# Parsing email data with regex in scripted field

**URL:** <https://discuss.elastic.co/t/parsing-email-data-with-regex-in-scripted-field/238593>\
**Category:** Kibana\
**Created:** [June 25, 2020, 3:54am UTC](https://discuss.elastic.co/t/parsing-email-data-with-regex-in-scripted-field/238593 "2020-06-25T03:54:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![whyptrap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whyptrap/32/70605_2.png) [@whyptrap](https://discuss.elastic.co/u/whyptrap)\
**Post date:** [June 25, 2020, 3:54am UTC](https://discuss.elastic.co/t/parsing-email-data-with-regex-in-scripted-field/238593/1 "2020-06-25T03:54:56Z")

</div>

Hello, i am newbie in ELK stack. I want to create new field using scripted field in kibana. The new field contain parsed email data from exist field that contain email data too. I just want to get string before @ character in email using regex then i save it in new scripted field. Here my script:  
def m = /.\*(?=[\<@])$/.matcher(doc['email.keyword'].value);  
if ( m.matches() ) {  
return m.group(1)  
} else {  
return "no match"  
}

Try to run it, but error. How to do that correctly?  
Thankyou before 🙂

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 25, 2020, 8:51am UTC](https://discuss.elastic.co/t/parsing-email-data-with-regex-in-scripted-field/238593/2 "2020-06-25T08:51:54Z")

</div>

What error are you getting?

---

<div class="post-metadata">

**Author:** ![whyptrap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whyptrap/32/70605_2.png) [@whyptrap](https://discuss.elastic.co/u/whyptrap)\
**Post date:** [June 26, 2020, 1:20am UTC](https://discuss.elastic.co/t/parsing-email-data-with-regex-in-scripted-field/238593/3 "2020-06-26T01:20:32Z")

</div>

```
   {
 "root_cause": [
  {
   "type": "script_exception",
   "reason": "compile error",
   "script_stack": [
    "def m = /.*(?=[<@])/.matcher(doc[ ...",
    " ^---- HERE"
   ],
   "script": "def m = /.*(?=[<@])/.matcher(doc['email'].value);\r\nif ( m.matches() ) {\r\nreturn m.group(1)\r\n} else {\r\nreturn \"no match\"\r\n}",
   "lang": "painless"
  }
 ],
 "type": "search_phase_execution_exception",
 "reason": "all shards failed",
 "phase": "query",
 "grouped": true,
 "failed_shards": [
  {
   "shard": 0,
   "index": "antifraudx",
   "node": "hunieQf6QT6Sox5mOL4bcw",
   "reason": {
    "type": "script_exception",
    "reason": "compile error",
    "script_stack": [
     "def m = /.*(?=[<@])/.matcher(doc[ ...",
     " ^---- HERE"
    ],
    "script": "def m = /.*(?=[<@])/.matcher(doc['email'].value);\r\nif ( m.matches() ) {\r\nreturn m.group(1)\r\n} else {\r\nreturn \"no match\"\r\n}",
    "lang": "painless",
    "caused_by": {
     "type": "illegal_state_exception",
     "reason": "Regexes are disabled. Set [script.painless.regex.enabled] to [true] in elasticsearch.yaml to allow them. Be careful though, regexes break out of Painless's protection against deep recursion and long loops."
    }
   }
  }
 ]
}

```

I've got this error.

---

<div class="post-metadata">

**Author:** ![whyptrap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whyptrap/32/70605_2.png) [@whyptrap](https://discuss.elastic.co/u/whyptrap)\
**Post date:** [June 26, 2020, 1:48am UTC](https://discuss.elastic.co/t/parsing-email-data-with-regex-in-scripted-field/238593/4 "2020-06-26T01:48:36Z")

</div>

> [@whyptrap](#):
>
> `"reason": "Regexes are disabled. Set [script.painless.regex.enabled] to [true] in elasticsearch.yaml to allow them. Be careful though, regexes break out of Painless's protection against deep recursion and long loops."`

I think this is the reason why my code error, but after i add in elasticsearch.yml my code still showing same error.

---

<div class="post-metadata">

**Author:** ![whyptrap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whyptrap/32/70605_2.png) [@whyptrap](https://discuss.elastic.co/u/whyptrap)\
**Post date:** [June 26, 2020, 3:53am UTC](https://discuss.elastic.co/t/parsing-email-data-with-regex-in-scripted-field/238593/5 "2020-06-26T03:53:28Z")

</div>

This error are solved, elasticsearch need to restart after edit elasticsearch.yml configuration. But the regex doesn't return any value that i wanted like parsed string email. Am i wrong in writing the statement?

---

<div class="post-metadata">

**Author:** ![whyptrap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whyptrap/32/70605_2.png) [@whyptrap](https://discuss.elastic.co/u/whyptrap)\
**Post date:** [June 26, 2020, 7:08am UTC](https://discuss.elastic.co/t/parsing-email-data-with-regex-in-scripted-field/238593/6 "2020-06-26T07:08:22Z")

</div>

Already solve guys. I was wrong using "matcher" statement, i should use "split" to parse the data value. Thankyou 😊

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2020, 7:08am UTC](https://discuss.elastic.co/t/parsing-email-data-with-regex-in-scripted-field/238593/7 "2020-07-24T07:08:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
