I'm trying to use a filter on a filtered query, this is what I'm trying with Sense:
GET myindex/catalog/_search
"query": {
"filtered": {
"query": {
"query_string": {
"analyze_wildcard": true,
"query": "test",
"fields": ["title^3.5", "contributions.authors.name^5", "publisher^2", "formats.productCode^0.5", "description^0.1"],
"use_dis_max": true
"filter": {
"term": {
"sku": "test-687"
This query hasn't any hit, but if I remove the filter property I get exactly the item with sku = test-687.
I cannot understand why the query with the filter doesn't give me the same result.
"myindex": {
"mappings": {
"catalog": {
"properties": {
"sku": {
"type": "string"
"title": {
"type": "string"
"updated_at": {
"type": "date",
"format": "strict_date_optional_time||epoch_millis"

the full query is:
GET myindex/catalog/_search {
"query": {
"filtered": {
"query": {
"query_string": {
"analyze_wildcard": true,
"query": "test",
"fields": ["title^3.5", "contributions.authors.name^5", "publisher^2", "formats.productCode^0.5", "description^0.1"],
"use_dis_max": true
"filter": {
"bool": {
"must": {
"query": {
"match": {
"sku": "test-687"
With default mapping the "Standard Analyser is used" :
An analyzer of type standard is built using the Standard Tokenizer with the Standard Token Filter, Lower Case Token Filter, and Stop Token Filter.
(More details her )
Term is case sensitive, match not


Search-as-you-type inside arrays

I am trying to implement a search-as-you-type query inside an array.
This is the structure of the documents:
"guid": "6f954d53-df57-47e3-ae9e-cb445bd566d3",
"name": "London",
"lang": "en"
"name": "Llundain",
"lang": "cy"
"name": "Lunnainn",
"lang": "gd"
and up to now this is what I came with:
"query": {
"multi_match": {
"fields": ["labels.name"],
"query": name,
"type": "phrase_prefix"
which works exactly as requested.
The problem is that I would like to search also by language.
What I tried is:
"query": {
"bool": {
"must": [
"multi_match": {
"fields": ["labels.name"],
"query": "london",
"type": "phrase_prefix"
"term": {
"labels.lang": "gd"
but these queries act on separate values of the array.
So, for example, I would like to search only Welsh language (cy). That means that my query that contains the city name should match only values that have "cy" on the "lang" tag.
How do I write this kind of query?
Internally, ElasticSearch flattens nested JSON objects, so it can't correlate the lang and name of a specific element in the labels array. If you want this kind of correlation, you'll need to index your documents differently.
The usual way to do this is to use the nested data type with a matching nested query.
The query would end up looking something like this:
"query": {
"nested": {
"path": "labels",
"query": {
"bool": {
"must": [
"multi_match": {
"fields": ["labels.name"],
"query": "london",
"type": "phrase_prefix"
"term": {
"labels.lang": "gd"
But note that you'll need to also specify nested mappings for your labels, e.g.:
"properties": {
"labels": {
"type": "nested",
"properties": {
"name": {
"type": "text"
/* you might want to add other mapping-related configuration here */
"lang": {
"type": "keyword"
Other ways to do this include:
Indexing each label as a separate document, repeating the guid field
Using parent/child documents
You should use Nested datatype in mapping instead of Object datatype. For detail explanation refer this:
So, you should define mapping of your field something like this:
"properties": {
"labels": {
"type": "nested",
"properties": {
"name": {
"type": "text"
"lang": {
"type": "keyword"
After this you could query using Nested Query as:
"query": {
"nested": {
"path": "labels",
"query": {
"bool": {
"must": [
"multi_match": {
"fields": ["labels.name"],
"query": "london",
"type": "phrase_prefix"
"term": {
"labels.lang": "gd"

Term query on nested fields returns no result in Elasticsearch

I have a nested type field in my mapping. When I use Term search query on my nested field no result is returned from Elasticsearch whereas when I change Term to Match query, it works fine and Elasticsearch returns expected result
here is my mapping, imagine I have only one nested field in my type mapping
"homing.estatefiles": {
"mappings": {
"estatefile": {
"properties": {
"DynamicFields": {
"type": "nested",
"properties": {
"Name": {
"type": "text",
"fields": {
"keyword": {
"type": "keyword",
"ignore_above": 256
"ValueBool": {
"type": "boolean"
"ValueDateTime": {
"type": "date"
"ValueInt": {
"type": "long"
And here is my term query (which returns no result)
"from": 50,
"size": 50,
"query": {
"bool": {
"filter": [
"nested": {
"query": {
"bool": {
"must": [
"term": {
"term": {
"DynamicFields.ValueBool": {
"value": true
"path": "DynamicFields"
And here is my query which returns expected result (by changing Term query to Match query)
"from": 50,
"size": 50,
"query": {
"bool": {
"filter": [
"nested": {
"query": {
"bool": {
"must": [
"match": {
"term": {
"DynamicFields.ValueBool": {
"value": true
"path": "DynamicFields"
This is happening because the capital letters with the analyzer of elastic.
When you are using term the elastic is looking for the exact value you gave.
up until now it sounds good, but before it tries to match the term, the value you gave go through an analyzer of elastic which manipulate your value.
For example in your case it also turn the HasParking to hasparking.
And than it will try to match it and of course will fail. They have a great explanation in the documentation in the "Why doesn’t the term query match my document" section. This analyzer not being activated on the value when you query using match and this why you get your result.

