# elasticSearch query\_string not applying on .keyword version of field

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606>\
**Category:** Elasticsearch\
**Created:** [October 8, 2023, 7:04pm UTC](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606 "2023-10-08T19:04:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![cpawali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cpawali/32/126350_2.png) [@cpawali](https://discuss.elastic.co/u/cpawali)\
**Post date:** [October 8, 2023, 7:04pm UTC](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606/1 "2023-10-08T19:04:40Z")

</div>

I am trying to query index with

```auto
{
	"query": {
		"query_string": {
			"query": "application_id:app-20231008232923-0060"
		}
	}
}

```

But records with application\_id:app-20231008232923-0061 are also showing up in result  
Here is my Index

```auto
{
	"devsakafka-logs-spark-info-2023.10.08": {
		"aliases": {},
		"mappings": {
			"doc": {
				"properties": {
					"@timestamp": {
						"type": "date"
					},
					"@version": {
						"type": "text",
						"fields": {
							"keyword": {
								"type": "keyword",
								"ignore_above": 256
							}
						}
					},
					"application_id": {
						"type": "text",
						"fields": {
							"keyword": {
								"type": "keyword",
								"ignore_above": 256
							}
						}
					},
....

```

Using elastic version 6.8.23  
but in query if i use "application\_id.keyword:app-20231008232923-0060" correct results are showing up  
what i am missing?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 8, 2023, 9:21pm UTC](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606/2 "2023-10-08T21:21:45Z")

</div>

Welcome!

One of the field is analyzed. Not the keyword field.

You could look at this video:

> **[Text analysis - Daily Elastic Byte S05E02](https://www.youtube.com/live/YFkKZSLRSSY?si=kCqxAqTJTjfTmpOb)**
>
> Daily Elastic Byte Season 05: SearchFor three weeks we will dive into a different topic related to the Search space every day before lunch in the CEST/EST ti...

Or read [Text analysis | Elasticsearch Guide [8.10] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis.html)

---

<div class="post-metadata">

**Author:** ![cpawali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cpawali/32/126350_2.png) [@cpawali](https://discuss.elastic.co/u/cpawali)\
**Post date:** [October 9, 2023, 3:47am UTC](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606/3 "2023-10-09T03:47:13Z")

</div>

But exactly same settings working in another environment(example dev).  
not given any specific analyzer

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 9, 2023, 5:51am UTC](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606/4 "2023-10-09T05:51:40Z")

</div>

Could you provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

A full reproduction script is something anyone can **copy and paste in Kibana dev console** , click on the run button to reproduce your use case. It will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.

Have a look at the [Elastic Stack and Solutions Help · Forums and Slack | Elastic](https://elastic.co/community/help) page. It contains also lot of useful information on how to ask for help.

It's also important that you upgrade to 7.17 at least.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 9, 2023, 5:53am UTC](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606/5 "2023-10-09T05:53:49Z")

</div>

Are the mappings exactly the same in the other environment?

---

<div class="post-metadata">

**Author:** ![cpawali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cpawali/32/126350_2.png) [@cpawali](https://discuss.elastic.co/u/cpawali)\
**Post date:** [October 9, 2023, 7:09am UTC](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606/6 "2023-10-09T07:09:58Z")

</div>

By removing type text and using keyword tockenizer it worked for application\_id it worked.  
got to know how tockerizer works!!  
thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2023, 7:10am UTC](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606/7 "2023-11-06T07:10:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
