# Failure to get results when querying specific field

**URL:** <https://discuss.elastic.co/t/failure-to-get-results-when-querying-specific-field/9172>\
**Category:** Elasticsearch\
**Created:** [September 27, 2012, 3:42pm UTC](https://discuss.elastic.co/t/failure-to-get-results-when-querying-specific-field/9172 "2012-09-27T15:42:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Oded\_Ben\_Ozer](https://avatars.discourse-cdn.com/v4/letter/o/da6949/32.png) [@Oded\_Ben\_Ozer](https://discuss.elastic.co/u/Oded_Ben_Ozer)\
**Post date:** [September 27, 2012, 3:42pm UTC](https://discuss.elastic.co/t/failure-to-get-results-when-querying-specific-field/9172/1 "2012-09-27T15:42:38Z")

</div>

I'm trying to understand a search issue with Graylog2 [http://graylog2.org/](http://graylog2.org/)  
.  
This is an example of how Graylog store data(taken from a successful query)  
:  
{  
"\_id": "Z5y6mxR-QBejYdDI07Ax3A",  
"\_index": "graylog2",  
"\_score": 1.4142135,  
"\_source": {  
"\_Comp": "app",  
"\_Env": "production",  
"\_Short\_path": "some\_file.log",  
"created\_at": 1348465507.609,  
"facility": "logstash-gelf",  
"file":  
"file:/usr/local/logstash/logstash-1.1.1-monolithic.jar!/logstash/outputs/gelf.rb",  
"full\_message": "Stacktrace:\norg.apache.jasper.JasperException:  
Exception in JSP: /jsp/mobile/some\_file.jsp:31",  
"host": "some\_host",  
"level": 7,  
"line": 138,  
"message": "Stacktrace:\norg.apache.jasper.JasperException: Exception  
in JSP: /jsp/mobile/some\_file.jsp:31",  
"streams": [  
"50558899fb7f611830000019"  
]  
},  
"\_type": "message"  
}

This is how Graylog2 tries(and fails) to search for data when I search  
for _JasperException_ (its a full text search as this string is  
not separated by whitespace )

{  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "_message_:_JasperException_"  
}  
},  
{  
"range": {  
"created\_at": {  
"gt": 1348465507,  
"lt": 1348465508  
}  
}  
}  
]  
}  
},  
"size": 5  
}'

But if I change the query\_string from "query": "_message_  
:_JasperException_" to "query": "_\_all_:_JasperException_" it works.  
As the substring 'JasperException' is clearly present in the message field  
I don't understand why the query graylog uses doesn't work.  
Can anybody shed some light on this ?

--

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [September 27, 2012, 4:30pm UTC](https://discuss.elastic.co/t/failure-to-get-results-when-querying-specific-field/9172/2 "2012-09-27T16:30:09Z")

</div>

Can you supply (gist) your mapping? Never used graylog, but  
perhaps allow\_leading\_wildcard is set to false for the message field, but  
not for the \_all field (which I also do not use). It might also not be  
analyzed.

--  
Ivan

On Thu, Sep 27, 2012 at 8:42 AM, Oded Ben-Ozer [oded.benozer@gmail.com](mailto:oded.benozer@gmail.com)wrote:

> I'm trying to understand a search issue with Graylog2[http://graylog2.org/](http://graylog2.org/)  
> .  
> This is an example of how Graylog store data(taken from a successful  
> query) :  
> {  
> "\_id": "Z5y6mxR-QBejYdDI07Ax3A",  
> "\_index": "graylog2",  
> "\_score": 1.4142135,  
> "\_source": {  
> "\_Comp": "app",  
> "\_Env": "production",  
> "\_Short\_path": "some\_file.log",  
> "created\_at": 1348465507.609,  
> "facility": "logstash-gelf",  
> "file":  
> "file:/usr/local/logstash/logstash-1.1.1-monolithic.jar!/logstash/outputs/gelf.rb",  
> "full\_message": "Stacktrace:\norg.apache.jasper.JasperException:  
> Exception in JSP: /jsp/mobile/some\_file.jsp:31",  
> "host": "some\_host",  
> "level": 7,  
> "line": 138,  
> "message": "Stacktrace:\norg.apache.jasper.JasperException: Exception  
> in JSP: /jsp/mobile/some\_file.jsp:31",  
> "streams": [  
> "50558899fb7f611830000019"  
> ]  
> },  
> "\_type": "message"  
> }
> 
> This is how Graylog2 tries(and fails) to search for data when I search  
> for _JasperException_ (its a full text search as this string is  
> not separated by whitespace )
> 
> {  
> "query": {  
> "bool": {  
> "must": [  
> {  
> "query\_string": {  
> "query": "_message_:_JasperException_"  
> }  
> },  
> {  
> "range": {  
> "created\_at": {  
> "gt": 1348465507,  
> "lt": 1348465508  
> }  
> }  
> }  
> ]  
> }  
> },  
> "size": 5  
> }'
> 
> But if I change the query\_string from "query": "_message_  
> :_JasperException_" to "query": "_\_all_:_JasperException_" it works.  
> As the substring 'JasperException' is clearly present in the message field  
> I don't understand why the query graylog uses doesn't work.  
> Can anybody shed some light on this ?
> 
> --

