# Kibana Regex check if a field contains the value of another

**URL:** <https://discuss.elastic.co/t/kibana-regex-check-if-a-field-contains-the-value-of-another/309295>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [July 11, 2022, 7:46am UTC](https://discuss.elastic.co/t/kibana-regex-check-if-a-field-contains-the-value-of-another/309295 "2022-07-11T07:46:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Druffle](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@Druffle](https://discuss.elastic.co/u/Druffle)\
**Post date:** [July 11, 2022, 7:46am UTC](https://discuss.elastic.co/t/kibana-regex-check-if-a-field-contains-the-value-of-another/309295/1 "2022-07-11T07:46:50Z")

</div>

Hello,  
I'm trying to search for documents in which a description field contains the value of a name field (from another document). I tried to do a Regex query as following :

```auto
GET inventory-full-index/_search
{
  "query": {
    "regexp": {
      "description.description_data.value.keyword": ".*doc['name.keyword'].*"
    }
  }
}

```

It returns me interesting documents, that fit my need. the problem is that i created a document that contains "python3" in the description, and i made sure there was a document named "python3" as well. This query doesn't return this document, so i obviously missed something.  
Any idea how to fix this ?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [July 13, 2022, 1:41pm UTC](https://discuss.elastic.co/t/kibana-regex-check-if-a-field-contains-the-value-of-another/309295/2 "2022-07-13T13:41:58Z")

</div>

"_doc['name.keyword']._" dosn't work just as a regex pattern? Does it really look up `doc['name.keyword']`?

And what do you mean by "(from another document)"? The query clause should work on a single document.

---

<div class="post-metadata">

**Author:** ![Druffle](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@Druffle](https://discuss.elastic.co/u/Druffle)\
**Post date:** [July 13, 2022, 1:54pm UTC](https://discuss.elastic.co/t/kibana-regex-check-if-a-field-contains-the-value-of-another/309295/3 "2022-07-13T13:54:29Z")

</div>

> [@Tomo\_M](#):
>
> And what do you mean by "(from another document)"? The query clause should work on a single document.

My index contains a list of softwares and a list of CVE, I need to compare the software's name with CVE's description.  
I figured out this morning that the documents returned by this query were just CVE that had a field named "name" (even though the mapping was different), containing a word in common with the description.  
I guess I have to do the script outside kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2022, 1:55pm UTC](https://discuss.elastic.co/t/kibana-regex-check-if-a-field-contains-the-value-of-another/309295/4 "2022-08-10T13:55:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
