# Boolean matchQuery on a not\_analyzed field?

**URL:** <https://discuss.elastic.co/t/boolean-matchquery-on-a-not-analyzed-field/13805>\
**Category:** Elasticsearch\
**Created:** [September 30, 2013, 2:12pm UTC](https://discuss.elastic.co/t/boolean-matchquery-on-a-not-analyzed-field/13805 "2013-09-30T14:12:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_Sanwald\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_sanwald_2/32/881_2.png) [@Paul\_Sanwald\_2](https://discuss.elastic.co/u/Paul_Sanwald_2)\
**Post date:** [September 30, 2013, 2:12pm UTC](https://discuss.elastic.co/t/boolean-matchquery-on-a-not-analyzed-field/13805/1 "2013-09-30T14:12:24Z")

</div>

having a very strange problem and hoping the group can provide some  
enlightenment. I have a field, activeLabels, which is defined as a  
multi-field in my index, with analyzed and not\_analyzed subfields.

A boolean query I have is matching as I expect when I use the analyzed  
field, but when I switch to using the not\_analyzed field, I no longer get a  
match, although the string values match exactly. here's the sub-query:  
{  
"bool" : {  
"must" : {  
"bool" : {  
"should" : {  
"match" : {  
"activeLabels\_not\_analyzed" : {  
"query" : "test1",  
"type" : "boolean",  
"operator" : "OR"  
} } } } } } }

Am I missing something about the way not analyzed fields are used vs  
analyzed?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![brian\_yoder](https://avatars.discourse-cdn.com/v4/letter/b/f1d935/32.png) [@brian\_yoder](https://discuss.elastic.co/u/brian_yoder)\
**Post date:** [September 30, 2013, 3:32pm UTC](https://discuss.elastic.co/t/boolean-matchquery-on-a-not-analyzed-field/13805/2 "2013-09-30T15:32:25Z")

</div>

Maybe try:

"activeLabels\*.\*not\_analyzed"

```
        "activeLabels_not_analyzed" : {

```

> Am I missing something about the way not analyzed fields are used vs  
> analyzed?

In other words, the dot and not the underscore is the field name scoping  
"operator".

Hope this helps!

Brian

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Paul\_Sanwald\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_sanwald_2/32/881_2.png) [@Paul\_Sanwald\_2](https://discuss.elastic.co/u/Paul_Sanwald_2)\
**Post date:** [September 30, 2013, 4:50pm UTC](https://discuss.elastic.co/t/boolean-matchquery-on-a-not-analyzed-field/13805/3 "2013-09-30T16:50:01Z")

</div>

Hi Brian,  
the subfield is actually named with the underscore, although you are  
right, I should have included the prefix. Alas, I tried it again with

"match" : {  
"activeLabels.activeLabels\_not\_analyzed" : {  
"query" : "test1",  
"type" : "boolean",  
"operator" : "OR"  
}

and still no dice :(.

On Monday, September 30, 2013 11:32:25 AM UTC-4, InquiringMind wrote:

> Maybe try:
> 
> "activeLabels\*.\*not\_analyzed"
> 
> ```
> "activeLabels_not_analyzed" : {
> 
> ```
> 
> > Am I missing something about the way not analyzed fields are used vs  
> > analyzed?
> 
> In other words, the dot and not the underscore is the field name scoping  
> "operator".
> 
> Hope this helps!
> 
> Brian

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![brian\_yoder](https://avatars.discourse-cdn.com/v4/letter/b/f1d935/32.png) [@brian\_yoder](https://discuss.elastic.co/u/brian_yoder)\
**Post date:** [October 1, 2013, 3:31pm UTC](https://discuss.elastic.co/t/boolean-matchquery-on-a-not-analyzed-field/13805/4 "2013-10-01T15:31:46Z")

</div>

(Second attempt to post this: Chrome is garbage and lost the first attempt.)

Here are my settings and mappings:

{  
"settings" : {  
"index" : {  
"number\_of\_shards" : 1,  
"refresh\_interval" : "1s",  
"analysis" : {  
"char\_filter" : { },  
"filter" : {  
"english\_snowball\_filter" : {  
"type" : "snowball",  
"language" : "English"  
}  
},  
"analyzer" : {  
"english\_stemming\_analyzer" : {  
"type" : "custom",  
"tokenizer" : "standard",  
"filter" : [ "standard", "lowercase", "asciifolding",  
"english\_snowball\_filter" ]  
},  
"english\_standard\_analyzer" : {  
"type" : "custom",  
"tokenizer" : "standard",  
"filter" : ["standard", "lowercase", "asciifolding"]  
}  
}  
}  
}  
},  
"mappings" : {  
"ghost" : {  
"\_all" : {  
"enabled" : false  
},  
"\_ttl" : {  
"enabled" : true,  
"default" : "1.9m"  
},  
"properties" : {  
"cn" : {  
"type" : "string",  
"analyzer" : "english\_stemming\_analyzer"  
},  
"text" : {  
"type" : "multi\_field",  
"fields" : {  
"text" : {  
"type" : "string",  
"analyzer" : "english\_stemming\_analyzer",  
"position\_offset\_gap" : 4  
},  
"std" : {  
"type" : "string",  
"analyzer" : "english\_standard\_analyzer",  
"position\_offset\_gap" : 4  
},  
"na" : {  
"type" : "string",  
"index" : "not\_analyzed"  
}  
}  
}  
}  
},  
"elf" : {  
"\_all" : {  
"enabled" : false  
},  
"\_ttl" : {  
"enabled" : true  
},  
"properties" : {  
"cn" : {  
"type" : "string",  
"analyzer" : "english\_stemming\_analyzer"  
},  
"_text_" : {  
"type" : "multi\_field",  
"fields" : {  
"_text_" : {  
"type" : "string",  
"analyzer" : "english\_stemming\_analyzer",  
"position\_offset\_gap" : 4  
},  
"std" : {  
"type" : "string",  
"analyzer" : "english\_standard\_analyzer",  
"position\_offset\_gap" : 4  
},  
"_na_" : {  
"type" : "string",  
"index" : "not\_analyzed"  
}  
}  
}  
}  
}  
}  
}

