# Regex queries possible?

**URL:** <https://discuss.elastic.co/t/regex-queries-possible/19758>\
**Category:** Elasticsearch\
**Created:** [September 12, 2014, 2:05pm UTC](https://discuss.elastic.co/t/regex-queries-possible/19758 "2014-09-12T14:05:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Log\_Muncher](https://avatars.discourse-cdn.com/v4/letter/l/839c29/32.png) [@Log\_Muncher](https://discuss.elastic.co/u/Log_Muncher)\
**Post date:** [September 12, 2014, 2:05pm UTC](https://discuss.elastic.co/t/regex-queries-possible/19758/1 "2014-09-12T14:05:20Z")

</div>

Hi,

One of my servers appears to be feeding nonsense into Fluentd which is then  
ending up in elastic search.

Is it possible to use regex in queries ?

The syslog message content is always the same.... they start with numbers  
followed by close bracket, etc.

1. 
2. 
3. 

Is there a way to do the equivalent of ^\d+) in a elastic search query ?

Thanks !

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineeth_mohan_2/32/747_2.png) [@vineeth\_mohan\_2](https://discuss.elastic.co/u/vineeth_mohan_2)\
**Post date:** [September 12, 2014, 3:33pm UTC](https://discuss.elastic.co/t/regex-queries-possible/19758/2 "2014-09-12T15:33:46Z")

</div>

Hi ,

If this pattern is a single word , regex query might do the trick -

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Thanks  
Vineeth

On Fri, Sep 12, 2014 at 7:35 PM, Log Muncher [railroaderslament@gmail.com](mailto:railroaderslament@gmail.com)  
wrote:

> Hi,
> 
> One of my servers appears to be feeding nonsense into Fluentd which is  
> then ending up in Elasticsearch.
> 
> Is it possible to use regex in queries ?
> 
> The syslog message content is always the same.... they start with numbers  
> followed by close bracket, etc.
> 
> 1. 
> 2. 
> 3. 
> 
> Is there a way to do the equivalent of ^\d+) in a Elasticsearch query ?
> 
> Thanks !
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5n4yowfX98esw1MuUxDtVSjyxRtNHvnjqarnZ20o32N0A%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5n4yowfX98esw1MuUxDtVSjyxRtNHvnjqarnZ20o32N0A%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [September 12, 2014, 5:11pm UTC](https://discuss.elastic.co/t/regex-queries-possible/19758/3 "2014-09-12T17:11:48Z")

</div>

If not you can write a script filter that runs the regex. Its slow but it  
doesn't sound like you need it to be fast.

On Fri, Sep 12, 2014 at 11:33 AM, vineeth mohan [vm.vineethmohan@gmail.com](mailto:vm.vineethmohan@gmail.com)  
wrote:

> Hi ,
> 
> If this pattern is a single word , regex query might do the trick -  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-regexp-query.html#query-dsl-regexp-query)
> 
> Thanks  
> Vineeth
> 
> On Fri, Sep 12, 2014 at 7:35 PM, Log Muncher [railroaderslament@gmail.com](mailto:railroaderslament@gmail.com)  
> wrote:
> 
> > Hi,
> > 
> > One of my servers appears to be feeding nonsense into Fluentd which is  
> > then ending up in Elasticsearch.
> > 
> > Is it possible to use regex in queries ?
> > 
> > The syslog message content is always the same.... they start with numbers  
> > followed by close bracket, etc.
> > 
> > 1. 
> > 2. 
> > 3. 
> > 
> > Is there a way to do the equivalent of ^\d+) in a Elasticsearch query ?
> > 
> > Thanks !
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/19b17dc5-f188-4223-8d72-40732112814c%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5n4yowfX98esw1MuUxDtVSjyxRtNHvnjqarnZ20o32N0A%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5n4yowfX98esw1MuUxDtVSjyxRtNHvnjqarnZ20o32N0A%40mail.gmail.com)  
> [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5n4yowfX98esw1MuUxDtVSjyxRtNHvnjqarnZ20o32N0A%40mail.gmail.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5n4yowfX98esw1MuUxDtVSjyxRtNHvnjqarnZ20o32N0A%40mail.gmail.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAPmjWd3hmLjyw-LZ5sKFUCvyOujD\_aj5VUymNh8U19Qfp9ALbQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAPmjWd3hmLjyw-LZ5sKFUCvyOujD_aj5VUymNh8U19Qfp9ALbQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:02am UTC](https://discuss.elastic.co/t/regex-queries-possible/19758/4 "2017-07-06T01:02:43Z")

</div>


