# Regex queries don't work in Kibana

**URL:** <https://discuss.elastic.co/t/regex-queries-dont-work-in-kibana/189723>\
**Category:** Kibana\
**Created:** [July 10, 2019, 10:33am UTC](https://discuss.elastic.co/t/regex-queries-dont-work-in-kibana/189723 "2019-07-10T10:33:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kechem](https://avatars.discourse-cdn.com/v4/letter/k/e99b99/32.png) [@kechem](https://discuss.elastic.co/u/kechem)\
**Post date:** [July 10, 2019, 10:33am UTC](https://discuss.elastic.co/t/regex-queries-dont-work-in-kibana/189723/1 "2019-07-10T10:33:03Z")

</div>

I have tried several combinations but cannot get regex queries to match the desired search string(s).

Sample extract:  
`[market-feed-render-4][user=xx.Xxxxx.Xxxx] [OUT] {"payload":{"id":"1562500842791.7273668","timestamp":"2019-07-09T15:25:39.303Z","messages": [guiapi-msg-processors-4][user=XX.XXXX] [IN] {"payload":{"command":{"requestContext":"clob2","commandName":"metrics","commandSubType":"UIResourceUsage","commandParams":{"metrics":`

Query:  
`index: et-ustlog* AND logMessage:/\[\s*[A-Z]+\]\ \{\"payload\"\:/`

Expectation is to match below strings:  
[OUT] {"payload":  
[IN] {"payload":

Note: Relevant field "logMessage" is not analyzed, and i have also attempted escaping the square brackets but no luck

Somebody help please.

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [July 10, 2019, 8:59pm UTC](https://discuss.elastic.co/t/regex-queries-dont-work-in-kibana/189723/2 "2019-07-10T20:59:09Z")

</div>

I like to use [https://regex101.com/](https://regex101.com/) when building regex. You can test your regex against some sample messages to ensure it works as expected.

Another suggestion is to break the message into fields at ingest. This will give you fields to query against and avoid regex altogether.

---

<div class="post-metadata">

**Author:** ![kechem](https://avatars.discourse-cdn.com/v4/letter/k/e99b99/32.png) [@kechem](https://discuss.elastic.co/u/kechem)\
**Post date:** [July 11, 2019, 7:40am UTC](https://discuss.elastic.co/t/regex-queries-dont-work-in-kibana/189723/3 "2019-07-11T07:40:25Z")

</div>

Thanks Nathan. My Regex is absolutely fine, see here too: [https://regex101.com/r/EvWd3Q/1](https://regex101.com/r/EvWd3Q/1)

If it turns out one cannot query data in ElasticSearch via Kibana using regex, it would be a fundamental flaw for such a search and analysis tool.

I know as a workaround I can break up my search but that's just not efficient.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2019, 7:40am UTC](https://discuss.elastic.co/t/regex-queries-dont-work-in-kibana/189723/4 "2019-08-08T07:40:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
