# Timelion query to string containing slash "/" -- aka: howto use regexp in timelion

**URL:** <https://discuss.elastic.co/t/timelion-query-to-string-containing-slash-aka-howto-use-regexp-in-timelion/320158>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [November 30, 2022, 1:58pm UTC](https://discuss.elastic.co/t/timelion-query-to-string-containing-slash-aka-howto-use-regexp-in-timelion/320158 "2022-11-30T13:58:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![DrG](https://avatars.discourse-cdn.com/v4/letter/d/49beb7/32.png) [@DrG](https://discuss.elastic.co/u/DrG)\
**Post date:** [November 30, 2022, 1:58pm UTC](https://discuss.elastic.co/t/timelion-query-to-string-containing-slash-aka-howto-use-regexp-in-timelion/320158/1 "2022-11-30T13:58:52Z")

</div>

Hello everybody,  
in the database, a set of strings (stringified ids) are there, stemming from a directory view.  
Now I like to filter out subfolders - aka filter out those elements containing slash(es).

the database contents for "cgroup\_id":

- simple one slash "/"
- subfolder - level one - e.g "folder1" "folder2" "folder3"
- subfolder level two - e.g. "folder1/subfolder1" "folder2/subfolder2" "folder2/subfolder3"  
... and so on.

Now I would like to filder for data on the specific levels.  
How should the query look like? I've tried around a lot, but did not succeed - how is the proper solution to go for subfolder level 2?

```auto
.es ( q='(cgroup_id:"*\/*")' )
.es ( q='(cgroup_id:"*\\/*")' )
.es ( q='(cgroup_id:/*\\/*/)' )
.es ( q='(cgroup_id:*/*)' )

```

Thanks in advance,  
Günter

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2022, 1:59pm UTC](https://discuss.elastic.co/t/timelion-query-to-string-containing-slash-aka-howto-use-regexp-in-timelion/320158/2 "2022-12-28T13:59:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
