Elastic search AND operator not woking - elasticsearch

If I run below query having AND it returns nothing:
TF1:"rohan sharma" AND TF3:"gaurav"
but if I use OR its returns result:
TF1:"rohan sharma" OR TF3:"gaurav"
both data is available
Here is mapping:
"TEST": {
"mappings": {
"indextestField1": {
"_ttl": {
"enabled": true
"properties": {
"TF1": {
"type": "string"
"TF2": {
"type": "string"
Here is my java code
SearchResponse response = client.prepareSearch("TEST")
.setQuery(QueryBuilders.queryString("TF1:\"rohan sharma\" AND TF2:\"milind bagal\""))

Your mapping must be wrong, add your analyzer to the fields TF1 and TF3.
"TEST": {
"mappings": {
"properties": {
"TF1": {
"type": "string",
"index": "not_analyzed"
"TF2": {
"type": "string",
"index": "not_analyzed"
hack on elasticsearch (3 hrs)
Scripts example

About the command you provided, you double-quoted the "rohan sharma", which means the positions of the two words must be located in order.
And I guess the document you want to find, these two words "rohan sharma" are not next to each other, which means this condition failed and it results in not-match using the AND operator.
So if you don't need the positional criteria, don't use double-quotes and just use:
TF1:rohan AND TF1:sharma AND TF3:gaurav
It's just my assumption. For more detailed answer, you might need to provide the document you want to find using the command you provides.


Kibana - missing text highlighting for multi-field mapping

I am experimenting with ECS - Elastic Common Schema.
We need to highlight text search for the field error.stack_trace . This field is a multi-field mapped defined here
I just did a simple test running Elasticsearch and Kibana 7.17.4 one field defined as multi-field and one with single field.
PUT simple-index-01
"mappings": {
"properties": {
"stack_trace01": { "type": "text" },
"stack_trace02": {
"fields": {
"text": {
"type": "text"
"type": "wildcard"
POST simple-index-01/_doc
"#timestamp" : "2022-06-07T08:21:05.000Z",
"stack_trace01": "java.lang.NullPointerException: null",
"stack_trace02": "java.lang.NullPointerException: null"
Is it a Kibana expected behavior not to highlight multi-fields?
wildcard type will be not available to search using full text query as mentioned in documentaion (it is part of keyword type family):
The wildcard field type is a specialized keyword field for
unstructured machine-generated content you plan to search using
grep-like wildcard and regexp queries.
So when you try below query it will not return result and this is the reason why it is not highlghting your stack_trace02 field in discover.
POST simple-index-01/_search
"query": {
"match": {
"stack_trace02": "null"
But below query will give result:
"query": {
"wildcard": {
"stack_trace02": {
"value": "*null*"
You can create index mapping something like below and your parent type field should text type:
PUT simple-index-01
"mappings": {
"properties": {
"stack_trace01": {
"type": "text"
"stack_trace02": {
"fields": {
"text": {
"type": "wildcard"
"type": "text"
You can now use stack_trace02.wildcard when you want to search wildcard type of query.
There is already open issue on similar behaviour but it is not for wildcard type.

Only getting results when elasticsearch is case sensitive

I currently have a problem with my multi match search in ES.
Its simple like that: If I'm searching for the City "Sachsen", I'm getting results.
If I'm searching for "sachsen" (lowercase), I'm getting no results.
how to avoid this?
QUERY with no results
"match" : {
"City" : {
"query" : "sachsen"
My analyzer is analyzer_keyword. Should I have anything add ?
City: {
type: "string",
analyzer: "analyzer_keyword"
Your analyzer_keyword analyzer is most probably of type keyword which means you can only perform exact matches on it.
It's standard practice to apply multiple "variants" of a field, one of which is going to match lowercase, possibly ascii-tokenized characters (think München -> munchen) and one which will not be tokenized in any way (this is what you have in your analyzer_keyword).
Since you intend to search the lowercase version of Sachsen, your mapping could look something like
PUT sachsen
"mappings": {
"properties": {
"City": {
"type": "keyword", <----
"fields": {
"standard": {
"type": "text",
"analyzer": "standard" <----
After indexing a doc
POST sachsen/_doc
"City": "Sachsen"
The following will work for exact matches:
GET sachsen/_search
"query": {
"match": {
"City": "Sachsen"
and this for lowercase
GET sachsen/_search
"query": {
"match": {
"City.standard": "sachsen"
Note that I'm using the default, standard analyzer here but you can choose any one you deem appropriate.

What's the right way to perform a keyword search?

