# Query with Regexp and Filter together

**URL:** https://discuss.elastic.co/t/query-with-regexp-and-filter-together/88682
**Category:** Elasticsearch
**Created:** [June 8, 2017, 8:11am UTC](https://discuss.elastic.co/t/query-with-regexp-and-filter-together/88682 "2017-06-08T08:11:31Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![davidS](https://avatars.discourse-cdn.com/v4/letter/d/65b543/32.png) [@davidS](https://discuss.elastic.co/u/davidS)
#### Post date: [June 8, 2017, 8:11am UTC](https://discuss.elastic.co/t/query-with-regexp-and-filter-together/88682/1 "2017-06-08T08:11:31Z")

</div>

Hi,

I have the following query.

```
GET /logstash-win*/_search
{
  "query": {
    "bool": {
      "must": [
        { "regexp": { "event_data.CommandLine": ".*Hidden.*" }}
      ],
      "filter": [
        { "range": { "@timestamp": {"from": "now-1d", "to": "now" }}}
      ]
    }
  }
}

```

There exists a Document in my defined time interval with a field 'event\_data.CommandLine' wich includes the word 'Hidden'. The Field is from type 'text'.

There exosts also another Dodument with that field with a File Path included like 'ANY.dll'. It will be find by the following regexp.

```
.*dll.*"

```

Whats the problem here?

I am using Elasticsearch 5.4 with XPack

Thanks

David

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 8:11am UTC](https://discuss.elastic.co/t/query-with-regexp-and-filter-together/88682/2 "2017-07-06T08:11:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
