# Elasticsearch query for documenting containing OR along with AND

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-for-documenting-containing-or-along-with-and/107555>\
**Category:** Elasticsearch\
**Created:** [November 14, 2017, 1:58pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-documenting-containing-or-along-with-and/107555 "2017-11-14T13:58:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [November 14, 2017, 1:58pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-documenting-containing-or-along-with-and/107555/1 "2017-11-14T13:58:32Z")

</div>

I'm new to elasticsearch and am doing a bit of query basics.

I have to retrieve count of those documents that: Either contain netflow.src\_port ['10','11','12'] OR netflow.dst\_port ['20','21','22'] AND timestamp being within the last 15 minutes.

I have a basic query as below:

```
body: {
    query: {
      bool:{
        should: [
          {terms: { 'netflow.src_port': ['10','11','12'] }},
          {terms: { 'netflow.dst_port': ['20','21','22] }},
        ],
        must: [
          {range : {
            "@timestamp" : {
              "gt" : "now-15"
            }
          }}
        ]
      }
    },
  }

```

Going by the [official documentation](https://www.elastic.co/guide/en/elasticsearch/guide/current/bool-query.html), should is used to note that: a document need not contain src\_port or dst\_port in that range, but if it does, then calculate cost accordingly.

What I actually need is an or condition for them.

If my explaination is not clear, the below might convey what I'm trying to achieve:

`if( (netflow.src_port contains [10 or 11 or 12] || netflow.dst_port contains [20 or 21 or 22]) && timestamp is within the last 15m.`

What exactly do I need to do to get the desired result?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [November 14, 2017, 2:09pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-documenting-containing-or-along-with-and/107555/2 "2017-11-14T14:09:51Z")

</div>

You have two top level clauses that both need to be satisfied -

- MUST be the right time
- MUST be the right IPs

So these are 2 clause objects in a MUST array.  
The first clause is a range query.  
The second of these clauses has a list of IPs from which to choose so needs wrapping in a `bool` query that lists the choices in a `should` clause:

```
{
  "query": {
	"must": [
	  {
		"range": {
		  "@timestamp": {
			"gt": "now-15"
		  }
		}
	  },
	  {
		"bool": {
		  "should": [
			{
			  "terms": {
				"netflow.src_port": [
				  "10",
				  "11",
				  "12"
				]
			  }
			},
			{
			  "terms": {
				"netflow.dst_port": [
				  "20",
				  "21",
				  "22"
				]
			  }
			}
		  ]
		}
	  }
	]
  }
}
```

---

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [November 14, 2017, 2:27pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-documenting-containing-or-along-with-and/107555/3 "2017-11-14T14:27:56Z")

</div>

> [@Mark\_Harwood](#):
>
> {  
> "terms": {  
> "netflow.src\_port": [  
> "10",  
> "11",  
> "12"  
> ]  
> }  
> },  
> {  
> "terms": {  
> "netflow.dst\_port": [  
> "20",  
> "21",  
> "22"  
> ]

Thanks for the quick reply Mark. I appreciate the help. but something regarding the documentation is tripping me.

According to the [documentation](https://www.elastic.co/guide/en/elasticsearch/guide/current/bool-query.html):

> The difference comes in with the two should clauses, which say that: a document is not required to contain either brown or dog, but if it does, then it should be considered more relevant

Applying the same logic here, does it not mean that:

> The document need not contain either of the IP ranges, but if it does contain, then boost it's score. ==\> which translates to the query picking up those docs that contain neither of the values in the range.

I'm sure I'm mistaken here, but could you please explain?

Thanks.

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [November 14, 2017, 2:34pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-documenting-containing-or-along-with-and/107555/4 "2017-11-14T14:34:15Z")

</div>

> [@blueren](#):
>
> I'm sure I'm mistaken here, but could you please explain?

That page from the guide isn't telling the whole story there. Looking at the [reference docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html) for `bool` query there's this added wrinkle:

> If the bool query ... has neither must or filter then at least one of the should queries must match a document for it to match the bool query

My inner `bool` query only has a `should` parameter which means that at least one of the listed `should` clauses has to match.

---

<div class="post-metadata">

**Author:** ![blueren](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@blueren](https://discuss.elastic.co/u/blueren)\
**Post date:** [November 14, 2017, 2:37pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-documenting-containing-or-along-with-and/107555/5 "2017-11-14T14:37:42Z")

</div>

Oh! understood.

So it's safe to assume that:  
Must \<--\> AND  
should \<--\> OR

Thanks for the solution!

---

<div class="post-metadata">

**Author:** ![david\_](https://avatars.discourse-cdn.com/v4/letter/d/c0e974/32.png) [@david\_](https://discuss.elastic.co/u/david_)\
**Post date:** [November 24, 2017, 11:04am UTC](https://discuss.elastic.co/t/elasticsearch-query-for-documenting-containing-or-along-with-and/107555/6 "2017-11-24T11:04:14Z")

</div>

For efficiency, also consider `filter` instead of `must`, if you don't need the scores.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2017, 11:04am UTC](https://discuss.elastic.co/t/elasticsearch-query-for-documenting-containing-or-along-with-and/107555/7 "2017-12-22T11:04:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
