# REGEX-Painless returns null

**URL:** <https://discuss.elastic.co/t/regex-painless-returns-null/128367>\
**Category:** Kibana\
**Created:** [April 17, 2018, 1:47pm UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367 "2018-04-17T13:47:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 17, 2018, 1:47pm UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367/1 "2018-04-17T13:47:39Z")

</div>

Hey guys,

I have the following problem. In the JSON Messages for ES I got multiple data in a field and I want to match this data with an regex. So I´ve tested it in the Kibana Developer Console (Webinterface) and I`ve tried to understand what I am doing wrong.

I have the following painless-script for a scripted field:

> **Painless-script**
>
> ```
> if(doc['myField.keyword'].value != null){
> Matcher m = (?<Group0>UserName=)(?<Group1>\w+\ {1,2}\w+)/.matcher(doc['myField.keyword'].value);
> if(m.find())
> {
> return m.group(2);
> }
> else{
> return \"NoMatch\";
> }}
> else{
> return \"NULL\";
> }
> 
> ```

The problem is that Kibana returns just the value for NULL, but **ALL** messages contain this data.  
If I understand correctly this would be mean that the field myField.keyword should be NULL but this is not the case.

I hope somebody have a solution for my problem.  
I am looking forward to hear from you!  
Best regards,  
Robert

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [April 17, 2018, 6:48pm UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367/2 "2018-04-17T18:48:30Z")

</div>

Have you tried using `doc['myField'].value` instead?

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 18, 2018, 6:15am UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367/3 "2018-04-18T06:15:38Z")

</div>

Hey @lukas,

Thanks for your answer.  
I´ve tried your version with doc['myField'].value. After I setting the property "fielddata" to true, I can search directly in the value of doc['myField']. But it seems that my regex-expression does not find anything, but it works for me in seperate tool to build regex-expressions.

Do you have an idea why I don´t get anything from the regex-expression in kibana?

Once again thanks a lot!  
Best regards,  
Robert

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [April 18, 2018, 4:02pm UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367/4 "2018-04-18T16:02:56Z")

</div>

Okay, looking at the docs, it looks like regex is disabled by default in Painless:

[https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-examples.html#modules-scripting-painless-regex](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-examples.html#modules-scripting-painless-regex)

Have you enabled it? And are you using the syntax that Painless suggests?

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 18, 2018, 4:09pm UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367/5 "2018-04-18T16:09:59Z")

</div>

Yes, I´ve enabled painless regex in the `elasticsearch.yml`.

Here you can see my script:

> **My script**
>
> ```
> if(doc['myField.keyword'].value != null){
> Matcher m = /(?<Group0>UserName=)(?<Group1>\w+\ {1,2}\w+)/.matcher(doc['myField.keyword'].value);
> if(m.find())
> {
> return m.group(2);
> }
> else{
> return \"NoMatch\";
> }}
> else{
> return \"NULL\";
> }
> 
> ```

This is my regex: `(?<Group0>UserName=)(?<Group1>\w+\ {1,2}\w+)`

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [April 18, 2018, 5:03pm UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367/6 "2018-04-18T17:03:55Z")

</div>

What is an example of something you want to match and something that you don't want to match?

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 19, 2018, 5:40am UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367/7 "2018-04-19T05:40:39Z")

</div>

Hey @lukas,  
Here you can see an example of my data inside the field:

> **MyField - Data**
>
> ```
> {ID=1234,
> Server=google.com,
> Application=OPERA,
> UserName=MYSERVER\\USERNAME1234,
> VERSION=1.0.0.1,
> Framework=.NET,
> Data=TEST-DATA,
> HostName=MYHOSTNAME
> }MyFIELD
> 
> ```

This is the field-value! It´s not a seperate Message.  
I want to get the Username including SERVER\\Username (the backslash can be one or two inside the name). I hope this "Test-Data" can help you to find out whats the problem.

Thank you!  
Best regards,  
Robert

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 20, 2018, 6:44am UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367/8 "2018-04-20T06:44:31Z")

</div>

Hey everybody,

I just let myself spend the `field value`, but I get back the value `"0"` even though my message on the `Discover` page is in this field. Does anyone have an idea why that is?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2018, 6:44am UTC](https://discuss.elastic.co/t/regex-painless-returns-null/128367/9 "2018-05-18T06:44:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
