# Regex query in search field of kibana dashboard

**URL:** https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038
**Category:** Kibana
**Created:** [April 28, 2017, 4:56pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038 "2017-04-28T16:56:49Z")
**Posts on this page:** 18
**Page:** 1

<div class="post-metadata">

### Author: ![Bhavana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavana/32/12221_2.png) [@Bhavana](https://discuss.elastic.co/u/Bhavana)
#### Post date: [April 28, 2017, 4:56pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/1 "2017-04-28T16:56:49Z")

</div>

Hello Everyone,

I am using a regex query in search field of kibana dashboard.  
my query is page: "[http://www.somename.com/places/](http://www.somename.com/places/)" \*

## result expected:

All the extension pages of "[http://www.somename.com/places/](http://www.somename.com/places/)" but i am getting few results with "[http://www.somename.com/](http://www.somename.com/)"

## mapping for the index

PUT search\_index  
{  
"mappings":  
{  
"all":  
{  
"properties" :  
{  
"page" :  
{  
"type" : "string",  
"index": "not\_analyzed"  
}  
}  
}  
}  
}

Could you please let me know what query should i use to get pages [http://www.somename.com/places/](http://www.somename.com/places/) extended to it .

Thank you

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [May 1, 2017, 7:36pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/2 "2017-05-01T19:36:21Z")

</div>

Hi Bhavana,

Can you try this: page:[http://www.somename.com/places/\*](http://www.somename.com/places/*) and see what happens?

There is some good learning resources here for understanding queries in Kibana:

> **[Elasticsearch/Kibana Queries - In Depth Tutorial](https://www.timroes.de/2016/05/29/elasticsearch-kibana-queries-in-depth-tutorial/#using-json-in-the-kibana-search)**
>
> This tutorial explains how to write and understand Kibana and Elasticsearch queries
> in depth and how the mapping of Elastichsearch influences these queries.

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![Bhavana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavana/32/12221_2.png) [@Bhavana](https://discuss.elastic.co/u/Bhavana)
#### Post date: [May 4, 2017, 1:40pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/3 "2017-05-04T13:40:22Z")

</div>

Thanks for the reply,

I tried "page:[http://www.somename.com/places/\*](http://www.somename.com/places/*)" it is returning zero results. I could not figure out the solution after reading the article too.

Page field is "not\_analyzed" and all the letters in the URL are small letters as the article mentioned about case-sensitive in "not\_analyzed" field .

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [May 4, 2017, 10:00pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/4 "2017-05-04T22:00:43Z")

</div>

Hi Bhavana,

Wild cards should work on not\_analyzed fields. Not sure what's really going on here. Can you please give us a sample document here? Will try to load it into my local machine and see whats up.

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [May 4, 2017, 10:09pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/5 "2017-05-04T22:09:58Z")

</div>

Bhavana,

Try this: page:[http://www.somename.com/places/\*](http://www.somename.com/places/*) and let me know. I got help and found out that we might need to escape the colon.

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![Bhavana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavana/32/12221_2.png) [@Bhavana](https://discuss.elastic.co/u/Bhavana)
#### Post date: [May 5, 2017, 2:43pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/6 "2017-05-05T14:43:57Z")

</div>

page:[http://www.somename.com/places/\*](http://www.somename.com/places/*) didn't worked out.

sample document is as below:

```
        "_source": {
           "date": "2017-02-03 12:00:00",
           "clientID": "http://www.somename.com/,
           "page": "http://www.somename.com/places/xxxx",
           "country": "India"
        }

```

## Mapping

"page": {  
"type": "string",  
"index": "not\_analyzed"  
}

Thank you,  
Bhavana.

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [May 5, 2017, 7:25pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/7 "2017-05-05T19:25:38Z")

</div>

Bhavana,

Can you please tell me which Kibana/ES version you are on?

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![Bhavana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavana/32/12221_2.png) [@Bhavana](https://discuss.elastic.co/u/Bhavana)
#### Post date: [May 5, 2017, 7:39pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/8 "2017-05-05T19:39:11Z")

</div>

Thank you for the reply,

ES version - 2.3.4 , Kibana version - 4.5.4.

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [May 5, 2017, 7:45pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/9 "2017-05-05T19:45:51Z")

</div>

Hi Bhavana,

Can you also post us what error do you see?

