# Painless Scripted Field - TimeStamp - Regex

**URL:** <https://discuss.elastic.co/t/painless-scripted-field-timestamp-regex/138229>\
**Category:** Kibana\
**Created:** [July 2, 2018, 2:33pm UTC](https://discuss.elastic.co/t/painless-scripted-field-timestamp-regex/138229 "2018-07-02T14:33:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vvaidya](https://avatars.discourse-cdn.com/v4/letter/v/e56c9b/32.png) [@vvaidya](https://discuss.elastic.co/u/vvaidya)\
**Post date:** [July 2, 2018, 2:33pm UTC](https://discuss.elastic.co/t/painless-scripted-field-timestamp-regex/138229/1 "2018-07-02T14:33:50Z")

</div>

Hello Team,

I need help fetching Timestamp from the specific Kibana field. I'm using below painless script, but I get unexpected character `\\` error. Can you please suggest the correct way. I could use split, but the timestamp index is variable in my case. Thanks.

Regex - [https://regex101.com/r/qtACqh/1](https://regex101.com/r/qtACqh/1)

```
def m = \d{2,2}\/\d{2,2}\/\d{4,4} \d{2,2}:\d{2,2}:\d{2,2}
$/.matcher(doc['message.keyword'].value);
if(m.matches())
{
  return m.group(1)
}
else
{
   return "no timestamp found"
}

```

`type":"illegal_argument_exception","reason":"unexpected character [\\].","caused_by":{"type":"lexer_no_viable_alt_exception","reason":null}}}},{"shard":3,"index":"default-2018.05","node":"XTVSx9u9RYqM3aJBp1_-Rw","reason":{"type":"general_script_exception","reason":"Failed to compile inline script`

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c1066289e3c7e5780d14f0310833dd738d81a76.png)

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [July 2, 2018, 7:04pm UTC](https://discuss.elastic.co/t/painless-scripted-field-timestamp-regex/138229/2 "2018-07-02T19:04:41Z")

</div>

Have you set `script.painless.regex.enabled: true` in your elasticsearch.yml?

---

<div class="post-metadata">

**Author:** ![vvaidya](https://avatars.discourse-cdn.com/v4/letter/v/e56c9b/32.png) [@vvaidya](https://discuss.elastic.co/u/vvaidya)\
**Post date:** [July 2, 2018, 7:20pm UTC](https://discuss.elastic.co/t/painless-scripted-field-timestamp-regex/138229/3 "2018-07-02T19:20:26Z")

</div>

Yes, no luck. I have restarted the service as well. Can you please confirm if I have set it in correct place (below screenshot).

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/0/406371a3c7d94a725a371b06d4b1706fb2892502.png)

Suspecting something wrong with my regex, I used the sample mentioned in the elastic documentation, I now get below error (Kibana 5.5.2)

`"reason":"Regexes are disabled. Set [script.painless.regex.enabled] to [true] in elasticsearch.yaml to allow them. Be careful though, regexes break out of Painless's protection against deep recursion and long loops.`

```
def m = /^.*\.([a-z]+)$/.matcher(doc['message.keyword'].value);
if ( m.matches() ) {
   return m.group(1)
} else {
   return "no match"
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2018, 7:20pm UTC](https://discuss.elastic.co/t/painless-scripted-field-timestamp-regex/138229/4 "2018-07-30T19:20:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
