# Regexp for Mac Addresses

**URL:** <https://discuss.elastic.co/t/regexp-for-mac-addresses/185622>\
**Category:** Elasticsearch\
**Created:** [June 13, 2019, 11:09am UTC](https://discuss.elastic.co/t/regexp-for-mac-addresses/185622 "2019-06-13T11:09:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![thomas.heuberger](https://avatars.discourse-cdn.com/v4/letter/t/e8c25b/32.png) [@thomas.heuberger](https://discuss.elastic.co/u/thomas.heuberger)\
**Post date:** [June 13, 2019, 11:09am UTC](https://discuss.elastic.co/t/regexp-for-mac-addresses/185622/1 "2019-06-13T11:09:02Z")

</div>

So, I have a keyword field (yes, type is keyword as well, not just the name) that I want to match against MAC addresses.  
The field contains just the MAC address and nothing else, so anchoring is not a problem.

However, a query like

```
{
  "query": {
    "regexp": {
      "winlog.event_data.TargetUserName.keyword": {
        "value": "([0-9A-Fa-f]{2}[:-]){5}([0-9A-Fa-f]{2})"
      }
    }
  }
}

```

returns no results, even when I know for sure that it should.

Obviously, there is some problem with that regex in combination with elasticsearch, because [https://regex101.com/r/xtEKPs/1](https://regex101.com/r/xtEKPs/1) works as supposed.

Any ideas why this isn't working?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 13, 2019, 11:49am UTC](https://discuss.elastic.co/t/regexp-for-mac-addresses/185622/2 "2019-06-13T11:49:16Z")

</div>

This uses the lucene regular expression engine, which is not PCRE compatible.

See [https://www.elastic.co/guide/en/elasticsearch/reference/7.1/query-dsl-regexp-query.html#regexp-syntax](https://www.elastic.co/guide/en/elasticsearch/reference/7.1/query-dsl-regexp-query.html#regexp-syntax)

You can also read about it here [https://lucene.apache.org/core/8\_0\_0/core/org/apache/lucene/util/automaton/RegExp.html](https://lucene.apache.org/core/8_0_0/core/org/apache/lucene/util/automaton/RegExp.html)

This expression worked for me, but maybe I am missing something: `([0-9A-Fa-f]{2}[:]){5}[0-9A-Fa-f]{2}`

---

<div class="post-metadata">

**Author:** ![thomas.heuberger](https://avatars.discourse-cdn.com/v4/letter/t/e8c25b/32.png) [@thomas.heuberger](https://discuss.elastic.co/u/thomas.heuberger)\
**Post date:** [June 13, 2019, 12:18pm UTC](https://discuss.elastic.co/t/regexp-for-mac-addresses/185622/3 "2019-06-13T12:18:19Z")

</div>

Yes, your version indeed works. Which leaves me kinda puzzled. The only difference is that I have a set of separators ('-' and ': ') and you are using just colons. So actually you don't even have to use a set and could simplify it to `([0-9A-Fa-f]{2}:){5}([0-9A-Fa-f]{2})` .  
Anyways, I don't understand why my regex wouldn't work, Perl compliant or not.

---

<div class="post-metadata">

**Author:** ![whatgeorgemade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whatgeorgemade/32/103246_2.png) [@whatgeorgemade](https://discuss.elastic.co/u/whatgeorgemade)\
**Post date:** [June 13, 2019, 1:57pm UTC](https://discuss.elastic.co/t/regexp-for-mac-addresses/185622/4 "2019-06-13T13:57:14Z")

</div>

Your original one may not have worked because of the `-` in the range. The regex engine may have thought that was indicating a range (like `[0-9]`) instead of just a character.  
If you want to match special characters, you need to escape them with (I think) a `\`. Try `[:\-]`, or maybe even just have the `-` as the first character in the group so the engine may not consider it as a range identifier (`[-:]`).  
I haven't tested these - it's just based on experience.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2019, 2:02pm UTC](https://discuss.elastic.co/t/regexp-for-mac-addresses/185622/5 "2019-07-11T14:02:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
