# Kibana painless scripted fields and regex - Only the first created works

**URL:** <https://discuss.elastic.co/t/kibana-painless-scripted-fields-and-regex-only-the-first-created-works/155414>\
**Category:** Kibana\
**Created:** [November 5, 2018, 2:31pm UTC](https://discuss.elastic.co/t/kibana-painless-scripted-fields-and-regex-only-the-first-created-works/155414 "2018-11-05T14:31:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_Pereira](https://avatars.discourse-cdn.com/v4/letter/r/f6c823/32.png) [@Robert\_Pereira](https://discuss.elastic.co/u/Robert_Pereira)\
**Post date:** [November 5, 2018, 2:31pm UTC](https://discuss.elastic.co/t/kibana-painless-scripted-fields-and-regex-only-the-first-created-works/155414/1 "2018-11-05T14:31:00Z")

</div>

Greetings,

Recently I tried to create three scripted fields in Kibana 6.2.2. They all try to get a string, using a regex matching, from a same specific document field. Only the first scripted field gets a match, and although I have used the same logic in the other two, they always return "no match".

Below is an example of the field from where I want to get the matchings:

 ![tags_on](https://us1.discourse-cdn.com/elastic/original/3X/7/0/70804c329cc68e163a53b220cd20b47678407320.png)

My scripted fields are:

 ![scripted_fields](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4ad460bacc5caa38b023e1261f7a250f85bb6f5c.png)

And my results:  
 ![scripted_fields_matchings](https://us1.discourse-cdn.com/elastic/original/3X/0/b/0b6b22072528f41ec31404bdcc4c3bb9c56effd9.png)

As the last image is showing, only the scripted field sc-apip have the desired value, but the other two, not.

What could be my error or misunderstanding?

I thanks in advance for any help.

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [November 5, 2018, 3:29pm UTC](https://discuss.elastic.co/t/kibana-painless-scripted-fields-and-regex-only-the-first-created-works/155414/2 "2018-11-05T15:29:55Z")

</div>

The second and third fields are looking for the REGEX `CPC_APMAC_.+.` and `CPC_APNAME_.+.` but the matches that you are trying to find do not have any `.` in their values. Try just matching for `CPC_APMAC_` and `CPC_APNAME_` in the REGEX.

---

<div class="post-metadata">

**Author:** ![Robert\_Pereira](https://avatars.discourse-cdn.com/v4/letter/r/f6c823/32.png) [@Robert\_Pereira](https://discuss.elastic.co/u/Robert_Pereira)\
**Post date:** [November 5, 2018, 6:17pm UTC](https://discuss.elastic.co/t/kibana-painless-scripted-fields-and-regex-only-the-first-created-works/155414/3 "2018-11-05T18:17:32Z")

</div>

Hi Nathan,

Thank you for your answer. I have tried your suggestion. But I did not get the expected result. The opennac\_tags\_on field is an array (the developer informed me), so I believe matching is only happening with the string of the first element of the array. Do you have any guidance on how to iterate through the array using the Painless language?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [November 5, 2018, 6:57pm UTC](https://discuss.elastic.co/t/kibana-painless-scripted-fields-and-regex-only-the-first-created-works/155414/4 "2018-11-05T18:57:14Z")

</div>

[Painless](https://www.elastic.co/guide/en/elasticsearch/painless/6.4/painless-api-reference.html) is just a subset of Java so you could use a standard `for` loop to iterate over the array.

I would recommend you preform these types of data parsing on ingest since scripted fields can be very resource intensive.

---

<div class="post-metadata">

**Author:** ![Robert\_Pereira](https://avatars.discourse-cdn.com/v4/letter/r/f6c823/32.png) [@Robert\_Pereira](https://discuss.elastic.co/u/Robert_Pereira)\
**Post date:** [November 6, 2018, 1:38pm UTC](https://discuss.elastic.co/t/kibana-painless-scripted-fields-and-regex-only-the-first-created-works/155414/5 "2018-11-06T13:38:42Z")

</div>

Hi Nathan,

I've managed to the the information into the scripted fields by using the Painless language. Below I share the solution using a for loop on each scripted fields in order to get the information from the array:

Field sc-apip:

for(int i=0; i \< doc['opennac\_tags\_on.keyword'].length;i++){  
def m = /(CPC\_APIP\_(?:[0-9]{1,3}.){3}[0-9]{1,3})/.matcher(doc['opennac\_tags\_on.keyword'][i]);  
if ( m.matches() ) {  
return m.group(1)  
}  
}

Field sc-apmac:

for(int i=0; i \< doc['opennac\_tags\_on.keyword'].length;i++){  
def n = /(CPC\_APMAC\_[0-9a-fA-F]{12})/.matcher(doc['opennac\_tags\_on.keyword'][i]);  
if ( n.matches() ) {  
return n.group(1)  
}  
}

Field sc-apname:

for(int i=0; i \< doc['opennac\_tags\_on.keyword'].length;i++){  
def n = /(CPC\_APNAME\_.+.\*)/.matcher(doc['opennac\_tags\_on.keyword'][i]);  
if ( n.matches() ) {  
return n.group(1)  
}  
}

Thanks for all assitance!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2018, 1:38pm UTC](https://discuss.elastic.co/t/kibana-painless-scripted-fields-and-regex-only-the-first-created-works/155414/6 "2018-12-04T13:38:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
