Elastic Search - search the data ignoring periods or - elasticsearch

The elastic search index has the data having CPFs.
"name": "A",
"cpf": "718.881.683-23",
"name": "B",
"cpf": "404.833.187-60",
I want to search the data by field cpf as following:
query: 718
output: doc with name "A"
query: 718.881.683-23
output: doc with name "A"
The above is working.
But the following is not working.
query: 71888168323
output: doc with name "A"
Here I want to search the doc by field CPF data but without period and hyphen also.

You can add a custom analyzer that will remove all characters that are not digits and only index the digits.
The analyzer looks like this:
PUT test
"settings": {
"analysis": {
"filter": {
"number_only": {
"type": "pattern_replace",
"pattern": "\\D"
"analyzer": {
"cpf_analyzer": {
"type": "custom",
"tokenizer": "keyword",
"filter": [
"mappings": {
"properties": {
"cpf": {
"type": "text",
"analyzer": "cpf_analyzer"
Then you can index your documents as usual:
POST test/_doc
"name": "A",
"cpf": "718.881.683-23"
POST test/_doc
"name": "B",
"cpf": "404.833.187-60"
Searching for a prefix like 718 can be done like this:
POST test/_search
"query": {
"prefix": {
"cpf": "718"
Searching for the exact value with non-digit characters can be done like this:
POST test/_search
"query": {
"match": {
"cpf": "718.881.683-23"
And finally, you can also search with numbers only:
POST test/_search
"query": {
"match": {
"cpf": "71888168323"
With the given analyzer, all the above queries will return the document you expect.
If you cannot recreate your index for whatever reason, you can create a sub-field with the right analyzer and update your data in place:
PUT test/_mapping
"properties": {
"cpf": {
"type": "text",
"fields": {
"numeric": {
"type": "text",
"analyzer": "cpf_analyzer"
And then simply run the following command which will reindex all the data in place and populate the cpf.numeric field:
POST test/_update_by_query
All your searches will then need to be done on the cpf.numeric field instead of cpf directly.

718.881.683-23 is tokenized to 718 881 683 23 by the standard analyzer. So by default, you will find the document A with 718, 718 881, 718 and 23, but not with 7188 as there is no such token in the field. Probably you want to specify a different analyzer, for example using the edge n-gram tokenizer.
You can create a custom analyzer specifying a filter - for example, a pattern replace like the following (strips everything that is not a digit)
"my_char_filter": {
"type": "pattern_replace",
"pattern": "[^\d]",
"replacement": ""
and a edge n-gram
"my_tokenizer": {
"type": "edge_ngram",
"min_gram": 1,
"max_gram": 11,
"token_chars": [


Configure highlighted part in the elasticsearch

Main question
The user is looking for a name and enters the part of the it, let's say au, and the document with the text paul is found.
I would like to have the doc highlighted like p<em>au</em>l.
How can I achieve it if I have a complex search query (combination of match, prefix, wildcard to rule relevance)?
Sub question
When do highlight settings from documentation for type, boundary_scanner and boundary_chars come into play? As per my tests described below, these settings don't change highlighted part.
Try 1: Wildcard query with default analyzer
PUT myindex
"mappings": {
"properties": {
"name": {
"type": "text",
"term_vector": "with_positions_offsets"
POST myindex/_doc/1
"name": "paul"
GET myindex/_search
"query": {
"wildcard": {"name": "*au*"}
"highlight": {
"fields": {
"name": {}
"type": "fvh",
"boundary_scanner": "chars",
"boundary_chars": "abcdefghijklmnopqrstuvwxyz.,!? \t\n"
This kind of search returns highlight <em>paul</em> but I need to get p<em>au</em>l.
Try 2: Match query with NGRAM analyzer
This one works as described in SO question: Highlighting part of word in elasticsearch
PUT myindexngram
"settings": {
"analysis": {
"tokenizer": {
"ngram_tokenizer": {
"type": "nGram",
"min_gram": "2",
"max_gram": "3",
"token_chars": [
"analyzer": {
"index_ngram_analyzer": {
"type": "custom",
"tokenizer": "ngram_tokenizer",
"filter": [
"search_term_analyzer": {
"type": "custom",
"tokenizer": "keyword",
"filter": "lowercase"
"mappings": {
"properties": {
"name": {
"type": "text",
"analyzer": "index_ngram_analyzer",
"term_vector": "with_positions_offsets"
POST myindexngram/_doc/1
"name": "paul"
GET myindexngram/_search
"query": {
"match": {"name": "au"}
"highlight": {
"fields": {
"name": {}
This highlights p<em>au</em>l as desired but:
Highlighting depends on the query type, so combining match and wildcard will again result in <em>paul</em>.
Highlighting is not affected at all on type, boundary_scanner and boundary_chars settings.
Elastic version 7.13.4
Response from Elasticsearch team:
A highlighter works on terms, so only full terms can be highlighted - whatever are the terms in your index. In your second example, au could be highlighted, because it it a term in the index, which is not the case for your first example.
There is also an option to define your own highlight_query that could be different from the main query, but this could lead to unpredictable highlights.

