Using named queries (matched_queries) for nested types in Elasticsearch? - elasticsearch

Using named queries, I can get a list of the matched_queries for boolean expressions such as:
(query1) AND (query2 OR query3 OR true)
Here is an example of using named queries to match on top-level document fields:
PUT /test
PUT /test/_mapping/_doc
"properties": {
"name": {
"type": "text"
"type": {
"type": "text"
"TAGS": {
"type": "nested"
POST /test/_doc
"name" : "doc1",
"type": "msword",
"TAGS" : [
"ID" : "tag1",
"ID" : "tag2",
"ID" : "tag3",
# (query1) AND (query2 or query3 or true)
GET /test/_search
"query": {
"bool": {
"must": [
"match": {
"name": {
"query": "doc1",
"_name": "query1"
"should": [
"match": {
"type": {
"query": "msword",
"_name": "query2"
"exists": {
"field": "type",
"_name": "query3"
The above query correctly returns all three matched_queries in the response:
"took" : 1,
"timed_out" : false,
"_shards" : {
"total" : 5,
"successful" : 5,
"skipped" : 0,
"failed" : 0
"hits" : {
"total" : 1,
"max_score" : 1.5753641,
"hits" : [
"_index" : "test",
"_type" : "_doc",
"_id" : "TKNJ9G4BbvPS27u-ZYux",
"_score" : 1.5753641,
"_source" : {
"name" : "doc1",
"type" : "msword",
"TAGS" : [
"ID" : "ds1",
"ID" : "wb1",
"matched_queries" : [
However, I'm trying to run a similar search:
(query1) AND (query2 OR query3 OR true)
only this time on the nested TAGS object rather than top-level document fields.
I've tried the following query, but the problem is I need to supply the inner_hits object for nested objects in order to get the matched_queries in the response, and I can only add it to one of the three queries.
GET /test/_search
"query": {
"bool": {
"must": {
"nested": {
"path": "TAGS",
"query": {
"match": {
"TAGS.ID": {
"query": "tag1",
"_name": "tag1-query"
// "inner_hits" : {}
"should": [
"nested": {
"path": "TAGS",
"query": {
"match": {
"TAGS.ID": {
"query": "tag2",
"_name": "tag2-query"
// "inner_hits" : {}
"nested": {
"path": "TAGS",
"query": {
"match": {
"TAGS.ID": {
"query": "tag3",
"_name": "tag3-query"
// "inner_hits" : {}
Elasticsearch will complain if I add more than one 'inner_hits'. I've commented out the places above where I can add it, but each of these will only return the single matched query.
I want my response to this query to return:
"matched_queries" : [
Any help is much appreciated, thanks!

A colleague helpfully provided a solution to this; move the _named parameter to directly under each nested section:
GET /test/_search
"query": {
"bool": {
"must": {
"nested": {
"_name": "tag1-query",
"path": "TAGS",
"query": {
"match": {
"TAGS.ID": {
"query": "tag1"
"should": [
"nested": {
"_name": "tag2-query",
"path": "TAGS",
"query": {
"match": {
"TAGS.ID": {
"query": "tag2"
"nested": {
"_name": "tag3-query",
"path": "TAGS",
"query": {
"match": {
"TAGS.ID": {
"query": "tag3"
This correctly returns all three tags now in the matched_queries response:
"took" : 1,
"timed_out" : false,
"_shards" : {
"total" : 5,
"successful" : 5,
"skipped" : 0,
"failed" : 0
"hits" : {
"total" : 1,
"max_score" : 2.9424875,
"hits" : [
"_index" : "test",
"_type" : "_doc",
"_id" : "TaNy9G4BbvPS27u--oto",
"_score" : 2.9424875,
"_source" : {
"name" : "doc1",
"type" : "msword",
"TAGS" : [
"ID" : "ds1",
"ID" : "wb1",
"ID" : "wb2",
"matched_queries" : [


