# Regex is not working

**URL:** <https://discuss.elastic.co/t/regex-is-not-working/23202>\
**Category:** Elasticsearch\
**Created:** [April 12, 2015, 11:44pm UTC](https://discuss.elastic.co/t/regex-is-not-working/23202 "2015-04-12T23:44:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ayman](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Ayman](https://discuss.elastic.co/u/Ayman)\
**Post date:** [April 12, 2015, 11:44pm UTC](https://discuss.elastic.co/t/regex-is-not-working/23202/1 "2015-04-12T23:44:04Z")

</div>

Hello,

I'm trying to get exact match of field but unfortunately regexp doesn't  
work with me.

I have kibana 4 and elasticsearch 1.4.4 .

i'm using logstash template in my index and i have all string fields  
analyzed and not\_analyzed.

Now i'm trying to search inside field for string exactly for example

I have this urlField : /lang1/page1/ and /lang2/page1/ and /lang3/page1/  
etc...

i tried to play with the reg to get the above three urls ONLY but Kibana  
keep giving me anything contains any of the above example:

but Kibana returns to me results contans also:

/lang1/page4/other/url/?blahblahblah and /hello/this/is/ayman/lang1

but i don't need those i just need the above red urls exactly.

What is the problem here? please advise

Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineeth_mohan_2/32/747_2.png) [@vineeth\_mohan\_2](https://discuss.elastic.co/u/vineeth_mohan_2)\
**Post date:** [April 13, 2015, 6:30am UTC](https://discuss.elastic.co/t/regex-is-not-working/23202/2 "2015-04-13T06:30:36Z")

</div>

Hello Ayman ,

The regex is done on the token level and not on the string level.

Lets assume your field value is = abc/xyz  
This is broken into abc/xyz =\> [abc , xyz]  
Now you can do regex match on the token level and not on abc/xyz.  
So if you search for ab\* , it will match as it matches to abc but abc/x\*  
wont work because there is no single token in that format.

Your best bet here would be to make this field not\_analyzed as told in the  
below link.

LINK -

> **[Core Types | Elasticsearch Guide \[1.4\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/1.4/mapping-core-types.html)**

Now if you apply regex , it should work fine , because there is not  
tokenizing happening.

Thanks  
Vineeth Mohan,  
Elasticsearch consultant,  
[qbox.io](http://qbox.io) ( Elasticsearch service provider [http://qbox.io/](http://qbox.io/))

On Mon, Apr 13, 2015 at 5:14 AM, Ayman Shorman [aymanshorman@gmail.com](mailto:aymanshorman@gmail.com)  
wrote:

> Hello,
> 
> I'm trying to get exact match of field but unfortunately regexp doesn't  
> work with me.
> 
> I have kibana 4 and elasticsearch 1.4.4 .
> 
> i'm using logstash template in my index and i have all string fields  
> analyzed and not\_analyzed.
> 
> Now i'm trying to search inside field for string exactly for example
> 
> I have this urlField : /lang1/page1/ and /lang2/page1/ and /lang3/page1/  
> etc...
> 
> i tried to play with the reg to get the above three urls ONLY but Kibana  
> keep giving me anything contains any of the above example:
> 
> but Kibana returns to me results contans also:
> 
> /lang1/page4/other/url/?blahblahblah and /hello/this/is/ayman/lang1
> 
> but i don't need those i just need the above red urls exactly.
> 
> What is the problem here? please advise
> 
> Thanks
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5kRT%2BBckR-rJbTbAMgsCqnkTMwk1kBvQU5Z-r5G9EytwA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5kRT%2BBckR-rJbTbAMgsCqnkTMwk1kBvQU5Z-r5G9EytwA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ayman](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Ayman](https://discuss.elastic.co/u/Ayman)\
**Post date:** [April 14, 2015, 5:07pm UTC](https://discuss.elastic.co/t/regex-is-not-working/23202/3 "2015-04-14T17:07:03Z")

</div>

Hi Vineeth,  
Thank you for your reply.

