# Painless scripted field with regex syntax

**URL:** <https://discuss.elastic.co/t/painless-scripted-field-with-regex-syntax/143572>\
**Category:** Kibana\
**Created:** [August 8, 2018, 6:01pm UTC](https://discuss.elastic.co/t/painless-scripted-field-with-regex-syntax/143572 "2018-08-08T18:01:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![SonJ](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@SonJ](https://discuss.elastic.co/u/SonJ)\
**Post date:** [August 8, 2018, 6:01pm UTC](https://discuss.elastic.co/t/painless-scripted-field-with-regex-syntax/143572/1 "2018-08-08T18:01:00Z")

</div>

Hi,  
Here is how my massage column (under available fields) looks like:  
[2018-07-12 19:02:09.050][**][**][**] TRANS | app | TRANS | [ud.queue.name=UDReplyQueue\_**][req=HDRA2| **|MSN** | NP\*\*||][exec.time=435][usw.time=435][resp=HDRA2|GDS\*\*|SGA\*\*| UMN\*\*\*\*\*||]

so I am using following script to get SGA from all records:  
def m = \|SGA([^\|]+).matcher(doc["\_source"].value);  
if ( m.matches() ) {  
return m.group(1)  
} else {  
return "no match"  
}

But this is giving me a compile error. Maybe there is something with its syntax. I would appreciate any help. Thanks!

SJ

---

<div class="post-metadata">

**Author:** ![Catherine\_Liu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catherine_liu/32/34294_2.png) [@Catherine\_Liu](https://discuss.elastic.co/u/Catherine_Liu)\
**Post date:** [August 8, 2018, 8:08pm UTC](https://discuss.elastic.co/t/painless-scripted-field-with-regex-syntax/143572/2 "2018-08-08T20:08:12Z")

</div>

You need to wrap your regex with `/`s. It should look like

```auto
def m = /\|SGA([^\|]+)/.matcher(doc["_source"].value);
if ( m.matches() ) {
return m.group(1)
} else {
return "no match"
}

```

Also, make sure you have regex enabled, by adding `script.painless.regex.enabled: true` in your `elasticsearch.yml`.

---

<div class="post-metadata">

**Author:** ![SonJ](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@SonJ](https://discuss.elastic.co/u/SonJ)\
**Post date:** [August 8, 2018, 8:37pm UTC](https://discuss.elastic.co/t/painless-scripted-field-with-regex-syntax/143572/3 "2018-08-08T20:37:13Z")

</div>

Thanks Catherine!

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/2/9284dca112ede806edcb053c8aba50be812d9af6.png)

but even following query is not returning anything:  
doc['message.keyword'].value

I do see some content under message field on discover tab but I don't see any thing under this new field. When I try to use regex, it gives me a compile error. Maybe there is something different in that message field.

SJ

---

<div class="post-metadata">

**Author:** ![Catherine\_Liu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catherine_liu/32/34294_2.png) [@Catherine\_Liu](https://discuss.elastic.co/u/Catherine_Liu)\
**Post date:** [August 8, 2018, 9:11pm UTC](https://discuss.elastic.co/t/painless-scripted-field-with-regex-syntax/143572/4 "2018-08-08T21:11:53Z")

</div>

Instead of accessing `doc['message.keyword'].value`, does it work with `doc['message'].value`?

---

<div class="post-metadata">

**Author:** ![SonJ](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@SonJ](https://discuss.elastic.co/u/SonJ)\
**Post date:** [August 9, 2018, 4:23pm UTC](https://discuss.elastic.co/t/painless-scripted-field-with-regex-syntax/143572/5 "2018-08-09T16:23:34Z")

</div>

I get following error when I use (doc['message'].value) syntax instead:  
courier fetch: 1 of 5 shards failed.

This is a very long field though. Maybe 'doc' statement here has a word limitation?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2018, 4:23pm UTC](https://discuss.elastic.co/t/painless-scripted-field-with-regex-syntax/143572/6 "2018-09-06T16:23:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
