\_chart: Kibana analytics and search dashboard for Elasticsearch

But there may also be another way to get your desired scripted field result that doesn't have the error. Instead of using a regular expression you could use some other string methods.

In my example I have some URLs in a field named `referer` and if I want to just get the `http` or `https` part off the front of the URL I can use this scripted field;

`doc['referer'].value.substring(0, doc['referer'].value.indexOf(":"))`  
This gets the substring starting at 0 and up to the ":". You could try this in your case and see if it works for you.  
I'm not sure how it handles the case where the ":" isn't found as all my data has it.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [December 6, 2016, 12:00am UTC](https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898/5 "2016-12-06T00:00:32Z")

</div>

Sorry, after re-reading your post and thinking about it a bit, I don't think you can ever use scripted fields in the query bar in Kibana as that goes directly to Elasticsearch which doesn't know about them. But you should be able to filter on them and use them in aggregations in Visualizations.

---

<div class="post-metadata">

**Author:** ![jerome831361](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerome831361/32/30125_2.png) [@jerome831361](https://discuss.elastic.co/u/jerome831361)\
**Post date:** [December 8, 2016, 8:50am UTC](https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898/6 "2016-12-08T08:50:04Z")

</div>

Hi,  
OK, thanks for your help.

Best regards  
Jérôme

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [December 13, 2016, 8:19pm UTC](https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898/7 "2016-12-13T20:19:33Z")

</div>

FYI - There is now a blog published on Painless in Kibana scripted fields: [https://www.elastic.co/blog/using-painless-kibana-scripted-fields](https://www.elastic.co/blog/using-painless-kibana-scripted-fields)

Make sure you are using Kibana 5.1.1, since prior to that version there were issues with filtering and sorting on some of the more advanced scripted fields. Also make sure that every execution path in your script has a well-defined return statement, otherwise some sorts will still fail. Here is the part of the blog that explains that:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/bcd34937533430f51f061020cdf686d653b865c2.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2017, 8:19pm UTC](https://discuss.elastic.co/t/kibana-5-apply-regex-on-scripted-fields/66898/8 "2017-01-10T20:19:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