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![Bhavana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavana/32/12221_2.png) [@Bhavana](https://discuss.elastic.co/u/Bhavana)
#### Post date: [May 5, 2017, 8:19pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/10 "2017-05-05T20:19:45Z")

</div>

I am not getting any error with the regular expression used,

## Regex in the search field of kibana dashboard

page:"[http://www.somename.com/places/](http://www.somename.com/places/)"\*

## Result is same in the below cases

page:"[http://www.somename.com/places/](http://www.somename.com/places/)"\*  
page:"[http://www.somename.com/](http://www.somename.com/)"\*

## Result expected

All the extension pages of "[http://www.somename.com/places/](http://www.somename.com/places/)" but i am getting results with "[http://www.somename.com/yyy/](http://www.somename.com/yyy/)" too

Thank you,  
Bhavana

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [May 5, 2017, 8:38pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/11 "2017-05-05T20:38:08Z")

</div>

Can you try without using double quotes. And if you see a parser error please paste it in?

page:[http://www.somename.com/places/\*](http://www.somename.com/places/*)  
page:[http://www.somename.com/\*](http://www.somename.com/*)

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![Bhavana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavana/32/12221_2.png) [@Bhavana](https://discuss.elastic.co/u/Bhavana)
#### Post date: [May 5, 2017, 9:27pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/12 "2017-05-05T21:27:49Z")

</div>

## case 1)

page:[http://www.somename.com/\*](http://www.somename.com/*)

```
Error: RequesttoElasticsearchfailed: {
  "error": {
    "root_cause": [
      {
        "type": "query_parsing_exception",
        "reason": "Failed to parse query [page:http\\://www.somename.com/*]",
        "index": "allfields",
        "line": 1,
        "col": 206
      }
    ],
    "type": "search_phase_execution_exception",
    "reason": "all shards failed",
    "phase": "query",
    "grouped": true,
    "failed_shards": [
      {
        "shard": 0,
        "index": "allfields",
        "node": "Yoq",
        "reason": {
          "type": "query_parsing_exception",
          "reason": "Failed to parse query [page:http\\://www.somename.com/*]",
          "index": "allfields",
          "line": 1,
          "col": 206,
          "caused_by": {
            "type": "parse_exception",
            "reason": "Cannot parse 'page:http\\://www.somename.com/*': Lexical error at line 1, column 34. Encountered: <EOF> after : \"/*\"",
            "caused_by": {
              "type": "token_mgr_error",
              "reason": "Lexical error at line 1, column 34. Encountered: <EOF> after : \"/*\""
            }
          }
        }
      }
    ]
  }
}

```

## case 2)

page:[http://www.somename.com/places/\*](http://www.somename.com/places/*)

No error but showing all the pages in the index.

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [May 8, 2017, 10:46pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/14 "2017-05-08T22:46:26Z")

</div>

Hi Bhavana,

Try searching for page:places and keep us posted?

Thanks  
Bhavya

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [May 9, 2017, 12:57pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/15 "2017-05-09T12:57:25Z")

</div>

OK Bhavana. We got the answer from someone who actually co-wrote elasticsearch the definitive guide 😃  
Here is what you need to try:

`The `/` need to be escaped as well, so `page.keyword:http\\:\\/\\/www.somename.com\\/places\\/*`, otherwise `//` is considered an empty regex`

You can use this to debug your queries to understand what is really being searched.  
POST search\_index/\_validate/query?explain  
{  
"query": {  
"query\_string": {  
"query": "page.keyword:http\://www.somename.com\/places\/\*",  
"analyze\_wildcard": true  
}  
}  
}

Let us know what happens.

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![Bhavana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavana/32/12221_2.png) [@Bhavana](https://discuss.elastic.co/u/Bhavana)
#### Post date: [May 9, 2017, 4:57pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/16 "2017-05-09T16:57:56Z")

</div>

```
case 1) 
page.keyword:"http\\:\\/\\/www.somename.com\\/places\\/"*

showing all the values in the index

case 2) 
page.keyword:"http\\:\\/\\/www.somename.com\\/places\\/*"

No results

case 3)
page:http\\:\\/\\/www.somename.com\\/places\\/*

failed to parse query

case 4)
page.keyword:http\\:\\/\\/www.somename.com\\/places\\/*

failed to parse query

case 5)
"page.keyword:http\\:\\/\\/www.somename.com\\/places\\/*"

No results

case 6)
"page.keyword:http\\:\\/\\/www.somename.com\\/places\\/"*

showing all the values in the index

```

Could not able to get the required result with the above changes too,

Thank you,  
Bhavana

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [May 10, 2017, 3:51pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/17 "2017-05-10T15:51:09Z")

</div>

Bhavana,

Can you please try this?  
page:[http://www.somename.com/places/\*](http://www.somename.com/places/*)

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![Bhavana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavana/32/12221_2.png) [@Bhavana](https://discuss.elastic.co/u/Bhavana)
#### Post date: [May 10, 2017, 4:14pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/18 "2017-05-10T16:14:11Z")

</div>

page:[http://www.somename.com/places/\*](http://www.somename.com/places/*) regex worked out perfectly to display all the extension pages of "[http://www.somename.com/places/](http://www.somename.com/places/)"

Great work.

Thank You,  
Bhavana.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 7, 2017, 4:22pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038/19 "2017-06-07T16:22:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
