# Elasticsearch query dsl

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-dsl/131222>\
**Category:** Elasticsearch\
**Created:** [May 9, 2018, 7:26pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl/131222 "2018-05-09T19:26:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![elktotherescue](https://avatars.discourse-cdn.com/v4/letter/e/9fc348/32.png) [@elktotherescue](https://discuss.elastic.co/u/elktotherescue)\
**Post date:** [May 9, 2018, 7:26pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl/131222/1 "2018-05-09T19:26:18Z")

</div>

I posted some simple json documents within a 'message' property in an index.

here is the mapping I have:  
Mappings for the WSLogging index:

```
{
  "ws.loggingtesting-20180504": {
    "mappings": {
      "fluentd": {
        "properties": {
          "@log_name": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "@timestamp": {
            "type": "date"
          },
          "level": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "logger_name": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "message": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword"
              }
            }
          },
          "sequence_id": {
            "type": "long"
          }
        }
      }
    }
  }
}

```

I have 20 or so entries for logging that look like this:  
Mappings for the WSLogging index:

```
{
  "_index": "ws.loggingtesting-20180504",
  "_type": "fluentd",
  "_id": "XuyxKGMBTx62wVJBapS4",
  "_version": 1,
  "_score": null,
  "_source": {
    "level": "Info",
    "message": "{ \"time\": \"2018-05-03 20:07:21.8465\", \"msg\": \"Testing02 0 on 5\\/3\\/18 - 8:07:21 PM\", \"@target_index\": \"LoggingTesting\", \"HostName\": \"G625C\", \"FullHostName\": \"G625C\", \"IPAddress\": \"10.211.55.3\", \"DomainName\": \"\", \"UserName\": \"G625C\\\\gggg\", \"CallerMemberName\": \"LogInfo\", \"CallerFilePath\": \"C:\\\\code\\\\LoggingTesting\\\\WS.Logging\\\\WSNLogLogger.cs\", \"CallerLineNumber\": 75 }",
    "logger_name": "WS.Logging.WSNLogLogger",
    "sequence_id": 2,
    "@timestamp": "2018-05-03T20:07:21.000000000-05:00",
    "@log_name": "LoggingTesting"
  },
  "fields": {
    "@timestamp": [
      "2018-05-04T01:07:21.000Z"
    ]
  },
  "sort": [
    1525396041000
  ]
}

```

In DevTools I'm trying to use the Query DSL of different variations. This is the latest, and there are no syntax errors, but there are 0 hits:

```
GET ws.loggingtesting-20180504/_search
{
"query": {
        "query_string": {
            "query": "testing03*"
        }
    }
}

```

I've also tried

```
"query" : {
   "match" : { 
"query": {
"message" : "testing03*"} }}

```

any assistance is greatly appreciated. Thank you.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 9, 2018, 7:38pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl/131222/2 "2018-05-09T19:38:28Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

---

<div class="post-metadata">

**Author:** ![elktotherescue](https://avatars.discourse-cdn.com/v4/letter/e/9fc348/32.png) [@elktotherescue](https://discuss.elastic.co/u/elktotherescue)\
**Post date:** [May 9, 2018, 9:25pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl/131222/3 "2018-05-09T21:25:15Z")

</div>

thank you for the tip. I have made the adjustments.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 9, 2018, 9:41pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl/131222/4 "2018-05-09T21:41:25Z")

</div>

Try to run the analyze API on the message content and you will see how this is indexed.

I think you should transform the content in more structured data to get advantage of it.

---

<div class="post-metadata">

**Author:** ![elktotherescue](https://avatars.discourse-cdn.com/v4/letter/e/9fc348/32.png) [@elktotherescue](https://discuss.elastic.co/u/elktotherescue)\
**Post date:** [May 9, 2018, 9:57pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl/131222/5 "2018-05-09T21:57:11Z")

</div>

thank you. I agree that it would be better to use structured data. I read that mappings are no longer going to be supported in version 7.0.0. I wanted to try to understand how to perform queries on this using Query DSL in it's current form (by default)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 9, 2018, 10:09pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl/131222/6 "2018-05-09T22:09:30Z")

</div>

Mapping will still be there in the future.  
Support for Multiple types per index is gone so types will be removed. But mapping still be there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2018, 10:09pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl/131222/7 "2018-06-06T22:09:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
