# Search for substrings in specific order of appearance

**URL:** <https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841>\
**Category:** Kibana\
**Created:** [April 22, 2019, 11:41am UTC](https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841 "2019-04-22T11:41:09Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sagilo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagilo/32/44555_2.png) [@sagilo](https://discuss.elastic.co/u/sagilo)\
**Post date:** [April 22, 2019, 11:41am UTC](https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841/1 "2019-04-22T11:41:09Z")

</div>

Hi  
Is it possible to search for substrings in the same order as they appear in a text?  
I know I can run something like `term:first AND second`, but it will also return results where `second` appearing before `first`.  
I've tried using regex (`/first.*second/` and `/.*first.*second.*/`) but it didn't return any results

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [April 25, 2019, 1:26am UTC](https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841/2 "2019-04-25T01:26:14Z")

</div>

@Bargs help please?

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [April 25, 2019, 10:02pm UTC](https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841/3 "2019-04-25T22:02:10Z")

</div>

For a regex to work you'll need to query against the `keyword` version of the field. The reason it does not match the `text` version of the field is that the analyzer breaks the string into separate tokens, `first` and `second`. Neither token contains both `first` and `second` so nothing matches.

---

<div class="post-metadata">

**Author:** ![sagilo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagilo/32/44555_2.png) [@sagilo](https://discuss.elastic.co/u/sagilo)\
**Post date:** [April 25, 2019, 10:16pm UTC](https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841/4 "2019-04-25T22:16:34Z")

</div>

Thank you @Bargs  
The field I'm trying to query is not indexed.  
In fact, I'm looking for different values of the same key in array (held in a single item)

```auto
{
  "arr":
  [
    {
      "key": "val1"
    },
    {
      "key": "val2"
    }
  ]
}

```

So here I would want to discover the item when I look for `val1` followed by `val2`

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [April 29, 2019, 4:25pm UTC](https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841/5 "2019-04-29T16:25:41Z")

</div>

Elasticsearch can't do queries based on the JSON structure of the original document like this. If you indexed the array as a string with the terms occurring in the same order as in the array you could use a phrase query to do what you want though.

---

<div class="post-metadata">

**Author:** ![sagilo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagilo/32/44555_2.png) [@sagilo](https://discuss.elastic.co/u/sagilo)\
**Post date:** [April 29, 2019, 4:48pm UTC](https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841/6 "2019-04-29T16:48:25Z")

</div>

Sounds good.  
Are you referring to this?  
[https://www.elastic.co/guide/en/elasticsearch/reference/6.7/query-dsl-match-query-phrase.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.7/query-dsl-match-query-phrase.html)

Is there a page with more info about how should I use it?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 1, 2019, 3:11pm UTC](https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841/7 "2019-05-01T15:11:10Z")

</div>

Yes, but you wouldn't have to write query DSL. You could just query the field in the query bar like this:

```auto
arr.key:"val1 val2"

```

The double quotes around the values implies a phrase search. You can learn more about that syntax here: [https://www.elastic.co/guide/en/kibana/current/kuery-query.html](https://www.elastic.co/guide/en/kibana/current/kuery-query.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2019, 3:16pm UTC](https://discuss.elastic.co/t/search-for-substrings-in-specific-order-of-appearance/177841/8 "2019-05-29T15:16:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
