# Combine \`should\` with \`filter\` search API

**URL:** <https://discuss.elastic.co/t/combine-should-with-filter-search-api/278696>\
**Category:** Elasticsearch\
**Tags:** language-clients\
**Created:** [July 14, 2021, 5:23pm UTC](https://discuss.elastic.co/t/combine-should-with-filter-search-api/278696 "2021-07-14T17:23:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![NoviceESCoder](https://avatars.discourse-cdn.com/v4/letter/n/ec9cab/32.png) [@NoviceESCoder](https://discuss.elastic.co/u/NoviceESCoder)\
**Post date:** [July 14, 2021, 5:23pm UTC](https://discuss.elastic.co/t/combine-should-with-filter-search-api/278696/1 "2021-07-14T17:23:19Z")

</div>

I wanted to translate my DSL query search that will return the results I am looking for, but when I translated my DSL query to NEST when I hit the end point it just shows `[]`.

Documentation that I read:

[Bool query usage](https://www.elastic.co/guide/en/elasticsearch/client/net-api/current/bool-query-usage.html)

[Writing bool queries](https://www.elastic.co/guide/en/elasticsearch/client/net-api/current/bool-queries.html)

My DSL query search that actually returns values:

```
GET /customer-simulation-es-app-logs*/_search
{
  "_source": ["@timestamp", "level", "message", "messageTemplate"], 
 "query": {
    "bool": {
      "should": [
        { "match": {"level" : "Error"} },
        { "match": {"level" : "Information"} }
      ], 
      "filter": [
        {
          "range": {
            "@timestamp": {
               "gte": "2021-07-14T00:00:00.000-05:00",
               "lt": "2021-07-14T23:59:59.999-05:00"
            }
          }
        }
      ],
      "minimum_should_match": 1
    }
  }
}

```

What I get when I run the DSL query:

[![enter image description here](https://i.stack.imgur.com/SFCYk.png)](https://i.stack.imgur.com/SFCYk.png)

My attempt to translate it to NEST:

`EsSource.cs`:

```
        public class EsSource
        {
            [Date(Name = "@timestamp")]
            public DateTimeOffset timestamp { get; set; }
            public String level { get; set; }
            public String messageTemplate { get; set; }
            public String message { get; set; }
            // public List<EsExceptions> exceptions { get; set; }
            // public EsFields fields { get; set; }
        }

[HttpGet("GetMonthlyLogs")]
public async Task<List<EsSource>> GetLogsByDate()
{
    var response = await _elasticClient.SearchAsync<EsSource>(s => s
          .Size(3000) // must see about this
          .Source(src => src.Includes(i => i
                            .Fields(f => f.timestamp,
                                    f => f.level,
                                    f => f.messageTemplate,
                                    f => f.message)))
          .Index("customer-simulation-es-app-logs*")
          .Query(q => q
              .Bool(b => b
                  .Should(
                        m => m
                        .Match(ma => ma
                            .Field(fa => fa.level.Contains("Error"))),
                        m => m
                        .Match(ma => ma
                            .Field(fa => fa.level.Contains("Information"))))
                  .Filter(f => f.DateRange(dr => dr
                  .Field("@timestamp")
                      .GreaterThanOrEquals("2021-07-14T00:00:00.000-05:00")
                      .LessThanOrEquals(DateTime.Now)))
                  .MinimumShouldMatch(1))));

    return response?.Documents.ToList();
}

```

_I even attempted to change the `.field()` inside of the should to see if that would help but it does not_

```
.Query(q => q
                      .Bool(b => b
                          .Should(
                                m => m
                                .Match(ma => ma
                                    .Field(fa => fa.level)
                                    .Name("Error")),
                                m => m
                                .Match(ma => ma
                                    .Field(fa => fa.level)
                                    .Name("Information")))

```

Even this above returns an empty array.

[![enter image description here](https://i.stack.imgur.com/MEuog.png)](https://i.stack.imgur.com/MEuog.png)

**Am I not translating the DSL query to NEST correctly?**

---

<div class="post-metadata">

**Author:** ![stevejgordon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stevejgordon/32/80912_2.png) [@stevejgordon](https://discuss.elastic.co/u/stevejgordon)\
**Post date:** [July 27, 2021, 10:11am UTC](https://discuss.elastic.co/t/combine-should-with-filter-search-api/278696/2 "2021-07-27T10:11:08Z")

</div>

Hi there! It looks like you're very close to the correct syntax for what you're trying to achieve. In this case, you need to specify the text you wish to search for in the level field.

To do this, using the fluent syntax, you specify it by providing a `Query` value.

```auto
var response = await Client.SearchAsync<EsSource>(s => s
    .Size(3000) // must see about this
    .Source(src => src.Includes(i => i
        .Fields(f => f.timestamp,
            f => f.level,
            f => f.messageTemplate,
            f => f.message)))
    .Index("customer-simulation-es-app-logs*")
    .Query(q => q
        .Bool(b => b
            .Should(
                m => m.Match(ma => ma.Field(fa => fa.level).Query("Error")),
                m => m.Match(ma => ma.Field(fa => fa.level).Query("Information")))
            .Filter(f => f.DateRange(dr => dr
                .Field("@timestamp")
                .GreaterThanOrEquals("2021-07-14T00:00:00.000-05:00")
                .LessThanOrEquals(DateTime.Now)))
            .MinimumShouldMatch(1))));

```

The above should translate the to query you showed, matching documents where the level is "Error" OR "Information".

Does this answer your question?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2021, 10:11am UTC](https://discuss.elastic.co/t/combine-should-with-filter-search-api/278696/3 "2021-08-24T10:11:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