Here is a query to the _text_ field:

{  
"bool" : {  
"must" : {  
"match" : {  
"_text_" : {  
"query" : "lives",  
"type" : "boolean"  
}  
}  
}  
}  
}

Here is a query to the _text.na_ field which is not\_analyzed:

{  
"bool" : {  
"must" : {  
"match" : {  
"_text.na_" : {  
"query" : "Lives forever",  
"type" : "boolean"  
}  
}  
}  
}  
}

And here are the two documents that are returned from each of the above  
queries:

On Monday, September 30, 2013 12:50:01 PM UTC-4, Paul Sanwald wrote:

> Hi Brian,  
> the subfield is actually named with the underscore, although you are  
> right, I should have included the prefix. Alas, I tried it again with
> 
> "match" : {  
> "activeLabels.activeLabels\_not\_analyzed" : {  
> "query" : "test1",  
> "type" : "boolean",  
> "operator" : "OR"  
> }
> 
> and still no dice :(.
> 
> On Monday, September 30, 2013 11:32:25 AM UTC-4, InquiringMind wrote:
> 
> > Maybe try:
> > 
> > "activeLabels\*.\*not\_analyzed"
> > 
> > ```
> > "activeLabels_not_analyzed" : {
> > 
> > ```
> > 
> > > Am I missing something about the way not analyzed fields are used vs  
> > > analyzed?
> > 
> > In other words, the dot and not the underscore is the field name scoping  
> > "operator".
> > 
> > Hope this helps!
> > 
> > Brian

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![brian\_yoder](https://avatars.discourse-cdn.com/v4/letter/b/f1d935/32.png) [@brian\_yoder](https://discuss.elastic.co/u/brian_yoder)\
**Post date:** [October 1, 2013, 3:35pm UTC](https://discuss.elastic.co/t/boolean-matchquery-on-a-not-analyzed-field/13805/5 "2013-10-01T15:35:38Z")

</div>

> And here are the two documents that are returned from each of the above  
> queries:

{ "\_index" : "mortal" , "\_type" : "elf" , "\_id" : "1" , "\_version" : 1 ,  
"\_score" : 2.982867956161499 , "\_source" : { "cn" : "Celeborn" , "text" :  
"Lives forever" } }  
{ "\_index" : "mortal" , "\_type" : "elf" , "\_id" : "2" , "\_version" : 1 ,  
"\_score" : 2.982867956161499 , "\_source" : { "cn" : "Galadriel" , "text" :  
"Lives forever" } }

(This second rewrite missed a few things that were in the first one....)

Also, here is a phrase query that also worked and returned the two  
documents:

{  
"bool" : {  
"must" : {  
"match" : {  
"_text_" : {  
"query" : "lives forever",  
"type" : "phrase",  
"slop" : 0  
}  
}  
}  
}  
}

Hope this helps!

Brian

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Paul\_Sanwald\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_sanwald_2/32/881_2.png) [@Paul\_Sanwald\_2](https://discuss.elastic.co/u/Paul_Sanwald_2)\
**Post date:** [October 2, 2013, 2:02pm UTC](https://discuss.elastic.co/t/boolean-matchquery-on-a-not-analyzed-field/13805/6 "2013-10-02T14:02:16Z")

</div>

Brian,  
thanks, this does help. The issue I was seeing ended up being around  
timing, the query worked correctly but I was running it from a java  
integration test and the index wasn't updating by the time the assert I was  
using was being called. so, I was seeing inconsistent behavior.

thanks for the detailed example, your help is much appreciated!

On Tue, Oct 1, 2013 at 11:35 AM, InquiringMind [brian.from.fl@gmail.com](mailto:brian.from.fl@gmail.com)wrote:

> > And here are the two documents that are returned from each of the above  
> > queries:
> 
> { "\_index" : "mortal" , "\_type" : "elf" , "\_id" : "1" , "\_version" : 1 ,  
> "\_score" : 2.982867956161499 , "\_source" : { "cn" : "Celeborn" , "text" :  
> "Lives forever" } }  
> { "\_index" : "mortal" , "\_type" : "elf" , "\_id" : "2" , "\_version" : 1 ,  
> "\_score" : 2.982867956161499 , "\_source" : { "cn" : "Galadriel" , "text" :  
> "Lives forever" } }
> 
> (This second rewrite missed a few things that were in the first one....)
> 
> Also, here is a phrase query that also worked and returned the two  
> documents:
> 
> {  
> "bool" : {  
> "must" : {  
> "match" : {  
> "_text_" : {  
> "query" : "lives forever",  
> "type" : "phrase",  
> "slop" : 0  
> }  
> }  
> }  
> }  
> }
> 
> Hope this helps!
> 
> Brian
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/dP8Wv3loOJI/unsubscribe](https://groups.google.com/d/topic/elasticsearch/dP8Wv3loOJI/unsubscribe).  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:14am UTC](https://discuss.elastic.co/t/boolean-matchquery-on-a-not-analyzed-field/13805/7 "2017-07-06T02:14:00Z")

</div>


