# Error: bool query does not support \[must-not\]

**URL:** <https://discuss.elastic.co/t/error-bool-query-does-not-support-must-not/49486>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 8, 2016, 3:23pm UTC](https://discuss.elastic.co/t/error-bool-query-does-not-support-must-not/49486 "2016-05-08T15:23:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![eeivin](https://avatars.discourse-cdn.com/v4/letter/e/90ced4/32.png) [@eeivin](https://discuss.elastic.co/u/eeivin)\
**Post date:** [May 8, 2016, 3:23pm UTC](https://discuss.elastic.co/t/error-bool-query-does-not-support-must-not/49486/1 "2016-05-08T15:23:41Z")

</div>

I get the following error when running the watcher:

"status": "failure"  
"reason": "SearchPhaseExecutionException[all shards failed]; nested: QueryParsingException[bool query does not support [must-not]]; "

Would appreciate your help

Thank you,  
Eric

{"watch" :  
"trigger" : {  
"schedule" : { "interval" : "300s" }  
},  
"input" : {  
"search" : {  
"request" : {  
"indices" : ["\<logstash-{now}\>", "\<logstash-{now-1d}\>"],  
"body" : {  
"query": {  
"filtered": {  
"query": {  
"query\_string": {  
"query": "\*",  
"analyze\_wildcard": true,  
"fields": [  
"json.message"  
]  
}  
},  
"filter": {  
"bool": {  
"must": [  
{  
"range": {  
"@timestamp": {  
"gt": "now-300s"  
}  
}  
},

```
                                      {
                                         "query": {
                                           "match": {
                                             "attrs.label_env": {
                                                "query": "prod"
                                              }
                                          }
                                        }
                                      },

                                      {
                                        "bool": {
                                            "should": [
                                                    {
                                                      "query": {
                                                        "match": {
                                                          "json.level": {
                                                            "query": "ERROR",
                                                            "type": "phrase"
                                                          }
                                                        }
                                                      }
                                                    },

                                                    {
                                                      "query": {
                                                        "match": {
                                                          "level": {
                                                            "query": "ERR",
                                                            "type": "phrase"
                                                          }
                                                        }
                                                      }
                                                    }

                                            ]
                                          }
                                        }
                              ],

                              "must-not": [
                                   {
                                    "query": {
                                       "match": {
                                         "json.message": {
                                            "query": "requestID:digital-retrieve-policy-details,message:General error while calling Guidewire: 10001 - Workflow exception triggered.",
                                             "type": "phrase"
                                         }
                                      }
                                   }
                                 }
                             ]

                              
                            }
                          }
                        }
                      },
                      "fields": [
                        "@timestamp",
                        "attrs.label_env",
                        "attrs.label_app",
                        "json.requestId",
                        "json.message",
                        "json.level"
                      ]
                    }
                  }
          }
        }
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 8, 2016, 4:34pm UTC](https://discuss.elastic.co/t/error-bool-query-does-not-support-must-not/49486/2 "2016-05-08T16:34:29Z")

</div>

Hey,

the exception is spot on. There is no such thing as a `must-not` query, that is part of a `bool` query. There is only a `must_not` query (with an underscore), see the [bool query documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html)

Always test your query, before inserting in your watch, so you know that it is valid. Makes it easier to spot watcher issues or query issues.

hope this helps.

--Alex

---

<div class="post-metadata">

**Author:** ![eeivin](https://avatars.discourse-cdn.com/v4/letter/e/90ced4/32.png) [@eeivin](https://discuss.elastic.co/u/eeivin)\
**Post date:** [May 8, 2016, 5:25pm UTC](https://discuss.elastic.co/t/error-bool-query-does-not-support-must-not/49486/3 "2016-05-08T17:25:25Z")

</div>

Got it. Thank you for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:45pm UTC](https://discuss.elastic.co/t/error-bool-query-does-not-support-must-not/49486/4 "2017-07-06T13:45:42Z")

</div>