elasticsearch filter nested object

I have an index with a nested object containing two attributes namely scopeId and categoryName. Following is the mappings part of the index
"mappedCategories" : {
"type" : "nested",
"properties": {
"scopeId": {"type":"long"},
"categoryName": {"type":"text",
"analyzer" : "productSearchAnalyzer",
"search_analyzer" : "productSearchQueryAnalyzer"}
A sample document containing the nested mappedCategories object is as follows:
POST productsearchna_2/_doc/1
"categoryName" : "Operating Systems",
"contexts" : [
"countryCode" : "US",
"id" : "10076327-1",
"languageCode" : "EN",
"localeId" : 1,
"mfgpartno" : "test123",
"manufacturerName" : "Hewlett Packard Enterprise",
"productDescription" : "HPE Microsoft Windows 2000 Datacenter Server - Complete Product - Complete Product - 1 Server - Standard",
"productId" : 10076327,
"skus" : [
{"sku": "43233004",
"skuName": "UNSPSC"},
{"sku": "43233049",
"skuName": "SP Richards"},
{"sku": "43234949",
"skuName": "Ingram Micro"}
"mappedCategories" : [
{"scopeId": 3228552,
"categoryName": "Laminate Bookcases"},
{"scopeId": 3228553,
"categoryName": "Bookcases"},
{"scopeId": 3228554,
"categoryName": "Laptop"}
I want to filter categoryName "lap" on scopeId: 3228553 i.e. my query should return 0 hits since Laptop is mapped to scopeId 3228554. But my following query is returning 1 hit with scopeId : 3228554
POST productsearchna_2/_search
"query": {
"bool": {
"must": [
"nested": {
"path": "mappedCategories",
"query": {
"term": {
"mappedCategories.categoryName": "lap"
"inner_hits": {}
"filter": [
"nested": {
"path": "mappedCategories",
"query": {
"term": {
"mappedCategories.scopeId": {
"value": 3228552
"_source": ["mappedCategories.categoryName", "productId"]
Following is part of the result of the query:
"inner_hits" : {
"mappedCategories" : {
"hits" : {
"total" : {
"value" : 1,
"relation" : "eq"
"max_score" : 1.5586993,
"hits" : [
"_index" : "productsearchna_2",
"_type" : "_doc",
"_id" : "1",
"_nested" : {
"field" : "mappedCategories",
"offset" : 2
"_score" : 1.5586993,
"_source" : {
"scopeId" : 3228554,
"categoryName" : "Laptop"
I want my query to return zero hits, and in case I search for "book" with scopeId: 3228552, I want my query to return 2 hits, 1 for Bookcases and another for Laminate Bookcases categoryNames. Please help.
This query solves part of the problem but when searching for book" with scopeId: 3228552 it will only get 1 result.
GET idx_test/_search?filter_path=hits.hits.inner_hits
"query": {
"nested": {
"path": "mappedCategories",
"query": {
"bool": {
"filter": [
"term": {
"mappedCategories.scopeId": {
"value": 3228553
"must": [
"match": {
"mappedCategories.categoryName": "laptop"
"inner_hits": {}

