# Kibana UI search text for specific pattern

**URL:** <https://discuss.elastic.co/t/kibana-ui-search-text-for-specific-pattern/243369>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [July 31, 2020, 3:30pm UTC](https://discuss.elastic.co/t/kibana-ui-search-text-for-specific-pattern/243369 "2020-07-31T15:30:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dvanwesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dvanwesh/32/73630_2.png) [@dvanwesh](https://discuss.elastic.co/u/dvanwesh)\
**Post date:** [July 31, 2020, 3:30pm UTC](https://discuss.elastic.co/t/kibana-ui-search-text-for-specific-pattern/243369/1 "2020-07-31T15:30:21Z")

</div>

I have log messages with below pattern

`user status for userId 1 change previous state x1 new state x2` where previous and new state are different

`user status for userId 2 change previous state x1 new state x1` where previous and new state are same

I'm new to kibana and using UI to search for logs. When I type `user status for userId` for text search I get logs of above scenarios together.

How to search with regex to fetch logs for above mentioned two different scenarios.

search 1 should only return `user status for userId 1 change previous state x1 new state x2`

search 2 should only return `user status for userId 2 change previous state x1 new state x1`

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [August 4, 2020, 9:41pm UTC](https://discuss.elastic.co/t/kibana-ui-search-text-for-specific-pattern/243369/2 "2020-08-04T21:41:55Z")

</div>

Hello @dvanwesh

How are the docs structured? How are they being ingested into elasticsearch?

Thanks,  
Matt

---

<div class="post-metadata">

**Author:** ![dvanwesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dvanwesh/32/73630_2.png) [@dvanwesh](https://discuss.elastic.co/u/dvanwesh)\
**Post date:** [August 10, 2020, 2:37pm UTC](https://discuss.elastic.co/t/kibana-ui-search-text-for-specific-pattern/243369/3 "2020-08-10T14:37:45Z")

</div>

@mattkime they are just app server logs. I'm not aware of how elasticsearch is set up to ingest these logs.

---

<div class="post-metadata">

**Author:** ![mattkime](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattkime/32/43522_2.png) [@mattkime](https://discuss.elastic.co/u/mattkime)\
**Post date:** [August 10, 2020, 3:23pm UTC](https://discuss.elastic.co/t/kibana-ui-search-text-for-specific-pattern/243369/4 "2020-08-10T15:23:26Z")

</div>

generally speaking, it would be good to break up a string of text into multiple fields.

You need to use Lucene Query syntax to support regex - [elastic.co/guide/en/kibana/current/lucene-query.html](http://elastic.co/guide/en/kibana/current/lucene-query.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2020, 3:23pm UTC](https://discuss.elastic.co/t/kibana-ui-search-text-for-specific-pattern/243369/5 "2020-09-07T15:23:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
