# Negative regrex \[field\] comparison in Logstash

**URL:** <https://discuss.elastic.co/t/negative-regrex-field-comparison-in-logstash/254060>\
**Category:** Logstash\
**Created:** [November 2, 2020, 5:10pm UTC](https://discuss.elastic.co/t/negative-regrex-field-comparison-in-logstash/254060 "2020-11-02T17:10:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Orest\_Gulman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orest_gulman/32/46463_2.png) [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Post date:** [November 2, 2020, 5:10pm UTC](https://discuss.elastic.co/t/negative-regrex-field-comparison-in-logstash/254060/1 "2020-11-02T17:10:16Z")

</div>

Hi,  
I'm trying to achieve simple `[username]` field character cheks.  
If `[username]` field NOT consists of [A-Za-z] then add new field. For example, if `[username]` equals `foo.foo` then write it into separate field.

I can't figure out why the code below in my case not working:

```
if [username] !~ /^[A-Za-z]+/ {
    mutate { add_field => { "username_invalid" => "%{username}" } }
}

```

Thanks in advance for the hint.  
logstash 7.9

---

<div class="post-metadata">

**Author:** ![Orest\_Gulman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orest_gulman/32/46463_2.png) [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Post date:** [November 2, 2020, 5:18pm UTC](https://discuss.elastic.co/t/negative-regrex-field-comparison-in-logstash/254060/2 "2020-11-02T17:18:41Z")

</div>

I forgot to add `$` to the end of `/^[A-Za-z]+/`.  
The correct regrex is `/^[A-Za-z]+$/`.

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [November 2, 2020, 5:19pm UTC](https://discuss.elastic.co/t/negative-regrex-field-comparison-in-logstash/254060/3 "2020-11-02T17:19:24Z")

</div>

Your regex is never going to be false, cause if you have a username "foo.bar", the regex is detecting the word "foo" as true", complete it with the end line char `^[A-Za-z]+$`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2020, 5:19pm UTC](https://discuss.elastic.co/t/negative-regrex-field-comparison-in-logstash/254060/4 "2020-11-30T17:19:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