Actually not\_anaylzed is worked fro me but I have problem.

let's get back to my example :

urlFiled.raw: /lang1/page1/ OR urlFiled.raw:/lang2/page1/ OR urlFiled.raw:  
/lang3/page1/ ------------\> works.

Now I'm trying to write regex to match the above urls in one regex line as  
the following:  
urlFieldd.raw: / /(lang1|lang2)/page1/ / --------\> didn't work  
urlField.raw: / /(lang1|lang2/page1)/$ /

and many others applied on urlFiled and urlFiled.raw

Can you please advise how get that regex working on Kibana and  
elasticsearch?

Thanks

On Monday, April 13, 2015 at 9:30:46 AM UTC+3, vineeth mohan wrote:

> Hello Ayman ,
> 
> The regex is done on the token level and not on the string level.
> 
> Lets assume your field value is = abc/xyz  
> This is broken into abc/xyz =\> [abc , xyz]  
> Now you can do regex match on the token level and not on abc/xyz.  
> So if you search for ab\* , it will match as it matches to abc but abc/x\*  
> wont work because there is no single token in that format.
> 
> Your best bet here would be to make this field not\_analyzed as told in the  
> below link.
> 
> LINK -  
> [Core Types | Elasticsearch Guide [1.4] | Elastic](http://www.elastic.co/guide/en/elasticsearch/reference/1.4/mapping-core-types.html)  
> [http://www.google.com/url?q=http%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Felasticsearch%2Freference%2F1.4%2Fmapping-core-types.html&sa=D&sntz=1&usg=AFQjCNF2HBtP6QOlrdDVeZoDWKBx7XEqOw](http://www.google.com/url?q=http%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Felasticsearch%2Freference%2F1.4%2Fmapping-core-types.html&sa=D&sntz=1&usg=AFQjCNF2HBtP6QOlrdDVeZoDWKBx7XEqOw)
> 
> Now if you apply regex , it should work fine , because there is not  
> tokenizing happening.
> 
> Thanks  
> Vineeth Mohan,  
> Elasticsearch consultant,  
> [qbox.io](http://qbox.io) ( Elasticsearch service provider [http://qbox.io/](http://qbox.io/))
> 
> On Mon, Apr 13, 2015 at 5:14 AM, Ayman Shorman \<[aymans...@gmail.com](mailto:aymans...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > Hello,
> > 
> > I'm trying to get exact match of field but unfortunately regexp doesn't  
> > work with me.
> > 
> > I have kibana 4 and elasticsearch 1.4.4 .
> > 
> > i'm using logstash template in my index and i have all string fields  
> > analyzed and not\_analyzed.
> > 
> > Now i'm trying to search inside field for string exactly for example
> > 
> > I have this urlField : /lang1/page1/ and /lang2/page1/ and  
> > /lang3/page1/ etc...
> > 
> > i tried to play with the reg to get the above three urls ONLY but Kibana  
> > keep giving me anything contains any of the above example:
> > 
> > but Kibana returns to me results contans also:
> > 
> > /lang1/page4/other/url/?blahblahblah and /hello/this/is/ayman/lang1
> > 
> > but i don't need those i just need the above red urls exactly.
> > 
> > What is the problem here? please advise
> > 
> > Thanks
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/7da6c37c-28b2-4fed-b555-ffead7475356%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/7da6c37c-28b2-4fed-b555-ffead7475356%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ayman](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Ayman](https://discuss.elastic.co/u/Ayman)\
**Post date:** [April 18, 2015, 4:08pm UTC](https://discuss.elastic.co/t/regex-is-not-working/23202/4 "2015-04-18T16:08:35Z")

</div>

Anyone please?

