# DSL compound Queries

**URL:** <https://discuss.elastic.co/t/dsl-compound-queries/330591>\
**Category:** Elasticsearch\
**Created:** [April 23, 2023, 8:53pm UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591 "2023-04-23T20:53:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![waitangi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/waitangi/32/110887_2.png) [@waitangi](https://discuss.elastic.co/u/waitangi)\
**Post date:** [April 23, 2023, 8:53pm UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591/1 "2023-04-23T20:53:36Z")

</div>

Hi everyone

I have following DSL queries:

```auto
GET eclaims-logs-2023.04.21/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "match": {
            "thread_name" : "http-nio-5050-exec-7"
          }
        }
      ]
    }
  }
}

```

It works well and returns 5036 results. All results have the value of 'thread\_name' equals 'http-nio-5050-exec-7'.  
Second query returns documents added beetween '2023-04-21T08:06:15.220Z' and '2023-04-21T08:06:15.500Z'. Number of such documents is 14

```auto
GET eclaims-logs-2023.04.21/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "range": {
            "@timestamp": {
              "gte": "2023-04-21T08:06:15.220Z",
              "lt": "2023-04-21T08:06:15.500Z"
            }
          }
        }
      ]
    }
  }
}

```

The third query that combines previus condiions is:

```auto
GET eclaims-logs-2023.04.21/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "range": {
            "@timestamp": {
              "gte": "2023-04-21T08:06:15.220Z",
              "lt": "2023-04-21T08:06:15.500Z"
            }
          }
        },
        {
          "match": {
            "thread_name" : "http-nio-5050-exec-7"
          }
        }
      ]
    }
  }
}

```

the query returns 14 results, and seems to ignore match condition.  
In my opinion the result should be 2.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 27, 2023, 1:51am UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591/2 "2023-04-27T01:51:15Z")

</div>

Do all the results match the `must` though?

---

<div class="post-metadata">

**Author:** ![waitangi1](https://avatars.discourse-cdn.com/v4/letter/w/f9ae1b/32.png) [@waitangi1](https://discuss.elastic.co/u/waitangi1)\
**Post date:** [May 18, 2023, 7:09pm UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591/3 "2023-05-18T19:09:54Z")

</div>

> [@waitangi](#):
>
> ```auto
> "query": {
> "bool": {
> "must": [
> {
> "range": {
> "@timestamp": {
> "gte": "2023-04-21T08:06:15.220Z",
> "lt": "2023-04-21T08:06:15.500Z"
> }
> }
> },
> {
> "match": {
> "thread_name" : "http-nio-5050-exec-7"
> }
> }
> ]
> }
> }
> 
> ```

That's the point. Only 2 documents in the index matches 2 conditions...  
I want a simple query that matches 2 conditions.  
Am I missing anything?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 18, 2023, 8:05pm UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591/4 "2023-05-18T20:05:58Z")

</div>

What is the mapping of the thread\_name field?

Can you show one sample document that you expect the compound query to match and one that is returned by should not match?

> [@waitangi](#):
>
> It works well and returns 5036 results. All results have the value of 'thread\_name' equals 'http-nio-5050-exec-7'.

Did you go through and inspect all 5036 results?

---

<div class="post-metadata">

**Author:** ![dhondup](https://avatars.discourse-cdn.com/v4/letter/d/f1d935/32.png) [@dhondup](https://discuss.elastic.co/u/dhondup)\
**Post date:** [May 18, 2023, 8:25pm UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591/5 "2023-05-18T20:25:11Z")

</div>

@waitangi1

Let's say the first match query == A which returns 5036 results and the range query == B which returns 14 results based on your question above.

Since the bool must query is an **AND** operation, it will find the intersection of the two results (A and B). Out of 5036 results that already matched A, 14 of them also matched B. That sounds correct.

How were you verifying that there were only 2 documents that matched the combined query?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2023, 8:26pm UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591/6 "2023-06-15T20:26:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
