# Regular expression search

**URL:** <https://discuss.elastic.co/t/regular-expression-search/197181>\
**Category:** Kibana\
**Created:** [August 28, 2019, 6:01pm UTC](https://discuss.elastic.co/t/regular-expression-search/197181 "2019-08-28T18:01:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticg](https://avatars.discourse-cdn.com/v4/letter/e/eada6e/32.png) [@elasticg](https://discuss.elastic.co/u/elasticg)\
**Post date:** [August 28, 2019, 6:01pm UTC](https://discuss.elastic.co/t/regular-expression-search/197181/1 "2019-08-28T18:01:52Z")

</div>

I'm trying to search for a request with search query - request:/api/user//[0-9a-z]{24}//status/summary  
example request: /api/user/\<24CharID\>/status/summary  
The search result shows any combination of the result. ex: /api, /api/search/user, /api/user/\<24CharID\>. How can I get results that only march regex?

Kibana version: 4.6.4  
Elasticsearch version: 2.4.4

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [August 28, 2019, 8:28pm UTC](https://discuss.elastic.co/t/regular-expression-search/197181/2 "2019-08-28T20:28:28Z")

</div>

I would recommend using a regex tester to verify your regex. [https://regex101.com/](https://regex101.com/) is one option.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 29, 2019, 4:24am UTC](https://discuss.elastic.co/t/regular-expression-search/197181/3 "2019-08-29T04:24:35Z")

</div>

I would recommend against using regex searches as it extremely inefficient and does not scale well at all. If you have specific things you are looking for it is better to extract this into separate fields or tag documents at index time as this means you do the processing once and can use the indices when querying rather than scan through all terms.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2019, 4:24am UTC](https://discuss.elastic.co/t/regular-expression-search/197181/4 "2019-09-26T04:24:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
