# Elasticsearch DSL query, exists and not exists fields

**URL:** <https://discuss.elastic.co/t/elasticsearch-dsl-query-exists-and-not-exists-fields/285489>\
**Category:** Elasticsearch\
**Tags:** eql-elastic-query-language\
**Created:** [September 29, 2021, 2:46pm UTC](https://discuss.elastic.co/t/elasticsearch-dsl-query-exists-and-not-exists-fields/285489 "2021-09-29T14:46:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![antonisnyc94](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antonisnyc94/32/94316_2.png) [@antonisnyc94](https://discuss.elastic.co/u/antonisnyc94)\
**Post date:** [September 29, 2021, 2:46pm UTC](https://discuss.elastic.co/t/elasticsearch-dsl-query-exists-and-not-exists-fields/285489/1 "2021-09-29T14:46:16Z")

</div>

Hello,

I am trying to achieve the following with DSL querying ( not\_exists: "data.aws.userIdentity.sessionContext.attributes.mfaAuthenticated" AND data.aws.eventName: ConsoleLogin AND data.aws.additionalEventData.MFAUsed: No) OR (exists: "data.aws.userIdentity.sessionContext.attributes.mfaAuthenticated" AND data.aws.eventName: ConsoleLogin AND data.aws.additionalEventData.MFAUsed: No AND data.aws.userIdentity.sessionContext.attributes.mfaAuthenticated: false)

This is what i've got but i dont think the second part of the query works.. Can someone help?

```auto
{
    "size": 0,
    "query": {
        "bool": {
            "must": [
                {
                    "bool": {
                        "must": [
                            {
                                "exists": {
                                    "field": "data.aws.userIdentity.sessionContext.attributes.mfaAuthenticated",
                                    "boost": 1
                                }
                            },
                            {
                                "match": {
                                    "data.aws.eventName": {
                                        "query": "ConsoleLogin",
                                        "operator": "OR",
                                        "prefix_length": 0,
                                        "max_expansions": 50,
                                        "fuzzy_transpositions": true,
                                        "lenient": false,
                                        "zero_terms_query": "NONE",
                                        "auto_generate_synonyms_phrase_query": true,
                                        "boost": 1
                                    }
                                }
                            },
                            {
                                "match": {
                                    "data.aws.additionalEventData.MFAUsed": {
                                        "query": "No",
                                        "operator": "OR",
                                        "prefix_length": 0,
                                        "max_expansions": 50,
                                        "fuzzy_transpositions": true,
                                        "lenient": false,
                                        "zero_terms_query": "NONE",
                                        "auto_generate_synonyms_phrase_query": true,
                                        "boost": 1
                                    }
                                }
                            },
                            {
                                "match": {
                                    "data.aws.userIdentity.sessionContext.attributes.mfaAuthenticated": {
                                        "query": "false",
                                        "operator": "OR",
                                        "prefix_length": 0,
                                        "max_expansions": 50,
                                        "fuzzy_transpositions": true,
                                        "lenient": false,
                                        "zero_terms_query": "NONE",
                                        "auto_generate_synonyms_phrase_query": true,
                                        "boost": 1
                                    }
                                }
                            }
                        ],
                        "adjust_pure_negative": true,
                        "boost": 1
                    }
                },
                {
                    "bool": {
                        "should": [
                            {
                                "bool": {
                                    "must": [
                                        {
                                            "exists": {
                                                "field": "data.aws.userIdentity.sessionContext.attributes.mfaAuthenticated",
                                                "boost": 1
                                            }
                                        },
                                        {
                                            "match": {
                                                "data.aws.eventName": {
                                                    "query": "ConsoleLogin",
                                                    "operator": "OR",
                                                    "prefix_length": 0,
                                                    "max_expansions": 50,
                                                    "fuzzy_transpositions": true,
                                                    "lenient": false,
                                                    "zero_terms_query": "NONE",
                                                    "auto_generate_synonyms_phrase_query": true,
                                                    "boost": 1
                                                }
                                            }
                                        },
                                        {
                                            "match": {
                                                "data.aws.additionalEventData.MFAUsed": {
                                                    "query": "No",
                                                    "operator": "OR",
                                                    "prefix_length": 0,
                                                    "max_expansions": 50,
                                                    "fuzzy_transpositions": true,
                                                    "lenient": false,
                                                    "zero_terms_query": "NONE",
                                                    "auto_generate_synonyms_phrase_query": true,
                                                    "boost": 1
                                                }
                                            }
                                        },
                                        {
                                            "match": {
                                                "data.aws.userIdentity.sessionContext.attributes.mfaAuthenticated": {
                                                    "query": "true",
                                                    "operator": "OR",
                                                    "prefix_length": 0,
                                                    "max_expansions": 50,
                                                    "fuzzy_transpositions": true,
                                                    "lenient": false,
                                                    "zero_terms_query": "NONE",
                                                    "auto_generate_synonyms_phrase_query": true,
                                                    "boost": 1
                                                }
                                            }
                                        }
                                    ],
                                    "adjust_pure_negative": true,
                                    "boost": 1
                                }
                            }
                        ],
                        "adjust_pure_negative": true,
                        "boost": 1
                    }
                }
            ],
            "filter": [
                {
                    "range": {
                        "@timestamp": {
                            "from": "{{period_end}}||-800000m",
                            "to": "{{period_end}}",
                            "include_lower": true,
                            "include_upper": true,
                            "format": "epoch_millis",
                            "boost": 1
                        }
                    }
                }
            ],
            "adjust_pure_negative": true,
            "boost": 1
        }
    },
    "aggregations": {}
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2021, 2:46pm UTC](https://discuss.elastic.co/t/elasticsearch-dsl-query-exists-and-not-exists-fields/285489/2 "2021-10-27T14:46:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