Elasticsearch Nested query not working as expected

I am bit new to elastic search. I am trying a nested query to get the result soem thing like below sql in query DSL..means I wanna restrict the search to driver last name as well as the vehicle make as below use case.
select driver.last_name,driver.vehicle.make,driver.vehicle.model from drivers
where driver.last_name='Hudson' and driver.vehicle.make"="Miller-Mete;
But this doesn't work in elastic search sql as well as Query DSL...
--> can we do the query like this in let me clarify..
if department has List[employees] in Elasticsearch denoarmalized data..
and i want to restrict the query to department_name and emp_position..
--> is this use case even possible in elastic search?
select department_name,emp_name,emp_salary,emp_position
where emp_position="Intern" and"devlopment"
--> Below are mappings and search Query DSL...
PUT /drivers
"mappings": {
"properties": {
"driver": {
"type": "nested",
"properties": {
"last_name": {
"type": "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
"vehicle": {
"type": "nested",
"properties": {
"make": {
"type": "text"
"model": {
"type": "text"
GET /drivers/_mapping
"drivers" : {
"mappings" : {
"properties" : {
"driver" : {
"type" : "nested",
"properties" : {
"last_name" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
"vehicle" : {
"type" : "nested",
"properties" : {
"make" : {
"type" : "text"
"model" : {
"type" : "text"
--> inserting documents..
PUT /drivers/_doc/1
"driver" : {
"last_name" : "McQueen",
"vehicle" : [
"make" : "Powell Motors",
"model" : "Canyonero"
"make" : "Miller-Meteor",
"model" : "Ecto-1"
PUT /drivers/_doc/2
"driver" : {
"last_name" : "Hudson",
"vehicle" : [
"make" : "Mifune",
"model" : "Mach Five"
"make" : "Miller-Meteor",
"model" : "Ecto-1"
--> Below is the search query dsl..this gives 0 results. Even i replace
"term": {
"driver.last_name.keyword": "McQueen"
with "match" or "filter" still gives 0 results...
GET /drivers/_search
"query": {
"nested": {
"path": "driver",
"query": {
"nested": {
"path": "driver.vehicle",
"query": {
"bool": {
"must": [
{ "match": { "driver.vehicle.make": "Powell Motors" } },
{ "match": { "driver.vehicle.model": "Canyonero" } },
"term": {
"driver.last_name.keyword": "McQueen"
==> below Query DSL gives 2 results...
GET /drivers/_search
"query": {
"nested": {
"path": "driver",
"query": {
"nested": {
"path": "driver.vehicle",
"query": {
"bool": {
"must": [
{ "match": { "driver.vehicle.make": "Miller-Meteor" } }
"took" : 1,
"timed_out" : false,
"_shards" : {
"total" : 1,
"successful" : 1,
"skipped" : 0,
"failed" : 0
"hits" : {
"total" : {
"value" : 2,
"relation" : "eq"
"max_score" : 1.3097506,
"hits" : [
"_index" : "drivers",
"_type" : "_doc",
"_id" : "1",
"_score" : 1.3097506,
"_source" : {
"driver" : {
"last_name" : "McQueen",
"vehicle" : [
"make" : "Powell Motors",
"model" : "Canyonero"
"make" : "Miller-Meteor",
"model" : "Ecto-1"
"_index" : "drivers",
"_type" : "_doc",
"_id" : "2",
"_score" : 1.3097506,
"_source" : {
"driver" : {
"last_name" : "Hudson",
"vehicle" : [
"make" : "Mifune",
"model" : "Mach Five"
"make" : "Miller-Meteor",
"model" : "Ecto-1"
==> this gives "parsing_exception",
"reason" : "[bool] malformed query, expected [END_OBJECT] but found [FIELD_NAME]",
==> even replacing 1st query bool to "match" also gives this below
GET /drivers/_search
"query": {
"nested": {
"path": "driver",
"query": {
"bool": {
"must": [
{"match": {
"driver.last_name.keyword": "Hudson"
"nested": {
"path": "driver.vehicle",
"query": {
"bool": {
"must": [
"match": {
"driver.vehicle.make": "Miller-Meteor"

Documents repeating in the query of elasticsearch

I'm new to elasticsearch. I need to build the query dynamically, where for each field name the the corresponding file is fetched
I have the below query, can anyone say if its the right approach? Also with this query, the documents are just repeating for one particular file name
Please let me know how to go about it
GET index_name/_search
"query": {
"bool": {
"should": [
"bool": {
"must": [
"match_phrase": {
"field_name": "program"
"match_phrase": {
"field_value": "aaa-123"
"bool": {
"must": [
"match_phrase": {
"field_name": "species"
"match_phrase": {
"field_value": "mouse"
"bool": {
"must": [
"match_phrase": {
"field_name": "model name"
"match_phrase": {
"field_value": "b45"
},"aggs": {
"2": {
"terms": {
"field": "myfile_file_name.keyword",
"size": 1000,
"order": {
"_key": "asc"
"aggs": {
"3": {
"terms": {
"field": "field_name.keyword",
"size": 1000,
"order": {
"_key": "asc"
mapping and Output
"_index" : "test",
"_type" : "test_data",
"_id" : "123",
"_score" : 1.0,
"_source" : {
"document_id" : 123,
"m_id" : 1,
"source" : "ADDD",
"type" : "M",
"name" : "Animal",
"value" : "None",
"test_type" : "Test123",
"file_name" : "",
"description" : "testing",
"program" : ["hello"],
"species" : ["mouse"],
"study" : ["Study1"],
"create_date" : "2020-08-20 11:51:21.152",
"update_date" : "2020-08-20 11:51:21.152",
"source_name" : "Anim",
"auth" : ["na"],
"treatment" : ["TR001", "TR002", "TR004"],
"timepoint" : ["72", "48"],
"findings_reports" : "na",
"model" : ["None",],
"additional" : "{'view': '', 'load': []}",
"data" : "Pre"

