# DSL Query with match phrase

**URL:** <https://discuss.elastic.co/t/dsl-query-with-match-phrase/299922>\
**Category:** Elasticsearch\
**Created:** [March 17, 2022, 8:01am UTC](https://discuss.elastic.co/t/dsl-query-with-match-phrase/299922 "2022-03-17T08:01:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Divyank\_Mahalle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divyank_mahalle/32/91240_2.png) [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)\
**Post date:** [March 17, 2022, 8:01am UTC](https://discuss.elastic.co/t/dsl-query-with-match-phrase/299922/1 "2022-03-17T08:01:15Z")

</div>

Hi,

My Doc in Index. I want to query fields in the source.

```auto
{
  "_index" : "hi-2022.01.04",
  "_type" : "_doc",
  "_id" : "-e2AIn4BnkeJqJCuSq9B",
  "_version" : 16,
  "_seq_no" : 264786,
  "_primary_term" : 2,
  "found" : true,
  "_source" : {
    "hostname" : "thehive",
    "ai" : {
      "rule_uid" : "ai26",
      "anomaly_flag" : 0,
      "anomaly_score" : 0.06
    }
  }
}

```

My Query-

```auto
GET hi-2022.01.04/_search
{
        "size": 2000,
        "sort": [
            {
            "@timestamp": {
                "order": "desc",
                "unmapped_type": "boolean"
            }
            }
        ],
        "_source": {
            "excludes": []
        },
        "aggs": {
            "2": {
            "date_histogram": {
                "field": "@timestamp",
                "calendar_interval": "1d",
                "time_zone": "Asia/Calcutta",
                "min_doc_count": 1
            }
            }
        },
        "stored_fields": [
            "*"
        ],
        "script_fields": {},
        "docvalue_fields": [
            {
            "field": "@timestamp",
            "format": "date_time"
            }
        ],
        "query": {
            "bool": {
            "must": [
              {
               "match_phrase": {
               "hostname": {
              "query": "thehive"
            }
          }
        },
                {
                "match_phrase": {
                    "ai.rule_uid": {                
                    "query": "ai26"
                    }
                }
                },
                {
                "match_phrase": {
                    "ai.anomaly_flag": {
                    "query": 0
                    }
                }
                },

                {
                "range": {
                    "@timestamp": {
                    "gte": "now-5M",
                    "lte": "now"
                    }
                }
                }
            ],
            "filter": [
                {
                "match_all": {}
                }
            ],
            "should": [],
            "must_not": []
            }
        }
        }

```

Response-

```auto
{"took":1,"timed_out":false,"_shards":{"total":2,"successful":2,"skipped":0,"failed":0},"hits":{"total":{"value":0,"relation":"eq"},"max_score":null,"hits":[]},"aggregations":{"2":{"buckets":[]}}}

```

If I checked without field "hostname" in above dsl query, its working,but with "hostname" field it's not working ,may be it's not nested.

I tried changing it by various ways, its not working.

Thank You

---

<div class="post-metadata">

**Author:** ![casterQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/casterq/32/93257_2.png) [@casterQ](https://discuss.elastic.co/u/casterQ)\
**Post date:** [March 17, 2022, 8:35am UTC](https://discuss.elastic.co/t/dsl-query-with-match-phrase/299922/2 "2022-03-17T08:35:49Z")

</div>

Why do you use `match_ phrase`，you may be able to try other queries like `math` ，`term`......  
`full_text` query from `text` field type:

> **[Full text queries | Elasticsearch Guide \[8.1\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.1/full-text-queries.html)**

`term-level` query from `keyword` field type:

> **[Term-level queries | Elasticsearch Guide \[8.1\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.1/term-level-queries.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2022, 8:36am UTC](https://discuss.elastic.co/t/dsl-query-with-match-phrase/299922/3 "2022-04-14T08:36:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
