# ES Query returns results that doesn't not fit the query

**URL:** <https://discuss.elastic.co/t/es-query-returns-results-that-doesnt-not-fit-the-query/82932>\
**Category:** Elasticsearch\
**Created:** [April 19, 2017, 5:40pm UTC](https://discuss.elastic.co/t/es-query-returns-results-that-doesnt-not-fit-the-query/82932 "2017-04-19T17:40:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jac1241](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@jac1241](https://discuss.elastic.co/u/jac1241)\
**Post date:** [April 19, 2017, 5:40pm UTC](https://discuss.elastic.co/t/es-query-returns-results-that-doesnt-not-fit-the-query/82932/1 "2017-04-19T17:40:14Z")

</div>

Hi all,

I've stumbled upon weird behavior in ES, where it returns results that does not match the query.  
We are on ES 2.4 with tribe, and i was wondering if anyone encountered such behavior.

**Query**

```
{
  "query": {
    "bool": {
      "must": [
        {
          "exists": {
            "field": "header.create_time"
          }
        }
      ],
      "must_not": [],
      "should": [
        {
          "term": {
            "o.dst.name": "10.61.248.170"
          }
        },
        {
          "term": {
            "o.sources.name": "10.61.248.170"
          }
        },
        {
          "term": {
            "o.src.name": "10.61.248.170"
          }
        }
      ]
    }
  },
  "sort": {
    "header.create_time": "desc"
  },
  "size": 1
}

```

**Result** (I've hidden some info to make it readable)

```
{
  "took": 4,
  "timed_out": false,
  "_shards": {
    "total": 48,
    "successful": 48,
    "failed": 0
  },
  "hits": {
    "total": 18889,
    "max_score": null,
    "hits": [
      {
        "_index": "someindex",
        "_type": "sometime",
        "_id": "6053119379950236520",
        "_score": null,
        "_source": {
          "o": {
            "src": {
              "name": "0.0.0.0"
            },
            "dst": {
              "name": ""
            }
          }
        },
        "sort": [
          1492611944340
        ]
      }
    ]
  }
}

```

Thanks,

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [April 20, 2017, 3:45am UTC](https://discuss.elastic.co/t/es-query-returns-results-that-doesnt-not-fit-the-query/82932/2 "2017-04-20T03:45:27Z")

</div>

Does the document contain a valid header.create\_time? I am assuming so  
since there is a sort value.

The should clauses of the boolean query are optional and are used to  
increase the score of a document. Any matching should clause will increase  
the score. As long as the must clause matches, you will get a hit.

What you are probably want is for that should match to be actually another  
bool query alongside the existing exist clause. And since you are using  
only exist and term queries, you also probably want to use filter clauses  
and avoid scoring altogether.

{  
"query": {  
"bool": {  
"filter": [  
{  
"exists": {  
"field": "header.create\_time"  
}  
},  
{  
"bool": {  
"should": [  
{  
"term": {  
"[o.dst.name](http://o.dst.name)": "10.61.248.170"  
}  
},  
{  
"term": {  
"[o.sources.name](http://o.sources.name)": "10.61.248.170"  
}  
},  
{  
"term": {  
"[o.src.name](http://o.src.name)": "10.61.248.170"  
}  
}  
]  
}  
}  
]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![jac1241](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@jac1241](https://discuss.elastic.co/u/jac1241)\
**Post date:** [April 20, 2017, 7:57am UTC](https://discuss.elastic.co/t/es-query-returns-results-that-doesnt-not-fit-the-query/82932/3 "2017-04-20T07:57:56Z")

</div>

Thank you for the reply.

I'm not sure i understand why the score would be increased and i get a hit if none of the should terms are matched in the results?

**Edit**  
Moreover, I've inserted the bool under one filter (like in your example) , this gave me an exception.  
I've added another bool and it worked.

```
{
  "query": {
    "bool": {
      "filter": {
        "bool": {
          "must": [
            {
              "exists": {
                "field": "header.create_time"
              }
            }
          ],
          "must_not": [
            
          ],
          "should": [
            {
              "term": {
                "o.dst.name": "10.61.248.170"
              }
            },
            {
              "term": {
                "o.sources.name": "10.61.248.170"
              }
            },
            {
              "term": {
                "o.src.name": "10.61.248.170"
              }
            }
          ]
        }
      }
    }
  },
  "sort": {
    "header.create_time": "desc"
  },
  "size": 1
}

```

This is different than the example provided in ES 2.4 changelog:  
[https://www.elastic.co/guide/en/elasticsearch/reference/2.4/breaking\_20\_query\_dsl\_changes.html#\_literal\_filtered\_literal\_query\_and\_literal\_query\_literal\_filter\_deprecated](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/breaking_20_query_dsl_changes.html#_literal_filtered_literal_query_and_literal_query_literal_filter_deprecated)

What am i missing here?

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 8:07am UTC](https://discuss.elastic.co/t/es-query-returns-results-that-doesnt-not-fit-the-query/82932/4 "2017-05-18T08:07:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