Elasticsearch : search document with conditional filter

I have two documents in my index (same type) :
"creation_date": ...
"creation_date": ...
"creation_date": ...,
"creation_date": ...
Clients would like to perform a full text search. Okay no problem here
My problem :
In this full text search, sometimes user will search by phone_number. In this case there is a parameter like expired=true.
Example :
First client search request : "987654321" with expired absent or set to false
--> Result : Only first document
Second client search request : "987654321" with expired set to true
--> Result : The two documents
How can I achieve that ?
Here is my mapping :
"user": {
"_all": {
"auto_boost": true,
"omit_norms": true
"properties": {
"phone_numbers": {
"type": "nested",
"properties": {
"phone_number": {
"type": "string"
"creation_date": {
"type": "string",
"index": "no"
"contract_number": {
"type": "string"
"expired": {
"type": "boolean"
"type": "string"
"type": "string"
"type": "string"
Thanks !
I tried this query :
"query": {
"filtered": {
"query": {
"query_string": {
"query": "987654321",
"analyze_wildcard": "true"
"filter": {
"nested": {
"path": "phone_numbers",
"filter": {
"bool": {
"bool": {
"must": [
"term": {
"phone_number": "987654321"
"missing": {
"field": "expired"
"bool": {
"must_not": [
"term": {
"phone_number": "987654321"
But I get the two documents instead of get only the first one
You're very close. Try using a combination of must and should, where the must clause ensures the phone_number matches the search value, and the should clause ensures that either the expired field is missing or set to false. For example:
"query": {
"filtered": {
"query": {
"query_string": {
"query": "987654321",
"analyze_wildcard": "true"
"filter": {
"nested": {
"path": "phone_numbers",
"query": {
"filtered": {
"filter": {
"bool": {
"must": [
"term": {
"phone_number": "987654321"
"should": [
"missing": {
"field": "expired"
"term": {
"expired": false
I ran this query using your mapping and sample documents and it returned the one document for John Doe, as expected.

elasticsearch query_string filter syntax bug (version 1.7.x)

im looking for the bug in the following query, as it doesn't bring any results. i want it to act like terms filter, and look for exact values in the country / device fields
GET idx/type/_search
"query": {
"filtered": {
"filter": {
"and": {
"filters": [
"query": {
"query_string": {
"query": "country:\"united kingdom\" AND device:\"desktop\""
specifically, this works:
"query": {
"query_string": {
"query": "\"united kingdom\""
but this doesnt work:
"query": {
"query_string": {
"query": "country:\"united kingdom\""
"country": {
"type": "string",
"index": "not_analyzed",
"doc_values": true

exact match query in elasticsearch

I'm trying to run an exact match query in ES
in MYSQL my query would be:
SELECT * WHERE `content_state`='active' AND `author`='bob' AND `title` != 'Beer';
I looked at the ES docs here:
and came up with this:
"from" : '.$offset.', "size" : '.$limit.',
"filter": {
"and": [
"and": [
"term": {
"content_state": "active"
"term": {
"author": "bob"
"not": {
"filter": {
"term": {
"title": "Beer"
but my results are still coming back with the title = Beer, it doesn't seem to be excluding the titles that = Beer.
did I do something wrong?
I'm pretty new to ES
I figured it out, I used this instead...
"from" : '.$offset.', "size" : '.$limit.',
"query": {
"bool": {
"must": [
"query_string": {
"default_field": "content_state",
"query": "active"
"query_string": {
"default_field": "author",
"query": "bob"
"must_not": [
"query_string": {
"default_field": "title",
"query": "Beer"
Query String Query is a pretty good concept to handle various relationship between search criteria. Have a quick look into Query string query syntax to understand in detail about this concept
"query": {
"query_string": {
"query": "(content_state:active AND author:bob) AND NOT (title:Beer)"
Filters are supposed to work on exact values, if you had defined your mapping in a manner where title was a non-analyzed field, your previous attempt ( with filters) would have worked as well.
"mappings": {
"test": {
"_all": {
"enabled": false
"properties": {
"content_state": {
"type": "string"
"author": {
"type": "string"
"title": {
"type": "string",
"index": "not_analyzed"
