# String Occurrences within a String

**URL:** <https://discuss.elastic.co/t/string-occurrences-within-a-string/177121>\
**Category:** Kibana\
**Created:** [April 16, 2019, 4:05pm UTC](https://discuss.elastic.co/t/string-occurrences-within-a-string/177121 "2019-04-16T16:05:19Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [April 17, 2019, 11:38am UTC](https://discuss.elastic.co/t/string-occurrences-within-a-string/177121/2 "2019-04-17T11:38:56Z")

</div>

the way Elasticsearch works doesn't make it suited for this kind of calculation. You could use a scripted field to count the number of substring occurrences, but it's not a recommended method as it will put more strain on your cluster.  
Here's an example of a scripted field that somebody used to find substrings:

> [@Scripted field for Matching Substring](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013/2):
>
> Fixed it myself. def logger= doc['path.keyword'].value; if (logger!= null) { int lastSlashIndex = logger.lastIndexOf('/'); int lastUndrIndex = logger.lastIndexOf('\_'); if (lastSlashIndex \> 0) { return logger.substring(lastSlashIndex+1,lastUndrIndex); } } return "";

---

_[View the full topic](https://discuss.elastic.co/t/string-occurrences-within-a-string/177121)._
