# Regexp is ignored in must\_not clause

**URL:** <https://discuss.elastic.co/t/regexp-is-ignored-in-must-not-clause/311544>\
**Category:** Elasticsearch\
**Created:** [August 5, 2022, 1:46pm UTC](https://discuss.elastic.co/t/regexp-is-ignored-in-must-not-clause/311544 "2022-08-05T13:46:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ahoffskov](https://avatars.discourse-cdn.com/v4/letter/a/a9adbd/32.png) [@ahoffskov](https://discuss.elastic.co/u/ahoffskov)\
**Post date:** [August 5, 2022, 1:46pm UTC](https://discuss.elastic.co/t/regexp-is-ignored-in-must-not-clause/311544/1 "2022-08-05T13:46:42Z")

</div>

I'm trying to exclude a log-entry from showing up in my hits, but it is necessary to use regular expression (expensive is allowed in configuration).

The log entry follows the pattern:

```auto
message:Aug 2 05:01:14 <hostname> <servicename>: (<item>@<IPv4>) [ERROR] <String with specific error message>

```

What is needed to exclude from my hits is the combination of "item" and "String with specific error message", as I need reaction if the error message is shown for any other values of "item\>" than a specific value.  
Furthermore "IPv4" is interchangeable

so, my JSON Request looks like this:

```auto
{
  "version": true,
  "size": 500,
  "sort": [
    {
      "@timestamp": {
        "order": "desc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "@timestamp",
        "fixed_interval": "30s",
        "time_zone": "Europe/Copenhagen",
        "min_doc_count": 1
      }
    }
  },
  "stored_fields": [
    "*"
  ],
  "script_fields": {},
  "docvalue_fields": [
    {
      "field": "@timestamp",
      "format": "date_time"
    },
    {
      "field": "event.created",
      "format": "date_time"
    },
    {
      "field": "stamp",
      "format": "date_time"
    }
  ],
  "_source": {
    "excludes": []
  },
  "query": {
    "bool": {
      "filter": [
        {
          "bool": {
            "should": []
          }
        },
        {
          "bool": {
            "must": [
              {
                "match_phrase": {
                  "host.name": "<FQDN of host>"
                }
              },
              {
                "match_phrase": {
                  "log.file.path": "/path/to/logfile"
                }
              },
              {
                "match_phrase": {
                  "message": "error"
                }
              },
              {
                "match_phrase": {
                  "message": "<service>:"
                }
              }
            ]
          }
        },
        {
          "bool": {
            "must_not": [
              {
                "match_phrase": {
                  "message": "Can't open filename.xml: No such file or directory"
                }
              },
              {
                "match_phrase": {
                  "message": "Can't open other_filename.csv: No such file or directory"
                }
              },
              {
                "regexp": {
                  "message": {
                    "value": ".*<item>.*"
                  }
                }
              }
            ]
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "now-24H",
              "format": "strict_date_optional_time"
            }
          }
        }
      ]
    }
  },
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {}
    },
    "fragment_size": 2147483647
  }
}

```

(Sanitized for business purposes)

This gives me the same amount of hits that I expect by checking in Discover.

However, if I put ANYTHING behind "item" in my regexp, it seems to ignore it, ie:

```auto
{
   "regexp": {
      "message": {
         "value": ".*<item>.*<partial string>"
      }
   }
}

```

even though "item" and "partial string" co-exist in "message"

Where did I mess up?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2022, 1:47pm UTC](https://discuss.elastic.co/t/regexp-is-ignored-in-must-not-clause/311544/2 "2022-09-02T13:47:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