--

---

<div class="post-metadata">

**Author:** ![Oded\_Ben\_Ozer](https://avatars.discourse-cdn.com/v4/letter/o/da6949/32.png) [@Oded\_Ben\_Ozer](https://discuss.elastic.co/u/Oded_Ben_Ozer)\
**Post date:** [September 27, 2012, 5:35pm UTC](https://discuss.elastic.co/t/failure-to-get-results-when-querying-specific-field/9172/3 "2012-09-27T17:35:01Z")

</div>

So, this is the mapping more or less (I removed some of the  
"properties" entries )

curl -XGET '[http://localhost:9200/graylog2/\_mapping?pretty](http://localhost:9200/graylog2/_mapping?pretty)'  
{  
"graylog2" : {  
"message" : {  
"dynamic\_templates" : [ {  
"store\_generic" : {  
"mapping" : {  
"index" : "not\_analyzed"  
},  
"match" : "\*"  
}  
} ],  
"properties" : {  
"\_Comp" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
"\_ZONE" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
"\_message" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
"\_timestampMs" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
"\_verb" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
"created\_at" : {  
"type" : "double",  
"ignore\_malformed" : false  
},

```
    "full_message" : {
      "type" : "string",
      "analyzer" : "whitespace"
    },
    "message" : {
      "type" : "string",
      "analyzer" : "whitespace"
    },

  }

```

And some more info :  
both queries(with 'message' and '\_all' ) take the same amount of time ,\> 5  
minutes , in which time the CPU of the data nodes is very busy.  
Its almost 1TB of text and the indexes are used because I'm using a leading  
wildcard and that field is analyzed using whitespace and I'm searching for  
pattern inside a long 'word'.

On Thu, Sep 27, 2012 at 6:30 PM, Ivan Brusic [ivan@brusic.com](mailto:ivan@brusic.com) wrote:

> Can you supply (gist) your mapping? Never used graylog, but  
> perhaps allow\_leading\_wildcard is set to false for the message field, but  
> not for the \_all field (which I also do not use). It might also not be  
> analyzed.
> 
> --  
> Ivan
> 
> On Thu, Sep 27, 2012 at 8:42 AM, Oded Ben-Ozer [oded.benozer@gmail.com](mailto:oded.benozer@gmail.com)wrote:
> 
> > I'm trying to understand a search issue with Graylog2[http://graylog2.org/](http://graylog2.org/)  
> > .  
> > This is an example of how Graylog store data(taken from a successful  
> > query) :  
> > {  
> > "\_id": "Z5y6mxR-QBejYdDI07Ax3A",  
> > "\_index": "graylog2",  
> > "\_score": 1.4142135,  
> > "\_source": {  
> > "\_Comp": "app",  
> > "\_Env": "production",  
> > "\_Short\_path": "some\_file.log",  
> > "created\_at": 1348465507.609,  
> > "facility": "logstash-gelf",  
> > "file":  
> > "file:/usr/local/logstash/logstash-1.1.1-monolithic.jar!/logstash/outputs/gelf.rb",  
> > "full\_message": "Stacktrace:\norg.apache.jasper.JasperException:  
> > Exception in JSP: /jsp/mobile/some\_file.jsp:31",  
> > "host": "some\_host",  
> > "level": 7,  
> > "line": 138,  
> > "message": "Stacktrace:\norg.apache.jasper.JasperException: Exception  
> > in JSP: /jsp/mobile/some\_file.jsp:31",  
> > "streams": [  
> > "50558899fb7f611830000019"  
> > ]  
> > },  
> > "\_type": "message"  
> > }
> > 
> > This is how Graylog2 tries(and fails) to search for data when I search  
> > for _JasperException_ (its a full text search as this string is  
> > not separated by whitespace )
> > 
> > {  
> > "query": {  
> > "bool": {  
> > "must": [  
> > {  
> > "query\_string": {  
> > "query": "_message_:_JasperException_"  
> > }  
> > },  
> > {  
> > "range": {  
> > "created\_at": {  
> > "gt": 1348465507,  
> > "lt": 1348465508  
> > }  
> > }  
> > }  
> > ]  
> > }  
> > },  
> > "size": 5  
> > }'
> > 
> > But if I change the query\_string from "query": "_message_  
> > :_JasperException_" to "query": "_\_all_:_JasperException_" it works.  
> > As the substring 'JasperException' is clearly present in the message  
> > field I don't understand why the query graylog uses doesn't work.  
> > Can anybody shed some light on this ?
> > 
> > --
> 
> --

--

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [September 27, 2012, 6:30pm UTC](https://discuss.elastic.co/t/failure-to-get-results-when-querying-specific-field/9172/4 "2012-09-27T18:30:13Z")

</div>

The whitespace analyzer will not lowercase tokens, while the query\_string  
parser will. Perhaps setting lowercase\_expanded\_terms to false might help.

