# Do I have to explicitly exclude the \_all field in queries?

**URL:** <https://discuss.elastic.co/t/do-i-have-to-explicitly-exclude-the--all-field-in-queries/22868>\
**Category:** Elasticsearch\
**Created:** [March 24, 2015, 5:50pm UTC](https://discuss.elastic.co/t/do-i-have-to-explicitly-exclude-the--all-field-in-queries/22868 "2015-03-24T17:50:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Brian\_Levine](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@Brian\_Levine](https://discuss.elastic.co/u/Brian_Levine)\
**Post date:** [March 24, 2015, 5:50pm UTC](https://discuss.elastic.co/t/do-i-have-to-explicitly-exclude-the--all-field-in-queries/22868/1 "2015-03-24T17:50:42Z")

</div>

Hi all,

I clearly haven't completely grokked something in how QueryString queries  
are interpreted. Consider the following query:

{  
"query": {  
"query\_string": {  
"analyze\_wildcard": true,  
"query": "Node.author:Brian Levine"  
}  
},  
"fields": ["Node.author"],  
"explain":true  
}

Note: The Node.author field is not\_analyzed.

The results from this query include documents for which the Node.author  
field contains neither "Brian" nor "Levine". In examining the the  
explanation, I found that the documents were included because another field  
in the document contained "Levine." A snippet from the explanation shows  
that the \_all field was considered:

{  
"value": 0.08775233,  
"description": "weight(\_all:levine in 464) [PerFieldSimilarity], result  
of:",  
...

Do I need to explicitly exclude the \_all field in the query?

Separate question: Because the Node.author field is not\_analyzed, I had  
thought that the value "Brian Levine" would also not be analyzed and  
therefore only documents whose Node.author field contained "Brian Levine"  
exactly would be matched, yet the explanation shows that the "brian" and  
"levine" tokens were considered. I also noticed that if I change the query  
to:

"query: "Node.author:(Brian Levine)"

then result set changes. Only the documents whose Node.author field  
contains either "brian" OR "levine" are included (which is what I would  
have expected). According to the explanation, the \_all field is not  
considered in this query.

So I'm confused. Clearly, I don't understand how my original query is  
interpreted.

Hopefully, someone can enlighten me.

Thanks.

-brian

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/120103bc-a60d-418a-b092-09f71732b682%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/120103bc-a60d-418a-b092-09f71732b682%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Brian\_Levine](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@Brian\_Levine](https://discuss.elastic.co/u/Brian_Levine)\
**Post date:** [March 24, 2015, 6:36pm UTC](https://discuss.elastic.co/t/do-i-have-to-explicitly-exclude-the--all-field-in-queries/22868/2 "2015-03-24T18:36:12Z")

</div>

OK, I think I figured this out. It's the space between "Brian" and  
"Levine". The query:

"query": "Node.author:Brian Levine"

is actually interpreted as Node.author:Brian OR Levine in which case  
"Levine" is searched for in the \_all field. Seems so obvious now! 😉

-b

On Tuesday, March 24, 2015 at 1:50:42 PM UTC-4, Brian Levine wrote:

> Hi all,
> 
> I clearly haven't completely grokked something in how QueryString queries  
> are interpreted. Consider the following query:
> 
> {  
> "query": {  
> "query\_string": {  
> "analyze\_wildcard": true,  
> "query": "Node.author:Brian Levine"  
> }  
> },  
> "fields": ["Node.author"],  
> "explain":true  
> }
> 
> Note: The Node.author field is not\_analyzed.
> 
> The results from this query include documents for which the Node.author  
> field contains neither "Brian" nor "Levine". In examining the the  
> explanation, I found that the documents were included because another field  
> in the document contained "Levine." A snippet from the explanation shows  
> that the \_all field was considered:
> 
> {  
> "value": 0.08775233,  
> "description": "weight(\_all:levine in 464) [PerFieldSimilarity],  
> result of:",  
> ...
> 
> Do I need to explicitly exclude the \_all field in the query?
> 
> Separate question: Because the Node.author field is not\_analyzed, I had  
> thought that the value "Brian Levine" would also not be analyzed and  
> therefore only documents whose Node.author field contained "Brian Levine"  
> exactly would be matched, yet the explanation shows that the "brian" and  
> "levine" tokens were considered. I also noticed that if I change the query  
> to:
> 
> "query: "Node.author:(Brian Levine)"
> 
> then result set changes. Only the documents whose Node.author field  
> contains either "brian" OR "levine" are included (which is what I would  
> have expected). According to the explanation, the \_all field is not  
> considered in this query.
> 
> So I'm confused. Clearly, I don't understand how my original query is  
> interpreted.
> 
> Hopefully, someone can enlighten me.
> 
> Thanks.
> 
> -brian

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/63c5fff3-cfd5-4003-89ad-015d8fdb4879%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/63c5fff3-cfd5-4003-89ad-015d8fdb4879%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:24am UTC](https://discuss.elastic.co/t/do-i-have-to-explicitly-exclude-the--all-field-in-queries/22868/3 "2017-07-06T00:24:19Z")

</div>