On Tuesday, April 14, 2015 at 8:07:03 PM UTC+3, Ayman Shorman wrote:

> Hi Vineeth,  
> Thank you for your reply.
> 
> Actually not\_anaylzed is worked fro me but I have problem.
> 
> let's get back to my example :
> 
> urlFiled.raw: /lang1/page1/ OR urlFiled.raw:/lang2/page1/ OR  
> urlFiled.raw:/lang3/page1/ ------------\> works.
> 
> Now I'm trying to write regex to match the above urls in one regex line as  
> the following:  
> urlFieldd.raw: / /(lang1|lang2)/page1/ / --------\> didn't work  
> urlField.raw: / /(lang1|lang2/page1)/$ /
> 
> and many others applied on urlFiled and urlFiled.raw
> 
> Can you please advise how get that regex working on Kibana and  
> elasticsearch?
> 
> Thanks
> 
> On Monday, April 13, 2015 at 9:30:46 AM UTC+3, vineeth mohan wrote:
> 
> > Hello Ayman ,
> > 
> > The regex is done on the token level and not on the string level.
> > 
> > Lets assume your field value is = abc/xyz  
> > This is broken into abc/xyz =\> [abc , xyz]  
> > Now you can do regex match on the token level and not on abc/xyz.  
> > So if you search for ab\* , it will match as it matches to abc but abc/x\*  
> > wont work because there is no single token in that format.
> > 
> > Your best bet here would be to make this field not\_analyzed as told in  
> > the below link.
> > 
> > LINK -  
> > [Core Types | Elasticsearch Guide [1.4] | Elastic](http://www.elastic.co/guide/en/elasticsearch/reference/1.4/mapping-core-types.html)  
> > [http://www.google.com/url?q=http%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Felasticsearch%2Freference%2F1.4%2Fmapping-core-types.html&sa=D&sntz=1&usg=AFQjCNF2HBtP6QOlrdDVeZoDWKBx7XEqOw](http://www.google.com/url?q=http%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Felasticsearch%2Freference%2F1.4%2Fmapping-core-types.html&sa=D&sntz=1&usg=AFQjCNF2HBtP6QOlrdDVeZoDWKBx7XEqOw)
> > 
> > Now if you apply regex , it should work fine , because there is not  
> > tokenizing happening.
> > 
> > Thanks  
> > Vineeth Mohan,  
> > Elasticsearch consultant,  
> > [qbox.io](http://qbox.io) ( Elasticsearch service provider [http://qbox.io/](http://qbox.io/))
> > 
> > On Mon, Apr 13, 2015 at 5:14 AM, Ayman Shorman [aymans...@gmail.com](mailto:aymans...@gmail.com)  
> > wrote:
> > 
> > > Hello,
> > > 
> > > I'm trying to get exact match of field but unfortunately regexp doesn't  
> > > work with me.
> > > 
> > > I have kibana 4 and elasticsearch 1.4.4 .
> > > 
> > > i'm using logstash template in my index and i have all string fields  
> > > analyzed and not\_analyzed.
> > > 
> > > Now i'm trying to search inside field for string exactly for example
> > > 
> > > I have this urlField : /lang1/page1/ and /lang2/page1/ and  
> > > /lang3/page1/ etc...
> > > 
> > > i tried to play with the reg to get the above three urls ONLY but Kibana  
> > > keep giving me anything contains any of the above example:
> > > 
> > > but Kibana returns to me results contans also:
> > > 
> > > /lang1/page4/other/url/?blahblahblah and /hello/this/is/ayman/lang1
> > > 
> > > but i don't need those i just need the above red urls exactly.
> > > 
> > > What is the problem here? please advise
> > > 
> > > Thanks
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit  
> > > [https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/f780fa73-1149-4eb7-8cf8-c1132fcb1a52%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/be9d679d-a0c1-4598-b5fa-a98ee8a97147%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/be9d679d-a0c1-4598-b5fa-a98ee8a97147%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:18am UTC](https://discuss.elastic.co/t/regex-is-not-working/23202/5 "2017-07-06T00:18:54Z")

</div>