Combining nested query get illegal_state_exception failed to find nested object under path

I'm creating a query on Elasticsearch, for find documents through all indices.
I need to combine should, must and nested query on Elasticsearch, i get the right result but i get an error inside the result.
This is the query I'm using
GET _all/_search
"query": {
"bool": {
"minimum_should_match": 1,
"should": [
{ "term": { "trimmed_final_url": "" } }
"must": [
"nested": {
"path": "entities",
"query": {
"bool": {
"must": [
{ "term": { "": "138511" } }
"term": {
"language": { "value": "it" }
And this is the result
"_shards" : {
"total" : 38,
"successful" : 14,
"skipped" : 0,
"failed" : 24,
"failures" : [
"shard" : 0,
"index" : ".kibana_1",
"node" : "7twsq85TSK60LkY0UiuWzA",
"reason" : {
"type" : "query_shard_exception",
"reason" : """
failed to create query: {
"index_uuid" : "HoHi97QFSaSCp09iSKY1DQ",
"index" : ".reporting-2019.06.02",
"caused_by" : {
"type" : "illegal_state_exception",
"reason" : "[nested] failed to find nested object under path [entities]"
"hits" : {
"total" : {
"value" : 50,
"relation" : "eq"
"max_score" : 16.90015,
"hits" : [
"_index" : "i_201906_v1",
"_type" : "_doc",
"_id" : "MugcbmsBAzi8a0oJt96Q",
"_score" : 16.90015,
"_source" : {
"language" : "it",
"entities" : [
"id" : 101580,
"id" : 156822,
I didn't write some fields because the code is too long
I am new to StackOverFlow (made this account to answer this question :D) so if this answer is out of line bear with me. I have been dabbling in nested fields in Elasticsearch recently so I have some ideas as to how this error could be appearing.
Have you defined a mapping for your document type? I don't believe Elasticsearch will recognize the field as nested if you do not tell it to do so in the mapping:
"mappings": {
"properties": {
"entities": {"type": "nested"}
You may have to specify this mapping for each index and document type. Not sure if there is a way to do that all with one request.
I also noticed you have a "should" clause with minimum matches set to 1. I believe this is exactly the same as a "must" clause so I am not sure what purpose this achieves (correct me if I'm wrong). If your mapping is specified, the query should look something like this:
GET /_all/_search
"query": {
"bool": {
"must": [
"nested": {
"path": "entities",
"query": {
"term": {
"": {
"value": "138511"
"term": {
"language": {
"value": "it"
"term": {
"trimmed_final_url": {
"value": ""

elasticsearch searching array field inside nested type

i am trying to filter my result using nested filter but i am getting incorrect result
here is my mapping info
"stock" : {
"mappings" : {
"clip" : {
"properties" : {
"description" : {
"type" : "string"
"keywords" : {
"type" : "nested",
"properties" : {
"category" : {
"type" : "string"
"tags" : {
"type" : "string",
"index_name" : "tag"
"tags" : {
"type" : "string",
"index_name" : "tag"
"title" : {
"type" : "string"
clip document data
"_index" : "stock",
"_type" : "clip",
"_id" : "AUnsTOBBpafrKleQN284",
"_score" : 1.0,
"title": "journey to forest",
"description": "this clip contain information about the animals",
"tags": ["birls", "wild", "animals", "roar", "forest"],
"keywords": [
"tags": ["spring","summer","autumn"],
"category": "Weather"
"tags": ["Cloudy","Stormy"],
"category": "Season"
"tags": ["Exterior","Interior"],
"category": "Setting"
i am trying to filter tags inside nested field 'keywords'
here is my query
"query": {
"filtered": {
"query": {
"match_all": {}
"filter": {
"nested": {
"path": "keywords",
"filter": {
"bool": {
"must": [
"terms": { "tags": ["autumn", "summer"] }
i am getting no result why ?
what's wrong with my query or schema please help
The above query is syntactically incorrect . You need to provide the full path to tags from root keywords in the term query i.e.keywords.tags
"query": {
"filtered": {
"query": {
"match_all": {}
"filter": {
"nested": {
"path": "keywords",
"filter": {
"bool": {
"must": [
"terms": { "keywords.tags": ["autumn", "summer"] }
