# String Occurrences within a String

**URL:** <https://discuss.elastic.co/t/string-occurrences-within-a-string/177121>\
**Category:** Kibana\
**Created:** [April 16, 2019, 4:05pm UTC](https://discuss.elastic.co/t/string-occurrences-within-a-string/177121 "2019-04-16T16:05:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![thalfast](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thalfast/32/44274_2.png) [@thalfast](https://discuss.elastic.co/u/thalfast)\
**Post date:** [April 16, 2019, 4:05pm UTC](https://discuss.elastic.co/t/string-occurrences-within-a-string/177121/1 "2019-04-16T16:05:19Z")

</div>

I am new to Elastic and Kibana. So far I have had very little issue in developing basic visualizations and searches. However I have come upon an issue that I have seen other people post about but cannot seem to resolve my problem.

I need to count the number of occurrences of a sub-string within a string field.

My index pattern is similar to this:

- \_id: type string (aggregatable)
- content.content: type string
- content.content.keyword: type string (aggregatable)

The content.content field is HTML for a webpage (yes, I know I have to escape out reserved characters when searching.) An example of what I am trying to do is count the number of times a specific iframe element exists within this webpage.

My query syntax looks like this: `content.content : "iframe class=\"lls_activity_embed\""` and it works but the results only return 1 hit per object. In english, this basically shows me "the number of objects that have _`insert search term`_ in the content.content field.

What I want is the number of times _`insert search term`_ occurs within the content.content field. I filtered the results down to a specific ID that I know had at least 2 iframes, and the result count was 1 (again, 1 ID that contained **at least one** iframe versus the 2 "iframes" count I was hoping for.

Is there anyway to accomplish this via query and visualization without adding calculated fields/filters/tokens/new index patterns/etc? Or worse yet, building a C# job that leverages HTML Agility pack to parse the inner elements and return counts to a db that I could then very easily count and group via SQL

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [April 17, 2019, 11:38am UTC](https://discuss.elastic.co/t/string-occurrences-within-a-string/177121/2 "2019-04-17T11:38:56Z")

</div>

the way Elasticsearch works doesn't make it suited for this kind of calculation. You could use a scripted field to count the number of substring occurrences, but it's not a recommended method as it will put more strain on your cluster.  
Here's an example of a scripted field that somebody used to find substrings:

> [@Scripted field for Matching Substring](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013/2):
>
> Fixed it myself. def logger= doc['path.keyword'].value; if (logger!= null) { int lastSlashIndex = logger.lastIndexOf('/'); int lastUndrIndex = logger.lastIndexOf('\_'); if (lastSlashIndex \> 0) { return logger.substring(lastSlashIndex+1,lastUndrIndex); } } return "";

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2019, 11:39am UTC](https://discuss.elastic.co/t/string-occurrences-within-a-string/177121/3 "2019-05-15T11:39:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
