# Need help to replace regex pattern to a common term in kibana query

**URL:** <https://discuss.elastic.co/t/need-help-to-replace-regex-pattern-to-a-common-term-in-kibana-query/209661>\
**Category:** Kibana\
**Created:** [November 27, 2019, 10:47am UTC](https://discuss.elastic.co/t/need-help-to-replace-regex-pattern-to-a-common-term-in-kibana-query/209661 "2019-11-27T10:47:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![keetsraj](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@keetsraj](https://discuss.elastic.co/u/keetsraj)\
**Post date:** [November 27, 2019, 10:47am UTC](https://discuss.elastic.co/t/need-help-to-replace-regex-pattern-to-a-common-term-in-kibana-query/209661/1 "2019-11-27T10:47:36Z")

</div>

Hi,

I am new to Kibana log analysis. I have to collect application usage data and I am trying to write a query that does the following work,

1. Some of the URLs have data embedded in it, thus making it difficult to group the URLs of same functionality together
2. I have written regex to extract them
3. Now, I need to replace those matches with a common term
4. Also, I need to access those values in the query.

How can I achieve this?

_Note: I do not have access to logstash or elastic search_

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [November 27, 2019, 11:41am UTC](https://discuss.elastic.co/t/need-help-to-replace-regex-pattern-to-a-common-term-in-kibana-query/209661/2 "2019-11-27T11:41:27Z")

</div>

Hi @keetsraj  
If you have the right to manage index patterns in kibana you can create an additional scripted field in your index that use the regex to compute a new field with these cleaned URLs.

[https://www.elastic.co/guide/en/kibana/current/scripted-fields.html](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html)

You will use Lucene or Painless scripting language to accomplish that:  
[https://www.elastic.co/guide/en/elasticsearch/reference/7.4/modules-scripting-painless.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/modules-scripting-painless.html)

You can check also this useful blog post that describe how to use regex in scripted fields:

> **[Using Painless in Kibana scripted fields](https://www.elastic.co/blog/using-painless-kibana-scripted-fields)**
>
> This blog presents common use cases for Kibana scripted fields, and walks user through how to create scripted fields in a newly set-up Elastic Cloud instance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2019, 11:55am UTC](https://discuss.elastic.co/t/need-help-to-replace-regex-pattern-to-a-common-term-in-kibana-query/209661/3 "2019-12-25T11:55:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
