I'm trying to run a wildcard query on a nested type in ElasticSearch. I have records with the following structure:
"field_1": "value_1",
"nested_field_1": [
"field_type": "some_field_type",
"field_value": "some_value"
"field_type": "another_field_type",
"field_value": "another_value"
I want to be able to run wildcard query on the nested_field, either on field_value or on field_type.
I can query for an exact match with this syntax:
"query": {
"nested": {
"path": "nested_field_1",
"query": {
"bool": {
"must": [
"match": {
"nested_field_1.field_value": "another_value"
But replacing the match with wildcard doesn't yield any results.
Any help would be welcome.

So I just tried your example and it gives me the result and used elasticsearch official wildcard query doc.
Index Def
"mappings": {
"properties": {
"field_1": {
"type": "text"
"nested_field_1" :{
"type" : "nested",
"properties" : {
"field_type" :{
"type" : "text"
"field_value" :{
"type" : "integer" --> created as interfere field
Index doc
"field_1": "value_1",
"nested_field_1": [
"field_type": "some_field_type",
"field_value": 20
"field_type": "another_field_type",
"field_value": 40
Wildcard search query
"query": {
"nested": {
"path": "nested_field_1",
"query": {
"bool": {
"must": [
"wildcard": { --> note
"nested_field_1.field_type": {
"value": "another_field_type"
Search result
"nested_field_1": [
"field_type": "some_field_type",
"field_value": 20
"field_type": "another_field_type",
"field_value": 40


How do I get the size of a 'nested' type array through a Painless script in Elasticsearch version 6.7?

I am using Elasticsearch version 6.7. I have the following mapping:
"customers": {
"mappings": {
"customer": {
"properties": {
"name": {
"type": "keyword"
"permissions": {
"type": "nested",
"properties": {
"entityId": {
"type": "keyword"
"entityType": {
"type": "keyword"
"permission": {
"type": "keyword"
"permissionLevel": {
"type": "keyword"
"userId": {
"type": "keyword"
I want to run a query to that shows all customers who have > 0 permissions. I have tried the following:
"query": {
"bool": {
"filter": {
"script": {
"script": {
"lang": "painless",
"source": "params._source != null && params._source.permissions != null && params._source.permissions.size() > 0"
But this returns no hits because params._source is null as Painless does not have access to the _source document according to this Stackoverflow post. How can I write a Painless script that gives me all customers who have > 0 permissions?
Solution 1: Using Script with must query
POST <your_index_name>/_search
"query": {
"bool": {
"must": [
"script": {
"script": {
"lang": "painless",
"inline": """
ArrayList st = params._source.permissions;
if(st!=null && st.size()>0)
return true;
Solution 2: Using Exists Query on nested fields
You could simply make use of Exists query something like the below to get customers who have > 0 permissions.
POST <your_index_name>/_search
"query": {
"bool": {
"must": [
"nested": {
"path": "permissions",
"query": {
"bool": {
"should": [
"field": "permissions.permission"
"field": "permissions.entityId"
"field": "permissions.entityType"
"field": "permissions.permissionLevel"
Solution 3: Create definitive structure but add empty values to the fields
Another alternative would be to ensure all documents would have the fields.
Ensure that all the documents would have the permissions nested document
However for those who would not have the permissions, just set the field permissions.permission to 0
Construct a query that could help you get such documents accordingly
Below would be a sample document for a user who doesn't have permissions:
POST mycustomers/customer/1
"name": "john doe",
"permissions": [
"entityId" : "null",
"entityType": "null",
"permissionLevel": 0,
"permission": 0
The query in that case would be as simple as this:
POST <your_index_name>/_search
"query": {
"bool": {
"must": [
"nested": {
"path": "permissions",
"query": {
"range": {
"permissions.permission": {
"gte": 1
Hope this helps!

Score keyword terms query on nested fields in elastichsearch 6.3

I have a set of keywords (skills in my example) and I would like to retrieve documents which match most of them. The documents should be sorted by how many of the keywords they match. The field i am searching into (skills) is of nested type. The index has the following mapping:
"mappings": {
"profiles": {
"properties": {
"id": {
"type": "keyword"
"skills": {
"type": "nested",
"properties": {
"level": {
"type": "float"
"name": {
"type": "keyword"
I tried both a terms query on the keyword field like:
"query": {
"nested": {
"path": "skills",
"query": {
"terms": {
"skills.name": [
And a boolean query
"query": {
"nested": {
"path": "skills",
"query": {
"bool": {
"should": [
"terms": {
"skills.name": [
"terms": {
"skills.name": [
For both queries the maximum score of the returned documents is 1. Thus both return documents that have ANY of the skills, but do not sort them such those with both skills are on top. The issues seems to be that skills is a nested field.
The second query works if each element of should is a nested query.
"query": {
"bool": {
"should": [
"nested": {
"path": "skills",
"query": {
"terms": {
"skills.name": [
"nested": {
"path": "skills",
"query": {
"terms": {
"skills.name": [

