# Tag Doc if match to List of Text terms Keywords

**URL:** <https://discuss.elastic.co/t/tag-doc-if-match-to-list-of-text-terms-keywords/286662>\
**Category:** Logstash\
**Created:** [October 13, 2021, 9:56pm UTC](https://discuss.elastic.co/t/tag-doc-if-match-to-list-of-text-terms-keywords/286662 "2021-10-13T21:56:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dallas\_Toth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dallas_toth/32/22630_2.png) [@Dallas\_Toth](https://discuss.elastic.co/u/Dallas_Toth)\
**Post date:** [October 13, 2021, 9:56pm UTC](https://discuss.elastic.co/t/tag-doc-if-match-to-list-of-text-terms-keywords/286662/1 "2021-10-13T21:56:59Z")

</div>

I have a list of terms about 1000 words and I want to have logstash in a Filter tag the document if there is a match in any of the words in a text field.  
Example:  
text : "The big brown dog"  
My List of 1000 terms has Dog as a word.  
So Logstash Tags that Document with "Animal"  
Notice I would like the match to be caseinsensitive as well.

The reason I would like to do this is that I have tried to use Filters like the below filter and they just don't perform well when you have 1000+ words it is searching through millions of documents. So if I could create a better performing Tag system I could just filter for the Documents that have that TAG.  
Anyone out there doing Keyword extractions like this to tag documents coming through Logstash?

```auto
{
  "query": {
    "bool": {
      "minimum_should_match": 1,
      "should": [
        {
          "match_phrase": {
            "text": "Dog"
          }
        },
        {
          "match_phrase": {
            "text": "Cat"
          }
        },
        {
          "match_phrase": {
            "text": "1000+ Animal Types"
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 13, 2021, 10:35pm UTC](https://discuss.elastic.co/t/tag-doc-if-match-to-list-of-text-terms-keywords/286662/2 "2021-10-13T22:35:59Z")

</div>

It is unclear whether you want to test if a field is equal to one of the values, or whether it contains one of the values (i.e. a substring). In either case you can use a [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter.

That said, in the substring case, matching a field against a thousand regular expressions `*dog*` `*cat*` etc. is going to be expensive. You can make the match case-insensitive by doing the translate against a copy of the field which you mutate+lowercase.

---

<div class="post-metadata">

**Author:** ![Dallas\_Toth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dallas_toth/32/22630_2.png) [@Dallas\_Toth](https://discuss.elastic.co/u/Dallas_Toth)\
**Post date:** [October 14, 2021, 5:42pm UTC](https://discuss.elastic.co/t/tag-doc-if-match-to-list-of-text-terms-keywords/286662/3 "2021-10-14T17:42:18Z")

</div>

Thanks for this. I believe I have a plan going forward with this as the solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2021, 5:42pm UTC](https://discuss.elastic.co/t/tag-doc-if-match-to-list-of-text-terms-keywords/286662/4 "2021-11-11T17:42:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
