# Regexp query for phrase

**URL:** <https://discuss.elastic.co/t/regexp-query-for-phrase/296026>\
**Category:** Elasticsearch\
**Tags:** eql-elastic-query-language\
**Created:** [February 2, 2022, 5:28am UTC](https://discuss.elastic.co/t/regexp-query-for-phrase/296026 "2022-02-02T05:28:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Divyank\_Garg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_garg/32/99581_2.png) [@Divyank\_Garg](https://discuss.elastic.co/u/Divyank_Garg)\
**Post date:** [February 2, 2022, 5:28am UTC](https://discuss.elastic.co/t/regexp-query-for-phrase/296026/1 "2022-02-02T05:28:31Z")

</div>

I need to search for two signature pattern with 'and' operator between two phrase. How to write the query for that. In these two phrase I as shown below the \* means any number or value between 0-9 can be taken into consideration. How to write advance query for such type of pattern?  
2 signature pattern- (GBUS error \* timeout error) and​ (Asic \* is not a valid chip)​

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 2, 2022, 6:11am UTC](https://discuss.elastic.co/t/regexp-query-for-phrase/296026/2 "2022-02-02T06:11:05Z")

</div>

Easy way is use boolean query. You can use AND operation by `must` or `filter` clause.

> **[Boolean query | Elasticsearch Guide \[7.17\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html)**

---

<div class="post-metadata">

**Author:** ![Divyank\_Garg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_garg/32/99581_2.png) [@Divyank\_Garg](https://discuss.elastic.co/u/Divyank_Garg)\
**Post date:** [February 2, 2022, 6:38am UTC](https://discuss.elastic.co/t/regexp-query-for-phrase/296026/3 "2022-02-02T06:38:14Z")

</div>

Thanks for that. Will try boolean query but how to include the \* condition as well which can take any value between 0-9?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 2, 2022, 6:59am UTC](https://discuss.elastic.co/t/regexp-query-for-phrase/296026/4 "2022-02-02T06:59:43Z")

</div>

There are [regex query](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/query-dsl-regexp-query.html) for regular expressions. If you are asking about the regular expression pattern, it seems you need to learn a little about regular expressions

---

<div class="post-metadata">

**Author:** ![Divyank\_Garg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_garg/32/99581_2.png) [@Divyank\_Garg](https://discuss.elastic.co/u/Divyank_Garg)\
**Post date:** [February 2, 2022, 2:23pm UTC](https://discuss.elastic.co/t/regexp-query-for-phrase/296026/5 "2022-02-02T14:23:13Z")

</div>

GET 2021-0705-0486/\_search  
{  
"query": {  
"bool":{  
"should":[  
{"regexp": {"message.keyword": {  
"value": "._GBUS error [0-9] timeout error._",  
"flags": "ALL",  
"case\_insensitive": true,  
"max\_determinized\_states": 10000,  
"rewrite": "constant\_score"}}  
},  
{"regexp": {"message.keyword": {  
"value": "._Asic [0-9] is not a valid chip._",  
"flags": "ALL",  
"case\_insensitive": true,  
"max\_determinized\_states": 10000,  
"rewrite": "constant\_score"}}  
}  
]  
}  
}  
}  
This worked fine. Is this correct way to use regexp query for phrase with space along with bool query?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 2, 2022, 2:47pm UTC](https://discuss.elastic.co/t/regexp-query-for-phrase/296026/6 "2022-02-02T14:47:01Z")

</div>

That looks ok and even better if it's working well.  
What is the intention of "." on the start/end of pattern? To guarantee that pattern occurs truely inside the keyword?

From next time, please preformat your json with \</\> button. Thanks.

---

<div class="post-metadata">

**Author:** ![Divyank\_Garg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_garg/32/99581_2.png) [@Divyank\_Garg](https://discuss.elastic.co/u/Divyank_Garg)\
**Post date:** [February 3, 2022, 12:50pm UTC](https://discuss.elastic.co/t/regexp-query-for-phrase/296026/7 "2022-02-03T12:50:27Z")

</div>

Sorry its typo. I used .\* in start and end to search pattern inside the keyword.  
Thanks for help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2022, 12:50pm UTC](https://discuss.elastic.co/t/regexp-query-for-phrase/296026/8 "2022-03-03T12:50:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