elasticsearch boost query in feild having multiple value

I have some document in elasticsearch index. Here is the sample document
"feild2":"some string"
"feild2":"some string"
"feild2":"some string"
I want to query for feild1 having values "hi" and "hello" if both is present then that document should come first if any one is present then it should come after that.
for example:
result should be in order of DOC1, DOC3, DOC2. I tried with boost query. but it is retuning not in the order that I want. Here is the query that I am trying.
"query": {
"bool": {
"must": [
"match_phrase": {
"avail_status": true
"bool": {
"should": [
"constant_score": {
"filter": {
"terms": {
"feild1": [
"boost": 20
"constant_score": {
"filter": {
"terms": {
"feild1": [
"boost": 18
this is returning me first those document having "hi" and then those having "hello". Thanks in advance!
To add extra boost for documents with larger field1, you can put funtion_score script score.
"mappings": {
"document_type" : {
"properties": {
"field1" : {
"type": "text",
"fielddata": true
"field2" : {
"type": "text"
"field3" : {
"type": "text"
Index documents
POST custom_score_index1/document_type
"feild2":"some string",
POST custom_score_index1/document_type
"feild2":"some string",
POST custom_score_index1/document_type
"feild2":"some string",
Query with function score add extra _score for larger size for field1
POST custom_score_index1/document_type/_search
"query": {
"function_score": {
"query": {
"bool": {
"must": [{
"match_phrase": {
"avail_status": true
"bool": {
"should": [{
"constant_score": {
"filter": {
"terms": {
"feild1": [
"boost": 20
"constant_score": {
"filter": {
"terms": {
"feild1": [
"boost": 18
"functions": [{
"script_score": {
"script": {
"inline": "_score + 10000 * doc['field1'].length"
"score_mode": "sum",
"boost_mode": "sum"

Search on array elements in ElasticSearch

Im trying to search two or more values on array and get only those ones that match with all words (AND CLAUSE)
Some example:
{ "name" : "Chevrolet",
"value" : [ "gasolina", "alcool", "diesel"]
{ "name" : "Fiat",
"value" : [ "eletrica", "alcool"]
{ "name" : "Honda",
"value" : [ "diesel", "gasolina"]
My mapping
"mappings": {
"cars": {
"properties": {
"name": {
"type": "string"
"GasType": {
"type": "nested",
"properties": {
"value": {
"type": "string"
"query": {
"nested": {
"path": "GasType",
"query": {
"bool": {
"must": [
{ "match": {"GasType.value": "gasolina"}},
{ "match": {"GasType.value": "diesel"}}
My return is always empty and if i change de query i have got all those that contains "Gasolina" or "diesel"
I need those that has "Gasolina" AND "diesel"
Your test data doesn't match the mapping of the index. In your test data I don't see the nested field name GasType. In any case, the following works for me just fine:
PUT test
"mappings": {
"cars": {
"properties": {
"name": {
"type": "string"
"GasType": {
"type": "nested",
"properties": {
"value": {
"type": "string"
POST test/cars/_bulk
GET test/_search
"query": {
"nested": {
"path": "GasType",
"query": {
"bool": {
"must": [
"match": {
"GasType.value": "gasolina"
"match": {
"GasType.value": "diesel"

Elasticsearch : search document with conditional filter

I have two documents in my index (same type) :
"creation_date": ...
"creation_date": ...
"creation_date": ...,
"creation_date": ...
Clients would like to perform a full text search. Okay no problem here
My problem :
In this full text search, sometimes user will search by phone_number. In this case there is a parameter like expired=true.
Example :
First client search request : "987654321" with expired absent or set to false
--> Result : Only first document
Second client search request : "987654321" with expired set to true
--> Result : The two documents
How can I achieve that ?
Here is my mapping :
"user": {
"_all": {
"auto_boost": true,
"omit_norms": true
"properties": {
"phone_numbers": {
"type": "nested",
"properties": {
"phone_number": {
"type": "string"
"creation_date": {
"type": "string",
"index": "no"
"contract_number": {
"type": "string"
"expired": {
"type": "boolean"
"type": "string"
"type": "string"
"type": "string"
Thanks !
I tried this query :
"query": {
"filtered": {
"query": {
"query_string": {
"query": "987654321",
"analyze_wildcard": "true"
"filter": {
"nested": {
"path": "phone_numbers",
"filter": {
"bool": {
"bool": {
"must": [
"term": {
"phone_number": "987654321"
"missing": {
"field": "expired"
"bool": {
"must_not": [
"term": {
"phone_number": "987654321"
But I get the two documents instead of get only the first one
You're very close. Try using a combination of must and should, where the must clause ensures the phone_number matches the search value, and the should clause ensures that either the expired field is missing or set to false. For example:
"query": {
"filtered": {
"query": {
"query_string": {
"query": "987654321",
"analyze_wildcard": "true"
"filter": {
"nested": {
"path": "phone_numbers",
"query": {
"filtered": {
"filter": {
"bool": {
"must": [
"term": {
"phone_number": "987654321"
"should": [
"missing": {
"field": "expired"
"term": {
"expired": false
I ran this query using your mapping and sample documents and it returned the one document for John Doe, as expected.
