# Elasticsearch QueryBuilder with dynamic value in term query

**URL:** <https://discuss.elastic.co/t/elasticsearch-querybuilder-with-dynamic-value-in-term-query/17910>\
**Category:** Elasticsearch\
**Created:** [June 4, 2014, 5:39pm UTC](https://discuss.elastic.co/t/elasticsearch-querybuilder-with-dynamic-value-in-term-query/17910 "2014-06-04T17:39:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [June 4, 2014, 5:39pm UTC](https://discuss.elastic.co/t/elasticsearch-querybuilder-with-dynamic-value-in-term-query/17910/1 "2014-06-04T17:39:08Z")

</div>

I have a code like below where I'm doing multiple must in bool query. Here  
I'm passing the must term queries in field "address". Now the ip address  
will come to me as a list from other api and I have to pass for all the  
ip's in the list as a must term query. Here I'm not getting a way how to  
pass the address values dynamically when creating the QueryBuilder.

Please suggest how to do this.

public static SearchResponse searchResultWithAggregation(String es\_index,  
String es\_type, List ipList, String queryRangeTime) {  
Client client = ESClientFactory.getInstance();

```
QueryBuilder qb = QueryBuilders.boolQuery()
        .must(QueryBuilders.termQuery("address", "10.203.238.138"))
        .must(QueryBuilders.termQuery("address", "10.203.238.137"))
        .must(QueryBuilders.termQuery("address", "10.203.238.136"))
        .mustNot(QueryBuilders.termQuery("address", "10.203.238.140"))
        .should(QueryBuilders.termQuery("client", ""));

queryRangeTime = "now-" + queryRangeTime + "m";
FilterBuilder fb = FilterBuilders.rangeFilter("@timestamp")
        .from(queryRangeTime).to("now");

SearchResponse response = client
        .prepareSearch(es_index)
        .setTypes(es_type)
        .setQuery(qb)
        .setPostFilter(fb)
        .addAggregation(
                AggregationBuilders.avg("cpu_average").field("value"))
        .setSize(10).execute().actionGet();

System.out.println(response.toString());
return response;}

```

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/1b6d7ba7-5cc5-4f26-abce-9e6614d39ed4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1b6d7ba7-5cc5-4f26-abce-9e6614d39ed4%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [June 4, 2014, 6:38pm UTC](https://discuss.elastic.co/t/elasticsearch-querybuilder-with-dynamic-value-in-term-query/17910/2 "2014-06-04T18:38:54Z")

</div>

Off the top of my head, you can either using a nested bool query for the IP  
address or use a terms query with the minimum match set to the size of the  
list.

_Option 1:_

QueryBuilder ipQuery = QueryBuilders.boolQuery();  
for (String ip: ipList) {  
ipQuery.must(must(QueryBuilders.termQuery("address", ip));  
}

QueryBuilder qb = QueryBuilders.boolQuery()  
.must(ipQuery)  
...

_Option 2:_

QueryBuilder qb = QueryBuilders.boolQuery()  
.must(termsQuery("address" ,  
ipList).minimumMatch(ipList.size()))  
...

Cheers,

Ivan

On Wed, Jun 4, 2014 at 10:39 AM, Subhadip Bagui [i.bagui@gmail.com](mailto:i.bagui@gmail.com) wrote:

> I have a code like below where I'm doing multiple must in bool query. Here  
> I'm passing the must term queries in field "address". Now the ip address  
> will come to me as a list from other api and I have to pass for all the  
> ip's in the list as a must term query. Here I'm not getting a way how to  
> pass the address values dynamically when creating the QueryBuilder.
> 
> Please suggest how to do this.
> 
> public static SearchResponse searchResultWithAggregation(String es\_index,  
> String es\_type, List ipList, String queryRangeTime) {  
> Client client = ESClientFactory.getInstance();
> 
> ```
> QueryBuilder qb = QueryBuilders.boolQuery()
> .must(QueryBuilders.termQuery("address", "10.203.238.138"))
> .must(QueryBuilders.termQuery("address", "10.203.238.137"))
> .must(QueryBuilders.termQuery("address", "10.203.238.136"))
> .mustNot(QueryBuilders.termQuery("address", "10.203.238.140"))
> .should(QueryBuilders.termQuery("client", ""));
> 
> queryRangeTime = "now-" + queryRangeTime + "m";
> FilterBuilder fb = FilterBuilders.rangeFilter("@timestamp")
> .from(queryRangeTime).to("now");
> 
> SearchResponse response = client
> .prepareSearch(es_index)
> .setTypes(es_type)
> .setQuery(qb)
> .setPostFilter(fb)
> .addAggregation(
> AggregationBuilders.avg("cpu_average").field("value"))
> .setSize(10).execute().actionGet();
> 
> System.out.println(response.toString());
> return response;}
> 
> ```
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/1b6d7ba7-5cc5-4f26-abce-9e6614d39ed4%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1b6d7ba7-5cc5-4f26-abce-9e6614d39ed4%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/1b6d7ba7-5cc5-4f26-abce-9e6614d39ed4%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/1b6d7ba7-5cc5-4f26-abce-9e6614d39ed4%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQAJ77dq-q7JMG41VPvikJjirOB1qtjmCDvaBu1HzZe0%3Dw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQAJ77dq-q7JMG41VPvikJjirOB1qtjmCDvaBu1HzZe0%3Dw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:24am UTC](https://discuss.elastic.co/t/elasticsearch-querybuilder-with-dynamic-value-in-term-query/17910/3 "2017-07-06T01:24:42Z")

</div>