--  
Ivan

On Thu, Sep 27, 2012 at 10:35 AM, Oded Ben-Ozer [oded.benozer@gmail.com](mailto:oded.benozer@gmail.com)wrote:

> So, this is the mapping more or less (I removed some of the  
> "properties" entries )
> 
> curl -XGET '[http://localhost:9200/graylog2/\_mapping?pretty](http://localhost:9200/graylog2/_mapping?pretty)'  
> {  
> "graylog2" : {  
> "message" : {  
> "dynamic\_templates" : [ {  
> "store\_generic" : {  
> "mapping" : {  
> "index" : "not\_analyzed"  
> },  
> "match" : "\*"  
> }  
> } ],  
> "properties" : {  
> "\_Comp" : {  
> "type" : "string",  
> "index" : "not\_analyzed"  
> },  
> "\_ZONE" : {  
> "type" : "string",  
> "index" : "not\_analyzed"  
> },  
> "\_message" : {  
> "type" : "string",  
> "index" : "not\_analyzed"  
> },  
> "\_timestampMs" : {  
> "type" : "string",  
> "index" : "not\_analyzed"  
> },  
> "\_verb" : {  
> "type" : "string",  
> "index" : "not\_analyzed"  
> },  
> "created\_at" : {  
> "type" : "double",  
> "ignore\_malformed" : false  
> },
> 
> ```
> "full_message" : {
> "type" : "string",
> "analyzer" : "whitespace"
> },
> "message" : {
> "type" : "string",
> "analyzer" : "whitespace"
> },
> 
> }
> 
> ```
> 
> And some more info :  
> both queries(with 'message' and '\_all' ) take the same amount of time ,\> 5  
> minutes , in which time the CPU of the data nodes is very busy.  
> Its almost 1TB of text and the indexes are used because I'm using a  
> leading wildcard and that field is analyzed using whitespace and I'm  
> searching for pattern inside a long 'word'.
> 
> On Thu, Sep 27, 2012 at 6:30 PM, Ivan Brusic [ivan@brusic.com](mailto:ivan@brusic.com) wrote:
> 
> > Can you supply (gist) your mapping? Never used graylog, but  
> > perhaps allow\_leading\_wildcard is set to false for the message field, but  
> > not for the \_all field (which I also do not use). It might also not be  
> > analyzed.
> > 
> > --  
> > Ivan
> > 
> > On Thu, Sep 27, 2012 at 8:42 AM, Oded Ben-Ozer [oded.benozer@gmail.com](mailto:oded.benozer@gmail.com)wrote:
> > 
> > > I'm trying to understand a search issue with Graylog2[http://graylog2.org/](http://graylog2.org/)  
> > > .  
> > > This is an example of how Graylog store data(taken from a successful  
> > > query) :  
> > > {  
> > > "\_id": "Z5y6mxR-QBejYdDI07Ax3A",  
> > > "\_index": "graylog2",  
> > > "\_score": 1.4142135,  
> > > "\_source": {  
> > > "\_Comp": "app",  
> > > "\_Env": "production",  
> > > "\_Short\_path": "some\_file.log",  
> > > "created\_at": 1348465507.609,  
> > > "facility": "logstash-gelf",  
> > > "file":  
> > > "file:/usr/local/logstash/logstash-1.1.1-monolithic.jar!/logstash/outputs/gelf.rb",  
> > > "full\_message": "Stacktrace:\norg.apache.jasper.JasperException:  
> > > Exception in JSP: /jsp/mobile/some\_file.jsp:31",  
> > > "host": "some\_host",  
> > > "level": 7,  
> > > "line": 138,  
> > > "message": "Stacktrace:\norg.apache.jasper.JasperException:  
> > > Exception in JSP: /jsp/mobile/some\_file.jsp:31",  
> > > "streams": [  
> > > "50558899fb7f611830000019"  
> > > ]  
> > > },  
> > > "\_type": "message"  
> > > }
> > > 
> > > This is how Graylog2 tries(and fails) to search for data when I search  
> > > for _JasperException_ (its a full text search as this string is  
> > > not separated by whitespace )
> > > 
> > > {  
> > > "query": {  
> > > "bool": {  
> > > "must": [  
> > > {  
> > > "query\_string": {  
> > > "query": "_message_:_JasperException_"  
> > > }  
> > > },  
> > > {  
> > > "range": {  
> > > "created\_at": {  
> > > "gt": 1348465507,  
> > > "lt": 1348465508  
> > > }  
> > > }  
> > > }  
> > > ]  
> > > }  
> > > },  
> > > "size": 5  
> > > }'
> > > 
> > > But if I change the query\_string from "query": "_message_  
> > > :_JasperException_" to "query": "_\_all_:_JasperException_" it works.  
> > > As the substring 'JasperException' is clearly present in the message  
> > > field I don't understand why the query graylog uses doesn't work.  
> > > Can anybody shed some light on this ?
> > > 
> > > --
> > 
> > --
> 
> --

--

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:11am UTC](https://discuss.elastic.co/t/failure-to-get-results-when-querying-specific-field/9172/5 "2017-07-06T03:11:08Z")

</div>


