# Elasticsearch: Understanding Match query

**URL:** <https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479>\
**Category:** Elasticsearch\
**Created:** [December 12, 2018, 5:27am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479 "2018-12-12T05:27:48Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [December 12, 2018, 5:27am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/1 "2018-12-12T05:27:48Z")

</div>

Hi Team

Can you please tell the difference between below two queries?

1. GET /\_search  
{  
"query": {  
"match" : {  
"message" : "this is a test"  
}  
}  
}

2. GET /\_search  
{  
"query": {  
"match" : {  
"message" : {  
"query" : "this is a test",  
"operator" : "and"  
}  
}  
}  
}

I've indexed few pdf files and when I use the second query, I'm getting more relevant results.

Can someone explain the difference?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 12, 2018, 5:55am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/2 "2018-12-12T05:55:43Z")

</div>

The first one is equivalent to

```
GET /_search
{
"query": {
"match" : {
"message" : {
"query" : "this is a test",
"operator" : "or"
}
}
}
}
```

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [December 12, 2018, 7:02am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/3 "2018-12-12T07:02:54Z")

</div>

Hi @dadoonet

got it.

any difference if we dont mention operator in 2.

1. "message: : "this is test"

2."message:  
"query":  
"this is a test"

because when I use both 1 and 2 in match query, the results are varying lot.

Thanks  
Rahul

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 12, 2018, 7:23am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/4 "2018-12-12T07:23:00Z")

</div>

No I don't think it makes any difference.

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [December 12, 2018, 8:21am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/5 "2018-12-12T08:21:58Z")

</div>

hi @dadoonet

facing a typical issue.

I have deployed my elasticsearch on Windows and Linux(same set of documents in both nodes, but both nodes are independent ) with same settings and mappings.

But when I search with a query, the results in windows and results in linux are completely different.

Any idea on this behavior?

Thanks  
rahul

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 12, 2018, 8:34am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/6 "2018-12-12T08:34:21Z")

</div>

No. You need to share both results from both systems.

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [December 12, 2018, 8:49am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/7 "2018-12-12T08:49:00Z")

</div>

Okay @dadoonet. will follow the instructions.

Issue: indexed 14 pdf files with same settings and mappings on 2 es nodes. but getting different results when queried.

**Case-1: Elasticsearch deployed on Amazon EC2(Windows)**

Indexed 14 pdf files

**query:**

**indexname: testindex**

```
{ "_source" : "url",
    "query": {
        "match" : {
            "content" : {
                "query" : "windows install"
                , "operator": "and"
            }
        }
    }
}

```

**Response:**

the last term in url is the name of the file

```
"hits": [
      {
        "_index": "testindex",
        "_type": "_doc",
        "_id": "5",
        "_score": 2.230532,
        "_source": {
          "url": "http://127.0.0.1:5000/js/Linux/linux _faq_3_manual.pdf"
        }
      },
      {
        "_index": "testindex",
        "_type": "_doc",
        "_id": "8",
        "_score": 2.084747,
        "_source": {
          "url": "http://127.0.0.1:5000/js/Linux/the-linux-faq.pdf"
        }
      }
]

```

**Case-2: Elasticsearch deployed on Redhat Linux**

Indexed same 14 pdf files

Index name: testindex

query:

```
{ "_source" : "url",
    "query": {
        "match" : {
            "content" : {
                "query" : "windows install"
                , "operator": "and"
            }
        }
    }
}

```

**results:**

```
"hits": [
            {  
                "_index": "testindex",
                "_type": "_doc",
                "_id": "11",
                "_score": 2.6487362,
                "_source": {
                    "url": "http://filesystemwef.com/Windows_Issues/31831392.pdf"
                }
            },
            {
                "_index": "testindex",
                "_type": "_doc",
                "_id": "12",
                "_score": 1.2416239,
                "_source": {
                    "url": "http://http://filesystemwef.com/Windows_Issues/357786482.pdf"
                }
            }
]
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 12, 2018, 9:52am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/8 "2018-12-12T09:52:58Z")

</div>

We can see that the computed `_score` is different. By default, elasticsearch sorts by `_score` so the ordering seems correct here.

Sadly I don't have the full response object just I'm just guessing here.  
May be you have more than one shard and the distribution of your documents is different in one case than the other. Also the total number of documents is may be different in one system than the other.

Some ideas:

- Run the same test with only one shard
- Or use [DFS](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-search-type.html#dfs-query-then-fetch): `?search_type=dfs_query_then_fetch`
- Check that you have exactly the same documents in both systems

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [December 12, 2018, 2:24pm UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/9 "2018-12-12T14:24:12Z")

</div>

@dadoonet

you are right. **both indices have 5 shards.**

**Any api to understand how many documents are in each shard?**

**using query\_then\_fetch is giving the same results in both nodes.** Also, the results are more relevant. **But is it recommended in production ?**

Thanks for the query\_then\_fetch. I haven't seen this before. All the elastic concepts literally makes sense. Elasticsearch is offering lot of fleixibility. the more you understand it, the more you use the features of it, the more relevant your search is.

still lot and lot to know. **thanks to all the elastic team for such sensible features.**  
🙂

-Rahul

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 12, 2018, 3:45pm UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/10 "2018-12-12T15:45:58Z")

</div>

> [@rahulnama](#):
>
> But is it recommended in production ?

You can but if you don't have so many data, it's always better to use one single shard.

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [December 14, 2018, 2:01pm UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/11 "2018-12-14T14:01:26Z")

</div>

hi @dadoonet

using one shard is giving more relevant results. Thank you for that.

If possible, Can you also suggest any solution to the below problem?

All the indexed documents are related to only windows and linux issues. Now whenever a user searches about **"mobile issues"** , elasticsearch will return the results as it matches with **issues** , and it might also match with **mobile** somewhere in the documents.

Reference:

**search query:**

