Matching the stored values and queries in Elastic Search - elasticsearch

I have a field called that is inside a nested field "name" that is a "Keyword" in elastic search.
Name field contains 2 values.
Jagannathan Rajagopalan
If I query "Rajagopalan", I should get only the item #2.
If I query the complete Jagannathan Rajagopalan, I should get #1.
How do I achieve it?

You need to use the term query which is used for exact search. Added a working example according to your use-case.
Index mapping
"mappings": {
"properties": {
"name": {
"type": "nested",
"properties": {
"keyword": {
"type": "keyword"
Index sample docs
"name" : {
"keyword" : "Jagannathan Rajagopalan"
And another doc
"name" : {
"keyword" : "Jagannathan"
And search query
"query": {
"nested": {
"path": "name",
"query": {
"bool": {
"must": [
"match": {
"name.keyword": "Jagannathan Rajagopalan"
Search result
"hits": [
"_index": "key",
"_type": "_doc",
"_id": "2",
"_score": 0.6931471,
"_source": {
"name": {
"keyword": "Jagannathan Rajagopalan"


Username search in Elasticsearch

I want to implement a simple username search within Elasticsearch. I don't want weighted username searches yet, so I would expect it wouldn't be to hard to find resources on how do this. But in the end, I came across NGrams and lot of outdated Elasticsearch tutorials and I completely lost track on the best practice on how to do this.
This is now my setup, but it is really bad because it matches so much unrelated usernames:
"settings": {
"index" : {
"max_ngram_diff": "11"
"analysis": {
"analyzer": {
"username_analyzer": {
"tokenizer": "username_tokenizer",
"filter": [
"tokenizer": {
"username_tokenizer": {
"type": "ngram",
"min_gram": "1",
"max_gram": "12"
"mappings": {
"properties": {
"_all" : { "enabled" : false },
"username": {
"type": "text",
"analyzer": "username_analyzer"
I am using the newest Elasticsearch and I just want to query similar/exact usernames. I have a user db and users should be able to search for eachother, nothing to fancy.
If you want to search for exact usernames, then you can use the term query
Term query returns documents that contain an exact term in a provided field. If you have not defined any explicit index mapping, then you need to add .keyword to the field. This uses the keyword analyzer instead of the standard analyzer.
There is no need to use an n-gram tokenizer if you want to search for the exact term.
Adding a working example with index data, index mapping, search query, and search result
Index Mapping:
"mappings": {
"properties": {
"username": {
"type": "text",
"fields": {
"keyword": {
"type": "keyword"
Index Data:
"username": "Jack"
"username": "John"
Search Query:
"query": {
"term": {
"username.keyword": "Jack"
Search Result:
"hits": [
"_index": "68844541",
"_type": "_doc",
"_id": "1",
"_score": 0.2876821,
"_source": {
"username": "Jack"
Edit 1:
To match for similar terms, you can use the fuzziness parameter along with the match query
"query": {
"match": {
"username": {
"query": "someting",
Search Result will be
"hits": [
"_index": "68844541",
"_type": "_doc",
"_id": "3",
"_score": 0.6065038,
"_source": {
"username": "something"

what types are best for elasticsearch "KEYWORDS"(like hashtags) field?

i want to make Elasticsearch index for something KEYWORDS, like.. hashtag.
and make synonym filter for KEYWORDs.
i think two ways indexing keyword, first is make keyword type.
"settings": {
"keywordField": {
"type": "keyword"
if make a index with League of Legends
maybe this.
"keywordField": ["leagueoflegends", "league", "legends", "lol" /* synonym */]
or text type:
"settings": {
"keywordField": {
"type": "text",
"analyzer": "lowercase_and_whitespace_and_synonym_analyzer"
maybe this.
"keywordField": ["league of legends"](synonym: lol => leagueoflegends)
if use _analyzer api for this field, expects "leagueoflegends", "league", "legends"
search query: 'lol', 'league of legends', 'League of Legends' have to match this field.
which practice is best?
Adding a working example with index data, mapping, search query, and search result. In the below example, I have taken two synonyms lol and leagueoflegends
Index Mapping:
"settings": {
"index": {
"analysis": {
"filter": {
"synonym_filter": {
"type": "synonym",
"synonyms": [
"leagueoflegends, lol"
"analyzer": {
"synonym_analyzer": {
"filter": [
"tokenizer": "standard"
"mappings": {
"properties": {
"keywordField": {
"type": "text"
Index Data:
"keywordField": ["leagueoflegends", "league", "legends"]
Search Query:
"query": {
"match": {
"keywordField": {
"query": "lol",
"analyzer": "synonym_analyzer"
Search Result:
"hits": [
"_index": "66872989",
"_type": "_doc",
"_id": "1",
"_score": 0.19363807,
"_source": {
"keywordField": [

ElasticSearch - Search if this term include in the list index or not?