Elasticsearch Edge NGram tokenizer higher score when word begins with n-gram

Suppose there is the following mapping with Edge NGram Tokenizer:
"settings": {
"analysis": {
"analyzer": {
"autocomplete_analyzer": {
"tokenizer": "autocomplete_tokenizer",
"filter": [
"autocomplete_search": {
"tokenizer": "whitespace"
"tokenizer": {
"autocomplete_tokenizer": {
"type": "edge_ngram",
"min_gram": 1,
"max_gram": 10,
"token_chars": [
"mappings": {
"tag": {
"properties": {
"id": {
"type": "long"
"name": {
"type": "text",
"analyzer": "autocomplete_analyzer",
"search_analyzer": "autocomplete_search"
And the following documents are indexed:
POST /tag/tag/_bulk
{"name" : "HITS FIND SOME"}
{"name" : "TRENDING HI"}
{"name" : "HITS OTHER"}
Then searching
"query": {
"match": {
"name": {
"query": "HI"
yields all with the same score, or TRENDING - HI with a score higher than one of the others.
How can it be configured, to show with a higher score the entries that actually start with the searcher n-gram? In this case, HITS FIND SOME and HITS OTHER to have a higher score than TRENDING HI; at the same time TRENDING HI should be in the results.
Highlighter is also used, so the given solution shouldn't mess it up.
The highlighter used in query is:
"highlight": {
"pre_tags": [
"post_tags": [
"fields": {
"name": {}
Using this with match_phrase_prefix messes up the highlighting, yielding <H><I><T><S> FIND SOME when searching only for H.
You must understand how elasticsearch/lucene analyzes your data and calculate the search score.
1. Analyze API
https://www.elastic.co/guide/en/elasticsearch/reference/current/_testing_analyzers.html this will show you what elasticsearch will store, in your case:
T / TR / TRE /.... TRENDING / / H / HI
2. Score
The bool query is often used to build complex query where you need a particular use case. Use must to filter document, then should to score. A common use case is to use different analyzers on a same field (by using the keyword fields in the mapping, you can analyze a same field differently).
3. dont mess highlight
According the doc: https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-highlighting.html#specify-highlight-query
You can add an extra query:
"query": {
"bool": {
"must" : [
"match": {
"name": "HI"
"should": [
"prefix": {
"name": "HI"
"highlight": {
"pre_tags": [
"post_tags": [
"fields": {
"name": {
"highlight_query": {
"match": {
"name": "HI"
In this particular case you could add a match_phrase_prefix term to your query, which does prefix match on the last term in the text:
"query": {
"bool": {
"should": [
"match": {
"name": "HI"
"match_phrase_prefix": {
"name": "HI"
The match term will match on all three results, but the match_phrase_prefix won't match on TRENDING HI. As a result, you'll get all three items in the results, but TRENDING HI will appear with a lower score.
Quoting the docs:
The match_phrase_prefix query is a poor-man’s autocomplete[...] For better solutions for search-as-you-type see the completion suggester and Index-Time Search-as-You-Type.
On a side note, if you're introducing that bool query, you'll probably want to look at the minimum_should_match option, depending on the results you want.
A possible solution for this problem is to use multifields. They allow for indexing of the same data from your source document in different ways. In your case you could index the name field as default text, then as ngrams and also as edgengrams. Then the query would have to be a bool query comparing with all those different fields.
The final score of documents is composed of the match value for each one. Those matches are also called signals, signalling that there is a match between the query and the document. The document with most signals matching gets the highest score.
In your case all documents would match the ngram HI. But only the HITS FIND SOME and the HITS OTHER document would get the edgengram additional score. This would give those two documents a boost and put them on top. The complication with this is that you have to make sure that the edgengram doesn't split on whitespaces, because then the HI at the end would get the same score as in the beginning of the document.
Here is an example mapping and query for your case:
PUT /tag/
"settings": {
"analysis": {
"analyzer": {
"edge_analyzer": {
"tokenizer": "edge_tokenizer"
"kw_analyzer": {
"tokenizer": "kw_tokenizer"
"ngram_analyzer": {
"tokenizer": "ngram_tokenizer"
"autocomplete_analyzer": {
"tokenizer": "autocomplete_tokenizer",
"filter": [
"autocomplete_search": {
"tokenizer": "whitespace"
"tokenizer": {
"kw_tokenizer": {
"type": "keyword"
"edge_tokenizer": {
"type": "edge_ngram",
"min_gram": 2,
"max_gram": 10
"ngram_tokenizer": {
"type": "ngram",
"min_gram": 2,
"max_gram": 10,
"token_chars": [
"autocomplete_tokenizer": {
"type": "edge_ngram",
"min_gram": 1,
"max_gram": 10,
"token_chars": [
"mappings": {
"tag": {
"properties": {
"id": {
"type": "long"
"name": {
"type": "text",
"fields": {
"edge": {
"type": "text",
"analyzer": "edge_analyzer"
"ngram": {
"type": "text",
"analyzer": "ngram_analyzer"
And a query:
POST /tag/_search
"query": {
"bool": {
"should": [
"function_score": {
"query": {
"match": {
"name.edge": {
"query": "HI"
"boost": "5",
"boost_mode": "multiply"
"match": {
"name.ngram": {
"query": "HI"
"match": {
"name": {
"query": "HI"

