# Elasticsearch filter query not working

**URL:** <https://discuss.elastic.co/t/elasticsearch-filter-query-not-working/120998>\
**Category:** Logstash\
**Created:** [February 22, 2018, 7:22am UTC](https://discuss.elastic.co/t/elasticsearch-filter-query-not-working/120998 "2018-02-22T07:22:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ranganath\_nangineni](https://avatars.discourse-cdn.com/v4/letter/r/3ec8ea/32.png) [@ranganath\_nangineni](https://discuss.elastic.co/u/ranganath_nangineni)\
**Post date:** [February 22, 2018, 7:22am UTC](https://discuss.elastic.co/t/elasticsearch-filter-query-not-working/120998/1 "2018-02-22T07:22:53Z")

</div>

Hi,

The below config file is workingfine but the same query when I used it in my logstash config , it is throwing some error.

# Working file:

input {  
elasticsearch {  
"hosts" =\> "[XYZ.com:9200](http://XYZ.com:9200)"  
"index" =\> "test-m-docs"  
#result\_size =\> 1  
query =\> '{ "query": {"match": { "ddocname" :"CNT1882742"} },"sort": {"@timestamp":{"order":"desc"}},"from":0,"size":0,"\_source":"ddoctitle\*" }'  
}  
}

output {  
stdout { codec =\> json\_lines }  
stdout { codec =\> rubydebug }  
}

# Output:

[logstash]# bin/logstash -f elasticquery.conf  
WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path //usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console  
{"ddoctitle":"VSNL\_R12Upgrade\_TECH\_UPG\_Resource\_Mix-DAA1\_V1.12.xls","@version":"1","@timestamp":"2018-02-22T06:58:10.386Z"}  
{"ddoctitle":"VSNL\_R12Upgrade\_TECH\_UPG\_Resource\_Mix-DAA1\_V1.12.xls","@version":"1","@timestamp":"2018-02-22T06:58:10.387Z"}  
{"ddoctitle":"VSNL\_R12Upgrade\_TECH\_UPG\_Resource\_Mix-DAA1\_V1.12.xls","@version":"1","@timestamp":"2018-02-22T06:58:10.388Z"}  
{"ddoctitle":"VSNL\_R12Upgrade\_TECH\_UPG\_Resource\_Mix-DAA1\_V1.12.xls","@version":"1","@timestamp":"2018-02-22T06:58:10.389Z"}  
{  
"ddoctitle" =\> "VSNL\_R12Upgrade\_TECH\_UPG\_Resource\_Mix-DAA1\_V1.12.xls",  
"@version" =\> "1",  
"@timestamp" =\> 2018-02-22T06:58:10.386Z  
}  
{  
"ddoctitle" =\> "VSNL\_R12Upgrade\_TECH\_UPG\_Resource\_Mix-DAA1\_V1.12.xls",  
"@version" =\> "1",  
"@timestamp" =\> 2018-02-22T06:58:10.387Z  
}  
{  
"ddoctitle" =\> "VSNL\_R12Upgrade\_TECH\_UPG\_Resource\_Mix-DAA1\_V1.12.xls",  
"@version" =\> "1",  
"@timestamp" =\> 2018-02-22T06:58:10.388Z  
}  
{  
"ddoctitle" =\> "VSNL\_R12Upgrade\_TECH\_UPG\_Resource\_Mix-DAA1\_V1.12.xls",  
"@version" =\> "1",  
"@timestamp" =\> 2018-02-22T06:58:10.389Z  
}

But the same query in the big config file is throwing the below error:

[2018-02-22T07:02:17,215][WARN][logstash.filters.elasticsearch] Failed to query elasticsearch for previous event {:index=\>"test-m-docs", :query=\>"{ "query": {"match": { "ddocname" :"CNT1882742"} },"\_source":"ddoctitle\*" }", :event=\>2018-02-22T06:01:35.599Z XYZServer XXX.XX.36.75 - - [20/Feb/2018:06:33:50 -0600] "GET /content/web/cnt146634 HTTP/1.1" 200 36 "[https://xyz.com/index.html?ssFolder=5434D69720E6B1899BEB3972EE5604DE](https://xyz.com/index.html?ssFolder=5434D69720E6B1899BEB3972EE5604DE)" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" "10.16.195.106" "image/unknown" , :error=\>#\<Elasticsearch::Transport::Transport::Errors::BadRequest: [400] {"error":{"root\_cause":[{"type":"parse\_exception","reason":"parse\_exception: Encountered " \<RANGE\_GOOP\> "{\"match\": "" at line 1, column 11.\nWas expecting:\n "TO" ...\n "}],"type":"search\_phase\_execution\_exception","reason":"all shards failed","phase":"query","grouped":true,"failed\_shards":[{"shard":0,"index":"test-myo-docs","node":"hdokW\_3gQFeowO0oKgOOrQ","reason":{"type":"query\_shard\_exception","reason":"Failed to parse query [{ "query": {"match": { "ddocname" :"CNT1882742"} },"\_source":"ddoctitle\*" }]","index\_uuid":"RKmSbV4CQsSZaoci6z73Wg","index":"test-myo-docs","caused\_by":{"type":"parse\_exception","reason":"parse\_exception: Cannot parse '{ "query": {"match": { "ddocname" :"CNT1882742"} },"\_source":"ddoctitle\*" }': Encountered " \<RANGE\_GOOP\> "{\"match\": "" at line 1, column 11.\nWas expecting:\n "TO" ...\n ","caused\_by":{"type":"parse\_exception","reason":"parse\_exception: Encountered " \<RANGE\_GOOP\> "{\"match\": "" at line 1, column 11.\nWas expecting:\n "TO" ...\n "}}}}]},"status":400}\>}

# Logstash file content:

if [docname] {  
elasticsearch {  
"hosts" =\> "[XYZ.com:9200](http://XYZ.com:9200)"  
"index" =\> "test-m-docs"  
query =\> '{ "query": {"match": { "ddocname" :"CNT1882742"} },"\_source":"ddoctitle\*" }'  
}  
}

What is causing this error ? and how can I store the results in to variables?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2018, 7:22am UTC](https://discuss.elastic.co/t/elasticsearch-filter-query-not-working/120998/2 "2018-03-22T07:22:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