It was mapped like this:
"parent_ids": {
"type": "text",
"fields": {
"keyword": {
"type": "keyword",
"ignore_above": 256
The actual data looks like this:
parent_ids = ["asdf", "aeraeg", "A123"]
I want to filter all products with parent_ids "A123":
"match": {
"parent_ids": "{{parent_ids}}"
But not working
You can use terms query that returns documents that contain one
or more exact terms in a provided field.
Search Query:
"query": {
"terms": {
"parent_ids.keyword": [ "A123"]
Search Result:
"hits": [
"_index": "64745756",
"_type": "_doc",
"_id": "1",
"_score": 1.0,
"_source": {
"parent_ids": [
Search Query using bool query:
"query": {
"bool": {
"filter": {
"match": {
"parent_ids": "A123"
If you need to format your query to support a JSON array in parameters, you'll need to format your query like this:
"terms": {
"parent_ids.keyword": {{#toJson}}parent_ids{{/toJson}}
Note that the match query doesn't support an array of values, only the terms query does.

search array of strings by partially match in elasticsearch

I got fields like that:
names: ["Red:123", "Blue:45", "Green:56"]
it's mapping is
"names": {
"type": "keyword"
how could I search like this
"query": {
"match": {
"names": "red"
to get all the documents where red is in element of names array?
Now it works only with
"query": {
"match": {
"names": "red:123"
You can add multi fields OR just change the type to text, to achieve your required result
Index Mapping using multi fields
"mappings": {
"properties": {
"names": {
"type": "text",
"fields": {
"raw": {
"type": "keyword"
Adding a working example with index data, mapping, search query, and search result
Index Mapping:
Index Data:
"names": [
Search Query:
"query": {
"match": {
"names": "red"
Search Result:
"hits": [
"_index": "64665127",
"_type": "_doc",
"_id": "1",
"_score": 0.2876821,
"_source": {
"names": [

How Elasticsearch relevance score gets calculated?

I am using multi_match with phrase_prefix for full text search in Elasticsearch 5.5. ES query looks like
query: {
bool: {
must: {
multi_match: {
query: "butt",
type: "phrase_prefix",
fields: ["", "item.keywords"],
max_expansions: 10
I am getting following response
"_index": "items_index",
"_type": "item",
"_id": "2",
"_score": 0.61426216,
"_source": {
"item": {
"keywords": "amul butter, milk, butter milk, flavoured",
"name": "Flavoured Butter"
"_index": "items_index",
"_type": "item",
"_id": "1",
"_score": 0.39063013,
"_source": {
"item": {
"keywords": "amul butter, milk, butter milk",
"name": "Butter Milk"
Mappings is as follows(I am using default mappings)
"items_index" : {
"mappings" : {
"parent_doc": {
"properties": {
"item" : {
"properties" : {
"keywords" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
"name" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
How item with "name": "Flavoured Butter" getting higher score of 0.61426216 against the document with "name": "Butter Milk" and score 0.39063013?
I tried applying boost to "" and removing "item.keywords" form search fields getting same results.
How scores in Elasticsearch works? Are above results correct in terms of relavance?
The scoring for phrase_prefix is similar to that of best_fields, meaning that score of a document is the score obtained from the best_field, which here is item.keywords.
So, isn't adding to score
Refer: multi-match-types
You can use 2 multi_match queries to combine the score from keywords and name.
"query": {
"bool": {
"must": [{
"multi_match": {
"query": "butt",
"type": "phrase_prefix",
"fields": [
"max_expansions": 10
"multi_match": {
"query": "butt",
"type": "phrase_prefix",
"fields": [
"max_expansions": 10