If I want to perform a keyword search using a TermQuery, what's the proper way to do this? Am I supposed to prepend ".keyword" to my field name? I would think there is a more first-class citizen way of doing it! 🤷‍♂️
QueryBuilders.termQuery(SOME_FIELD_NAME + ".keyword", someValue)
It all boils down to your mapping. If your field is mapped as a 'straightforward' keyword like so
"mappings": {
"properties": {
"some_field": {
"type": "keyword"
you won't need to append .keyword -- you'd do just
QueryBuilders.termQuery(SOME_FIELD_NAME, someValue)
It's good practice, though, not to restrict yourself to only keywords, esp. if you'll be doing partial matches, expansions, autocomplete etc down the line.
A typical text field mapping would look like
PUT kwds
"mappings": {
"properties": {
"some_field": {
"type": "text",
"fields": {
"keyword": { <---
"type": "keyword"
"analyzed": { <---
"type": "text",
"analyzer": "simple"
"...": { <---
This means you'd be able to access differently-indexed "versions" (fields) of the same "property" (field). The naming is rather confusing but you get the gist.
Long story short, this is where the .keyword convention stems from. You don't need it if your field is already mapped as a keyword.

Elasticsearch Mapping - Rename existing field

Is there anyway I can rename an element in an existing elasticsearch mapping without having to add a new element ?
If so whats the best way to do it in order to avoid breaking the existing mapping?
e.g. from fieldCamelcase to fieldCamelCase
"myType": {
"properties": {
"timestamp": {
"type": "date",
"format": "date_optional_time"
"fieldCamelcase": {
"type": "string",
"index": "not_analyzed"
"field_test": {
"type": "double"
You could do this by creating an Ingest pipeline, that contains a Rename Processor in combination with the Reindex API.
PUT _ingest/pipeline/my_rename_pipeline
"description" : "describe pipeline",
"processors" : [
"rename": {
"field": "fieldCamelcase",
"target_field": "fieldCamelCase"
POST _reindex
"source": {
"index": "source"
"dest": {
"index": "dest",
"pipeline": "my_rename_pipeline"
Note that you need to be running Elasticsearch 5.x in order to use ingest. If you're running < 5.x then you'll have to go with what #Val mentioned in his comment :)
Updating field name in ES (version>5, missing has been removed) using _update_by_query API:
POST http://localhost:9200/INDEX_NAME/_update_by_query
"query": {
"bool": {
"must_not": {
"exists": {
"field": "NEW_FIELD_NAME"
"script" : {
"inline": "ctx._source.NEW_FIELD_NAME = ctx._source.OLD_FIELD_NAME; ctx._source.remove(\"OLD_FIELD_NAME\");"
First of all, you must understand how elasticsearch and lucene store data, by immutable segments (you can read about easily on Internet).
So, any solution will remove/create documents and change mapping or create a new index so a new mapping as well.
The easiest way is to use the update by query API: https://www.elastic.co/guide/en/elasticsearch/reference/2.4/docs-update-by-query.html
POST /XXXX/_update_by_query
"query": {
"missing": {
"field": "fieldCamelCase"
"script" : {
"inline": "ctx._source.fieldCamelCase = ctx._source.fieldCamelcase; ctx._source.remove(\"fieldCamelcase\");"
Starting with ES 6.4 you can use "Field Aliases", which allow the functionality you're looking for with close to 0 work or resources.
Do note that aliases can only be used for searching - not for indexing new documents.

ElasticSearch - issue with sub term aggregation with array fields

I have the two following documents:
"title":"The Avengers",
"name":"Robert Downey Jr.",
"name":"Chris Evans",
"title":"The Judge",
"name":"Robert Downey Jr.",
"name":"Robert Duvall",
I would like to perform aggregations, based on two fields : casting.name and casting.category.
I tried with a TermsAggregation based on casting.name field, with a subaggregation, which is another TermsAggregation based on the casting.category field.
The problem is that for the "Chris Evans" entry, ElasticSearch set buckets for ALL categories (Actor, Producer) whereas it should set only 1 bucket (Actor).
It seems that there is a cartesian product between all casting.category occurences and all casting.name occurences.
It behaves like this with array fields (casting), whereas I don't have the problem with simple fields (as title, or year).
I also tried to use nested aggregations, but maybe not properly, and ElasticSearch throws an error telling that casting.category is not a nested field.
Any idea here?
Elasticsearch will flatten the nested objects, so internally you will get:
"title":"The Judge",
"casting.name": ["Robert Downey Jr.","Robert Duvall"],
"casting.category": ["Producer", "Actor"]
if you want to keep the relationship you'll need to use either nested objects or a parent child relationship
To do a nested mapping you'd need to do something like this:
"mappings": {
"movies": {
"properties": {
"title" : { "type": "string" },
"year" : { "type": "integer" },
"casting": {
"type": "nested",
"properties": {
"name": { "type": "string" },
"category": { "type": "string" }
