# Must\_not with an exception

**URL:** <https://discuss.elastic.co/t/must-not-with-an-exception/278301>\
**Category:** Elasticsearch\
**Created:** [July 9, 2021, 6:21pm UTC](https://discuss.elastic.co/t/must-not-with-an-exception/278301 "2021-07-09T18:21:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bcam135](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bcam135/32/91435_2.png) [@bcam135](https://discuss.elastic.co/u/bcam135)\
**Post date:** [July 9, 2021, 6:21pm UTC](https://discuss.elastic.co/t/must-not-with-an-exception/278301/1 "2021-07-09T18:21:11Z")

</div>

In basic terms, I have a current kibana alert and the query is set up to exclude all systems that have 800-999 in the hostname with the extraction query code below. That works fine.

However, I would I would like to exclude one system from that must\_not, let's just say a system with 855 in the name. How can I exclude 800-999, but include 855?

```auto
            "must_not": [
                {
                    "regexp": {
                        "host.hostname": {
                            "value": ".*[8-9][0-9][0-9].*",
                            "flags_value": 65535,
                            "max_determinized_states": 10000,
                            "boost": 1
                        }
                    }
                }

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 12, 2021, 8:47am UTC](https://discuss.elastic.co/t/must-not-with-an-exception/278301/2 "2021-07-12T08:47:29Z")

</div>

Hey,

My gut feeling tells me, that there might be a better and more performant solution than using a regexp query. Can you share a sample hostname/document and maybe we can find a more performant solution by indexing parts of the hostname into a dedicated field and then have fast queries?

--Alex

---

<div class="post-metadata">

**Author:** ![bcam135](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bcam135/32/91435_2.png) [@bcam135](https://discuss.elastic.co/u/bcam135)\
**Post date:** [July 12, 2021, 3:13pm UTC](https://discuss.elastic.co/t/must-not-with-an-exception/278301/3 "2021-07-12T15:13:31Z")

</div>

Hi Alex, thanks for the response. Sample hostnames could be system801, system901, system123, but they could also be anything else. They could be abc100defg or hijklmnop. The query is saying exclude the specific systems that are system800-999, but anything else include.

As background there are probably 20+ alerts/queries that exist already, created by someone else that are set up similarly. My specific task is to allow system855 which falls in that range of 800-999 to be included in this one alert.

---

<div class="post-metadata">

**Author:** ![bcam135](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bcam135/32/91435_2.png) [@bcam135](https://discuss.elastic.co/u/bcam135)\
**Post date:** [July 14, 2021, 9:05pm UTC](https://discuss.elastic.co/t/must-not-with-an-exception/278301/4 "2021-07-14T21:05:55Z")

</div>

Curious if anyone has other potential suggestions on this one?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2021, 9:06pm UTC](https://discuss.elastic.co/t/must-not-with-an-exception/278301/5 "2021-08-11T21:06:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
