# Workflow - Compare complex string

**URL:** <https://developer.sailpoint.com/discuss/t/workflow-compare-complex-string/23260>\
**Category:** SHF Discussion and Questions\
**Tags:** identity-security-cloud, workflows\
**Created:** [December 28, 2023, 11:12pm UTC](https://developer.sailpoint.com/discuss/t/workflow-compare-complex-string/23260 "2023-12-28T23:12:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![fatimahm](https://avatars.discourse-cdn.com/v4/letter/f/3d9bf3/32.png) [@fatimahm](https://developer.sailpoint.com/discuss/u/fatimahm)\
**Post date:** [December 28, 2023, 11:12pm UTC](https://developer.sailpoint.com/discuss/t/workflow-compare-complex-string/23260/1 "2023-12-28T23:12:47Z")

</div>

Hello,

Is there a way to make a complex string comparison with workflows ?  
I’m trying to check if a string has the format “word1 xyz word2” where “xyz” is a variable string.

Thanks !

---

<div class="post-metadata">

**Author:** ![jsosa](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jsosa/32/31578_2.png) [@jsosa](https://developer.sailpoint.com/discuss/u/jsosa)\
**Post date:** [December 29, 2023, 3:55am UTC](https://developer.sailpoint.com/discuss/t/workflow-compare-complex-string/23260/2 "2023-12-29T03:55:07Z")

</div>

Hi @fatimahm ! I think you can do it with the Define Variable Operator combined later with the Compare String. I tried this example and actually works, perhaps you should only work more on the pattern box of the last define variable.

This is my structure (trigger is only for testing purposes, and certainly you should get variables from other context):

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/b/ba43a390f9fdcf5115406b6df1373be7ed7b9015.png)

First define variable is only to set the 3 variables you mentioned (word1, word2 and XXX):

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/3/39eb2b1927be6f164053f677d926e1bf5573893e.png)

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/4/45adc621f0c1bf97d2e946921dd1de9e0df0c889.png)

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/6/66f3f7e4e2978d8f1cb272b6827551796284e2c2.png)

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/8/840e534dfa33f04d20f158659092e4656d1cecb3.png)

Next define variable only joins these three variables:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/4/434ddb06fb22678f62ae96a6ad44449c5f35eb43.png)

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/f/f52209199b162dca570cd9b77d3d1f8c1190721b.png)

Define Variable 3 (I used a DV2 but deleted it later), is the one that evaluates regular expression. It replace the “Word1 XXX Word2” String with the “ISOK” fixed String. So, always that the pattern is matched, the Define Variable 3 operator will return ISOK. Otherwise, it will return the result from Define Variable1:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/a/a1f70694f059f2af611182fe290dd113d745ecc1.png)

Is on the pattern box that you perhaps should to work a little more than this:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/7/7574cf77bc9a61d41c1a1aa3553f28148fb81ffe.png)

Finally, I use Compare Stirngs operator, to test if Define Variable 3 output is “ISOK” (meaning that original variable matches pattern), or is not:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/9/9a639f33c5ef41abb735716e8912acfc7ae68f5e.png)

For example, letting first 3 variables be Word1, XXX and Word2:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/5/5a388ef532c352d500e9b049bfaf1f0bad153d51.png)

Compounding last 3 variables:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/d/dfb66b22a83504a743819c9944a582d9bf4911fc.png)

Regex evaluates to “ISOK”:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/0/006405e5b32215a01e46355ec18c67a7d3f34fac.png)

Now suppose I change received XXX variable to YYY:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2a910e0146f8c601f2caedcd0a716f024231859.png)

When testing, pattern evaluation will cause to continue on the FALSE exit:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/7/78fef2d37d004e416320949a221fdcde71c5aae5.png)

Notice that the REGEX Defined Variable, as the patter is not matched, it returns original String:

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/5/5e202a603a7cce47dcd37a4e1d49ebea74558111.png)

And as it is not the “ISOK” String, that is why it goes on the FALSE exit path.

Hope it works!

---

<div class="post-metadata">

**Author:** ![fatimahm](https://avatars.discourse-cdn.com/v4/letter/f/3d9bf3/32.png) [@fatimahm](https://developer.sailpoint.com/discuss/u/fatimahm)\
**Post date:** [December 29, 2023, 10:04pm UTC](https://developer.sailpoint.com/discuss/t/workflow-compare-complex-string/23260/3 "2023-12-29T22:04:34Z")

</div>

Hello @jsosa  
Thank you so much for your time and your feedback.  
However, I’m not sure this could help for the context. Indeed, after getting roles (by Http Request), I’m using a loop to check if roles have assigned identities. I want to exclude some roles from the check and the format role names is “word1 xyz word2”.  
“word1” and “word2” are the same for all the roles.

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/d/d44f148f7f2f0cdc08470a7d0dd4b3b687d1b510.png)

One solution is to use the compare strings and specify all the ids (I want to avoid it since I have more than 100 roles).

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/5/5ca99b2b71363ef45540244f740e2b59f155a80f.png)

Thank you so much.

---

<div class="post-metadata">

**Author:** ![jsosa](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jsosa/32/31578_2.png) [@jsosa](https://developer.sailpoint.com/discuss/u/jsosa)\
**Post date:** [December 30, 2023, 3:39am UTC](https://developer.sailpoint.com/discuss/t/workflow-compare-complex-string/23260/4 "2023-12-30T03:39:00Z")

</div>

My pleasure! Does the XXX part of unwanted entitlements have some pattern? Remember that the regex Define Variable pattern box support full regular expression.

For example, pattern  
word1\s[^\s-]+\sword2

Should match  
word1 xxx word2  
wors1 yyy word2  
word1 otherword word2  
word1 anynonwhitespace word2

and then you can replace all pattern wih SOMESTRING, and use the comparator as I showed.

I think major problem is to find something in common of all these unwanted entitlements and try to put it in a regex expression, in the place where I put [^\s-]+ earlier (rest of pattern should remain the same)

---

<div class="post-metadata">

**Author:** ![fatimahm](https://avatars.discourse-cdn.com/v4/letter/f/3d9bf3/32.png) [@fatimahm](https://developer.sailpoint.com/discuss/u/fatimahm)\
**Post date:** [December 31, 2023, 12:43pm UTC](https://developer.sailpoint.com/discuss/t/workflow-compare-complex-string/23260/5 "2023-12-31T12:43:17Z")

</div>

Thank you so much @jsosa for your help 🙂 It works !  
Indeed, the part xyz is a country or city wich is defined as a membership criteria (They don’t have the same json path for all unwanted roles. Otherwise, I could put it in the variable and use it for filtering).

---

<div class="post-metadata">

**Author:** ![jsosa](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jsosa/32/31578_2.png) [@jsosa](https://developer.sailpoint.com/discuss/u/jsosa)\
**Post date:** [December 31, 2023, 4:33pm UTC](https://developer.sailpoint.com/discuss/t/workflow-compare-complex-string/23260/6 "2023-12-31T16:33:05Z")

</div>

Thanks you Tima! Grest it worked, have a happy new year!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [March 2, 2024, 8:47am UTC](https://developer.sailpoint.com/discuss/t/workflow-compare-complex-string/23260/8 "2024-03-02T08:47:33Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
