# Regex double quotation use Lucene on Elasticsearch

**URL:** <https://discuss.elastic.co/t/regex-double-quotation-use-lucene-on-elasticsearch/352484>\
**Category:** Kibana\
**Created:** [February 4, 2024, 2:48pm UTC](https://discuss.elastic.co/t/regex-double-quotation-use-lucene-on-elasticsearch/352484 "2024-02-04T14:48:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![S\_n\_Ngo\_Hoang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s_n_ngo_hoang/32/123759_2.png) [@S\_n\_Ngo\_Hoang](https://discuss.elastic.co/u/S_n_Ngo_Hoang)\
**Post date:** [February 4, 2024, 2:48pm UTC](https://discuss.elastic.co/t/regex-double-quotation-use-lucene-on-elasticsearch/352484/1 "2024-02-04T14:48:48Z")

</div>

Hello everyone, I'm new to ELK and I'm eager to learn about searching and regex with Lucene. I want to know how to regex double quotation marks in logs. For example, in the "message" field, I want to filter logs that contain "user":"". I have tried escaping with \ but it removes all logs containing the word "user", or \\\ but it doesn't give me any results. I would greatly appreciate any assistance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2024, 2:49pm UTC](https://discuss.elastic.co/t/regex-double-quotation-use-lucene-on-elasticsearch/352484/2 "2024-03-03T14:49:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
