# Regexp not working in nested query

**URL:** <https://discuss.elastic.co/t/regexp-not-working-in-nested-query/286357>\
**Category:** Kibana\
**Created:** [October 11, 2021, 10:31am UTC](https://discuss.elastic.co/t/regexp-not-working-in-nested-query/286357 "2021-10-11T10:31:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ankit\_Anuj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankit_anuj/32/77134_2.png) [@Ankit\_Anuj](https://discuss.elastic.co/u/Ankit_Anuj)\
**Post date:** [October 11, 2021, 10:31am UTC](https://discuss.elastic.co/t/regexp-not-working-in-nested-query/286357/1 "2021-10-11T10:31:32Z")

</div>

{  
"query": {  
"bool": {  
"must": [  
{  
"match": {  
"testCase.status": "PASS"  
}  
},  
{  
"nested": {  
"path": "testCase.logs",  
"query": {  
"regexp": {  
"testCase.logs.message": {  
"value": "W.\*R"  
}  
}  
}  
}  
}

```auto
      ]
   }

```

}  
}  
i am searching for word WETR  
but using this query i am getting no match found

but manually when i tried finding the word its there.  
can you solve this bug?

---

<div class="post-metadata">

**Author:** ![sebastien](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastien/32/36119_2.png) [@sebastien](https://discuss.elastic.co/u/sebastien)\
**Post date:** [October 11, 2021, 2:42pm UTC](https://discuss.elastic.co/t/regexp-not-working-in-nested-query/286357/2 "2021-10-11T14:42:50Z")

</div>

Hi @Ankit_Anuj

Welcome to our community!

Could you provide a sample document (removing any sensitive data) that should match your query?  
Also could you format your message so we can better see the request you are sending?

I guess that in your mappings you have `testCase.status` as `keyword` and `testCase.logs` as `nested` field, is that correct?

Thank you  
Sébastien

---

<div class="post-metadata">

**Author:** ![Ankit\_Anuj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankit_anuj/32/77134_2.png) [@Ankit\_Anuj](https://discuss.elastic.co/u/Ankit_Anuj)\
**Post date:** [October 11, 2021, 3:05pm UTC](https://discuss.elastic.co/t/regexp-not-working-in-nested-query/286357/3 "2021-10-11T15:05:45Z")

</div>

the mapping is very huge.

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/2/4/240c5e0560c2e9ea73e05b0c35ccab78d3f73591.jpeg)  
and yes you are correct testCase.Status type is "text" and testCase.logs is "Nested" and testCase.logs.message is type "text"

"message": "WETR\*2\<\<",  
my query should match this but it is not maching  
▼

logs:

type:

nested

▼

properties:

▶

logger\_name:

▼

message:

type:

text  
hope this helps  
and please let me know how i can solve this?  
its very urgent for me  
actually Elastic is tokenizing my log file and that's why this query is not working.  
so please help me by telling the query which can solve this

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/4/145f98baba858be2f09e690a6d69664e0134a75b.png)

---

<div class="post-metadata">

**Author:** ![sebastien](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastien/32/36119_2.png) [@sebastien](https://discuss.elastic.co/u/sebastien)\
**Post date:** [October 12, 2021, 9:03am UTC](https://discuss.elastic.co/t/regexp-not-working-in-nested-query/286357/4 "2021-10-12T09:03:02Z")

</div>

Hi,

It is very difficult to follow if you don't format the code using the `code` block.

It seems that the string you want to match is `WETR*2<<` is that correct?

In that case the regex needs to be `W.*<` and not `W.*R`

Thanks  
Sébastien

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2021, 9:03am UTC](https://discuss.elastic.co/t/regexp-not-working-in-nested-query/286357/5 "2021-11-09T09:03:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
