# Elasticsearch query not returning the exact value

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373>\
**Category:** Elasticsearch\
**Created:** [June 30, 2016, 7:56am UTC](https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373 "2016-06-30T07:56:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [June 30, 2016, 7:56am UTC](https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373/1 "2016-06-30T07:56:23Z")

</div>

Unable to get the values from my JSON data.

my Data :

{"web1":{"Uptime":1295843,"thr":408685,"nx01\_01":{"Uptime":157635,"Name":"nx01\_01","Bytes":14416383831,"TotalConnections":2},"timestamp": "2016-06-28 09:15:24","Srv":"web1","nx02\_01":{"Uptime":423606,"Name":"nx02\_01","Bytes":0,"TotalConnections":3},"nx04\_01":{"Uptime":496782,"Name":"nx04\_01","Bytes":0,"TotalConnections":2},"nx03\_01":{"Uptime":496782,"Name":"nx03\_01","Bytes":0,"TotalConnections":3}}}

My Elasticsearch Query:

curl -XGET [http://localhost:9200/8m1ea8-2016.06.28/\_search?pretty](http://localhost:9200/8m1ea8-2016.06.28/_search?pretty)? -d '{"size":0,"query":{"filtered":{"query":{"query\_string":{"analyze\_wildcard":true,"query":"\*"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"gte":"1467112598780","lte":"1467112680435"}}}]}}}},"aggs":{"1":{"terms":{"field":"Name","size":0,"order":{"\_term":"asc"}}}}}'

But above query only return single value [**nx04\_01**] instead of showing 4 values . Can you please confirm the above query is correct one.

Output of above query :  
"took":1,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":1,"max\_score":0.0,"hits":[]},"aggregations":{"1":{"doc\_count\_error\_upper\_bound":0,"sum\_other\_doc\_count":0,"buckets":[{"key":"nx04\_01","doc\_count":1}]}}}

Expected values: nx01\_01,nx02\_01,nx03\_01,nx04\_01.

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 1, 2016, 5:52am UTC](https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373/2 "2016-07-01T05:52:33Z")

</div>

Even I tried with some patterns by removing time range and search whole data. But still it shows same value [only showing single value]. Any suggestions ?. Thanks in Advance.

this is my actual data:

```
{
    "web1": {
        "Uptime": 1295843,
        "thr": 408685,
        "nx01_01": {
            "Uptime": 157635,
            "Name": "nx01_01",
            "Bytes": 14416383831,
            "TotalConnections": 2
        },
        "timestamp": "2016-06-28 09:15:24",
        "Srv": "web1",
        "nx02_01": {
            "Uptime": 423606,
            "Name": "nx02_01",
            "Bytes": 0,
            "TotalConnections": 3
        },
        "nx04_01": {
            "Uptime": 496782,
            "Name": "nx04_01",
            "Bytes": 0,
            "TotalConnections": 2
        },
        "nx03_01": {
            "Uptime": 496782,
            "Name": "nx03_01",
            "Bytes": 0,
            "TotalConnections": 3
        }
    }
}

```

I just want to retrieve only the value of "Name" field.

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 4, 2016, 7:39am UTC](https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373/3 "2016-07-04T07:39:30Z")

</div>

Any idea on this ? . Still I'm unable find a solution for this. Please someone give share your suggestions.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 4, 2016, 8:07am UTC](https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373/4 "2016-07-04T08:07:57Z")

</div>

Hey,

it might be possible that you are using an older version of Elasticsearch, that tried to look up field names in some automagic way. Thus when you specify `Name`, then `web1.nx04_01.Name` was used. In current versions this does not work anymore, you always need to specify the full path.

I think in your example it makes more sense to index those four parts of this document as four single documents, because then you are able to use a `name` field, that can be addressed uniquely - which it cannot in your current dataset.

--Alex

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 4, 2016, 10:30am UTC](https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373/5 "2016-07-04T10:30:01Z")

</div>

Yes, I'm using ELS - 1.7.5 version. Right now, I have no plan for migrating my ELS to latest version 2.x since I wasn't hit with any issues on my current ELS version.

Is there any work around solution to get the values ?. Pls share

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 5, 2016, 6:34am UTC](https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373/6 "2016-07-05T06:34:47Z")

</div>

Hey,

you need to change your data model (or even split your single document into several documents, or use nested), if you want to aggregate by the name. The [definitive guide](https://www.elastic.co/guide/en/elasticsearch/guide/master/index.html) has some nice chapters about data modeling (which also contains a chapter about nested document). Take your time and read the whole book if you can 🙂

--Alex

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [July 5, 2016, 6:38am UTC](https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373/7 "2016-07-05T06:38:09Z")

</div>

thanks for your suggestion. let me check the link.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:38pm UTC](https://discuss.elastic.co/t/elasticsearch-query-not-returning-the-exact-value/54373/8 "2017-07-05T22:38:22Z")

</div>