Elasticsearch query returning false results when term exceeds ngram length

The requirement is to search partial phrases in a block of text. Most of the words will be standard length. I want to keep the max_gram value down to 10. But there may be the occasional id/code with more characters than that, and these show up if I type in a query where the first 10 characters match, but then the rest don't.
For example, here is the mapping:
PUT my_index
"settings": {
"analysis": {
"analyzer": {
"autocomplete": {
"tokenizer": "autocomplete",
"filter": [
"tokenizer": {
"autocomplete": {
"type": "edge_ngram",
"min_gram": 1,
"max_gram": 10,
"token_chars": [
"mappings": {
"doc": {
"properties": {
"title": {
"type": "text",
"analyzer": "autocomplete"
and document:
POST my_index/doc/1
"title": "Quick fox with id of ABCDEFGHIJKLMNOP"
If I run the query:
POST my_index/doc/_search
"query": {
"match_phrase": {
"title": {
"query": "fox wi"
It returns the document as expected. However, if I run this:
POST my_index/doc/_search
"query": {
"match_phrase": {
"title": {
"query": "ABCDEFGHIJxxx"
It also returns the document, when it shouldn't. It will do this if the x's are after the 10th character, but not before it. How can I avoid this?
I am using version 5.
By default, the analyzer that is used at index time is the same analyzer that is used at search time, meaning the edge_ngram analyzer is used on your search term. This is not what you want. You will end up with 10 tokens as the search terms, none of which contain those last 3 characters.
You will want to take a look at the Search Analyzer for your mapping. This documentation points out this specific use case:
Sometimes, though, it can make sense to use a different analyzer at search time, such as when using the edge_ngram tokenizer for autocomplete.
The standard analyzer may suit your needs:
"mappings": {
"doc": {
"properties": {
"title": {
"type": "text",
"analyzer": "autocomplete",
"search_analyzer": "standard"

ElasticSearch Reverse Wildcard Search

In ElasticSearch v5.2.2 I can search for "Jo*" using Wildcard and it will match the index value containing "Joseph"
But what if my index also has these values "Joseph","Jo", "Jos", "Jose" and "Josep" and I want to reverse the query.
How can I find "Jo", "Jos", "Jose" and "Josep" in the index using the string "Joseph" as search criteria?
That's possible, but you need to create an edgeNGram search analyzer in your index settings.
First create the settings like this. The name field will be indexed with the standard analyzer but searched with your custom prefix_search analyzer instead.
PUT test
"settings": {
"analysis": {
"analyzer": {
"prefix_search": {
"type": "custom",
"tokenizer": "standard",
"filter": [
"filter": {
"prefix": {
"type": "edgeNGram",
"min_gram": 1,
"max_gram": 10
"mappings": {
"doc": {
"properties": {
"name": {
"type": "string",
"analyzer": "standard",
"search_analyzer": "prefix_search"
Then if you create a document like this:
PUT test/doc/1
"name": "Jos"
You can find it with a query like this one:
POST /test/doc/_search
"query": {
"match": {
"name": "Joseph"

wildcard on different tokens in elastic search

I have a document which looks like this
Thomy tyson Olando Magua
Using ngram i was able to acheive the wildcard search so that if i type in omy tyson it can return me the above document pretty much similar to this sql query
select name from table where name like '%omy tyson%'
PUT sample
"settings": {
"analysis": {
"analyzer": {
"my_ngram_analyzer": {
"tokenizer": "my_ngram_tokenizer"
"tokenizer": {
"my_ngram_tokenizer": {
"type": "nGram",
"min_gram": "2",
"max_gram": "15"
"mappings": {
"typename": {
"properties": {
"name": {
"type": "string",
"fields": {
"search": {
"type": "string",
"analyzer": "my_ngram_analyzer"
PUT sample/typename/2
"name": "Thomy tyson Olando Magua"
"query": {
"bool": {
"should": [
"term": {
"name.search": "omy tyson"
Is there a way in elastic search where i can perform wildcard search on 2 different words separated by other words like
select name from table where name like '%omy Magua%'
So in this case i would like to perform partial search on first and fourth word.
Any feedback would be helpfull
