# Regex in pipeline "when" not working

**URL:** <https://community.graylog.org/t/regex-in-pipeline-when-not-working/3932>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, route-to-streampl\
**Created:** [January 24, 2018, 8:13pm UTC](https://community.graylog.org/t/regex-in-pipeline-when-not-working/3932 "2018-01-24T20:13:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![derqurps](https://avatars.discourse-cdn.com/v4/letter/d/c5a1d2/32.png) [@derqurps](https://community.graylog.org/u/derqurps)\
**Post date:** [January 24, 2018, 8:13pm UTC](https://community.graylog.org/t/regex-in-pipeline-when-not-working/3932/1 "2018-01-24T20:13:25Z")

</div>

I am trying to match a message field to a regex but the pipeline rule editor does not let me save the pipeline rule.

have i done something wrong ?

rule source:

> rule “route to stream abschluesse”  
> when  
> regex(“\/\*\/\*abgeschlossen”, to\_string($message.http\_request\_uri\_normalized)).matches == true  
> then  
> route\_to\_stream(“streamid”);  
> end

See attached picture for the error in the editor.

![pipelineRule](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/d/d25a0c0bc508e1f9e4ba97e4f889e485e37235a3.jpg)

I am using version 2.4.2 (currently upgraded from 2.3.2 to see if it changes something).

Edit: If i am using an empty regex, the editor would let me save the rule…

> regex(“”, to\_string($message.http\_request\_uri\_normalized)).matched == true

---

<div class="post-metadata">

**Author:** ![derqurps](https://avatars.discourse-cdn.com/v4/letter/d/c5a1d2/32.png) [@derqurps](https://community.graylog.org/u/derqurps)\
**Post date:** [January 24, 2018, 8:47pm UTC](https://community.graylog.org/t/regex-in-pipeline-when-not-working/3932/2 "2018-01-24T20:47:19Z")

</div>

i will answer this myself.

I forgot to escape the backslashes in the pattern as stated in the docs:

> Note: Patterns have to be valid Java String literals, please ensure you escape any backslashes in your regular expressions!

sorry for the unnecessary question

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [February 7, 2018, 8:47pm UTC](https://community.graylog.org/t/regex-in-pipeline-when-not-working/3932/3 "2018-02-07T20:47:22Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
