# Regex Search in Kibana

**URL:** <https://discuss.elastic.co/t/regex-search-in-kibana/97436>\
**Category:** Kibana\
**Created:** [August 17, 2017, 2:13pm UTC](https://discuss.elastic.co/t/regex-search-in-kibana/97436 "2017-08-17T14:13:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kevin\_Wiegand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_wiegand/32/19436_2.png) [@Kevin\_Wiegand](https://discuss.elastic.co/u/Kevin_Wiegand)\
**Post date:** [August 17, 2017, 2:13pm UTC](https://discuss.elastic.co/t/regex-search-in-kibana/97436/1 "2017-08-17T14:13:23Z")

</div>

Hey there,  
i want to do a Regex based Search on Kibana, i've read the Regex Instruction for Kibana an Lucene but i can't get my Search or Query to work.

I want to find each entry which begins with `"Login 123456"(<-6 Digits vom 0-9)`in the `logmsg` field.

So i tried this but there are no Search results.

`logmsg:/Login [0-9]{6}/`

I also tried Searching by a Custom Query but same result:

```
{
    "query": {
        "regexp":{
            "logmsg":"/Login [0-9]{6}/"
            }
        }
    }
}

```

Thanks for your Help!

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [August 17, 2017, 3:23pm UTC](https://discuss.elastic.co/t/regex-search-in-kibana/97436/2 "2017-08-17T15:23:58Z")

</div>

I assume that the problem is that the `logmsg` field is an analyzed `text` field. So the space doesn't actually exist in the indexed data. The regex you write needs to match a single token that was generated by the tokenizer for your field.

You could accomplish something similar by checking for both terms, but I'm not sure that accomplishes exactly what you want: (note the lower-case L which is how the token gets formatted)

```auto
  "query": {
    "bool": {
      "must": [
        {
          "regexp":{
            "logmsg":"[0-9]{6}"
            }
        },
        {
          "regexp":{
            "logmsg":"login"
            }
        }
      ]
    }
  }

```

If you instead index your field as a `keyword` instead of a `text` field, then you can write your regular expression as you would expect:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/4/c44fa4a82a684b0c5b2414de2d6730215bbc860e.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2017, 3:24pm UTC](https://discuss.elastic.co/t/regex-search-in-kibana/97436/3 "2017-09-14T15:24:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
