# Libbeat common.Match not work with case insensitive

**URL:** <https://discuss.elastic.co/t/libbeat-common-match-not-work-with-case-insensitive/195315>\
**Category:** Beats\
**Created:** [August 15, 2019, 8:01am UTC](https://discuss.elastic.co/t/libbeat-common-match-not-work-with-case-insensitive/195315 "2019-08-15T08:01:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![111193](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111193/32/52350_2.png) [@111193](https://discuss.elastic.co/u/111193)\
**Post date:** [August 15, 2019, 8:01am UTC](https://discuss.elastic.co/t/libbeat-common-match-not-work-with-case-insensitive/195315/1 "2019-08-15T08:01:51Z")

</div>

beats document said filebeat suppport "(?i)" regexp

> **[Regular expression support | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/regexp-support.html#grouping)**

I read the beats code,found it depend on beats/libbeat/common/match,  
but I found beats/libbeat/common/match does not work with "(?i)" option  
version: [GitHub - elastic/beats: 🐠 Beats - Lightweight shippers for Elasticsearch & Logstash](http://github.com/elastic/beats) v7.3.0  
output:

> not match  
> match

code:

```
package main

import (
	"fmt"
	"log"
	"regexp"

	"github.com/elastic/beats/libbeat/common/match"
)

func main() {
	pattern := `(?i)warning`
	str := `warning`
	m, err := match.Compile(pattern)
	if err != nil {
		log.Fatal(err.Error())
	}
	if m.MatchString(str) {
		fmt.Println("match")
	} else {
		fmt.Println("not match")
	}
	m2, err := regexp.Compile(pattern)
	if err != nil {
		log.Fatal(err.Error())
	}
	ok := m2.MatchString(str)
	if ok {
		fmt.Println("match")
	} else {
		fmt.Println("not match")
	}
}

```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 15, 2019, 11:57am UTC](https://discuss.elastic.co/t/libbeat-common-match-not-work-with-case-insensitive/195315/2 "2019-08-15T11:57:46Z")

</div>

I was able to reproduce this. I opened [PR #13250](https://github.com/elastic/beats/pull/13250) with a fix.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2019, 1:57pm UTC](https://discuss.elastic.co/t/libbeat-common-match-not-work-with-case-insensitive/195315/3 "2019-09-12T13:57:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