```
GET pdfminerone/_search
{ 
  "size": 10, 
  "_source": "url", 
  "query": {
    "match": {
      "content": "mobile issues"
     
    }
  }
}

```

**Response:**

```
"hits": [
      {
        "_index": "pdfminerone",
        "_type": "_doc",
        "_id": "12",
        "_score": 4.144372,
        "_source": {
          "url": "http://127.0.0.1:5000/js/Windows_Issues/357786482.pdf"
        }
      },
      {
        "_index": "pdfminerone",
        "_type": "_doc",
        "_id": "10",
        "_score": 2.7226787,
        "_source": {
          "url": "http://127.0.0.1:5000/js/Linux/linux _faq_2_manual.pdf"
        }
      }]

```

The first document with score 4 is related to windows issues and nothing to say about mobile issues.

But, if we recommend that url to the user, user will waste his time searching about mobile issues in that url.

**How to avoid such scenarios?**

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 14, 2018, 2:25pm UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/12 "2018-12-14T14:25:41Z")

</div>

By default elasticsearch does a "or" but you can change it to be a "and" with something like

```
GET /_search
{
    "query": {
        "match" : {
            "Field" : {
                "query" : "text",
                "operator" : "and"
            }
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [December 14, 2018, 3:04pm UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/13 "2018-12-14T15:04:36Z")

</div>

makes sense but still I see similar results

**Query-1**

```
GET testbooks/_search
{ 
  "size": 10, 
  "_source": "url", 
  "query": {
    "match": {
      "content": "mobile issues"
     
    }
  }
}

```

**response:**

```
"hits": {
    "total": 9,
    "max_score": 4.144372,
    "hits": [
      {
        "_index": "testbooks",
        "_type": "_doc",
        "_id": "3",
        "_score": 4.144372,
        "_source": {
          "url": "/Windows_Issues/357786482.pdf"
        }
      },
      {
        "_index": "testbooks",
        "_type": "_doc",
        "_id": "8",
        "_score": 2.7226787,
        "_source": {
          "url": "/Linux/linux _faq_2_manual.pdf"
        }
      }]

```

**Query-2:**

```
GET testbooks/_search
{ "_source": "url", 
    "query": {
        "match" : {
            "content" : {
                "query" : "mobile issues",
                "operator" : "and"
            }
        }
    }
}

```

**Response:**

```
"hits": {
    "total": 2,
    "max_score": 4.144372,
    "hits": [
      {
        "_index": "testbooks",
        "_type": "_doc",
        "_id": "3",
        "_score": 4.144372,
        "_source": {
          "url": "/Windows_Issues/357786482.pdf"
        }
      },
      {
        "_index": "testbooks",
        "_type": "_doc",
        "_id": "8",
        "_score": 2.7226787,
        "_source": {
          "url": "/Linux/linux _faq_2_manual.pdf"
        }
      }
    ]
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 14, 2018, 5:27pm UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/14 "2018-12-14T17:27:55Z")

</div>

There is no `content` field in your example so I don't see how this works.

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [December 17, 2018, 5:19am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/15 "2018-12-17T05:19:33Z")

</div>

hi @dadoonet

Yea I agree. will both queries return the same score if both keywords( **mobile , issues** ) appeared in the documents even once?

-Rahul

---

<div class="post-metadata">

**Author:** ![rahulnama](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Post date:** [December 19, 2018, 11:45am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/16 "2018-12-19T11:45:53Z")

</div>

hi @dadoonet.

I've indexed 14 books out of which two-three books talk about internet

search query:

```
GET testbooks/_search
{ "_source": "url", 
      "explain": true, 
    "query": {
        "match" : {
            "content" : {
                "query" : "unable to connect to the internet ",  
                "operator" : "and"
            }
        }
    }
} 

```

when I run this query, I got a document which is not relevant to internet. though documents which are more relevant to internet are available in ES.

In the document ES returned, the keyword **unable** is repeated 60 times, the word connected is repeated 100 times but the internet is repeated only 2 times.

Still it got first in results: How to avoid such scenarios?

Please suggest

**Note: I could post the results but it has lot of text so I didn't.**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2019, 11:45am UTC](https://discuss.elastic.co/t/elasticsearch-understanding-match-query/160479/17 "2019-01-16T11:45:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
