# Filtered And Query

**URL:** <https://discuss.elastic.co/t/filtered-and-query/3278>\
**Category:** Elasticsearch\
**Created:** [August 30, 2010, 11:30pm UTC](https://discuss.elastic.co/t/filtered-and-query/3278 "2010-08-30T23:30:29Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ted\_Karmel](https://avatars.discourse-cdn.com/v4/letter/t/e9a140/32.png) [@Ted\_Karmel](https://discuss.elastic.co/u/Ted_Karmel)\
**Post date:** [August 30, 2010, 11:30pm UTC](https://discuss.elastic.co/t/filtered-and-query/3278/1 "2010-08-30T23:30:29Z")

</div>

Hi,

The documentation is very clear and comprehensive. But I run into an  
error when trying to do a query with an AND filter for values on  
different keys. I do a POST on  
[http://localhost:9200/twitter/tweet/\_search](http://localhost:9200/twitter/tweet/_search) I base myself on the  
following documentation :  
[http://www.elasticsearch.com/docs/elasticsearch/rest\_api/query\_dsl/filtered\_query/](http://www.elasticsearch.com/docs/elasticsearch/rest_api/query_dsl/filtered_query/)

The JSON of the query I make is :

{  
"filtered" : {  
"query" : {  
"term" : { "user" : "kimchy" }  
},  
"filter" : {  
"and" : {  
"term" : { "message" : "search" }  
}  
}  
}  
}

The error message I get starts with :  
{"error":"SearchPhaseExecutionException[Failed to execute phase  
[query], total failure; shardFailures  
{[6eaf3f5a-f1da-4c5b-9af6-cb1e146ed655][twitter][3]:  
SearchParseException[[twitter][3]: query[null],from[-1],size[-1]:  
Parse Failure [Failed to parse

Any suggestions to overcome my stupidity?

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [August 31, 2010, 8:17am UTC](https://discuss.elastic.co/t/filtered-and-query/3278/2 "2010-08-31T08:17:13Z")

</div>

The below json just realtes to the query part of the search request. You  
need to wrap it in a "query" element, for example:

{  
"query" : {  
"filtered" " {...}  
},  
"from" : ...  
}

(I put the from there to show that there are other things a search request  
can have, such as from/size, facets and so on, and thats why there is the  
"query" element).

-shay.banon

On Tue, Aug 31, 2010 at 2:30 AM, Ted Karmel [ted.karmel@gmail.com](mailto:ted.karmel@gmail.com) wrote:

> Hi,
> 
> The documentation is very clear and comprehensive. But I run into an  
> error when trying to do a query with an AND filter for values on  
> different keys. I do a POST on  
> [http://localhost:9200/twitter/tweet/\_search](http://localhost:9200/twitter/tweet/_search) I base myself on the  
> following documentation :
> 
> [http://www.elasticsearch.com/docs/elasticsearch/rest\_api/query\_dsl/filtered\_query/](http://www.elasticsearch.com/docs/elasticsearch/rest_api/query_dsl/filtered_query/)
> 
> The JSON of the query I make is :
> 
> {  
> "filtered" : {  
> "query" : {  
> "term" : { "user" : "kimchy" }  
> },  
> "filter" : {  
> "and" : {  
> "term" : { "message" : "search" }  
> }  
> }  
> }  
> }
> 
> The error message I get starts with :  
> {"error":"SearchPhaseExecutionException[Failed to execute phase  
> [query], total failure; shardFailures  
> {[6eaf3f5a-f1da-4c5b-9af6-cb1e146ed655][twitter][3]:  
> SearchParseException[[twitter][3]: query[null],from[-1],size[-1]:  
> Parse Failure [Failed to parse
> 
> Any suggestions to overcome my stupidity?

---

<div class="post-metadata">

**Author:** ![Ted\_Karmel](https://avatars.discourse-cdn.com/v4/letter/t/e9a140/32.png) [@Ted\_Karmel](https://discuss.elastic.co/u/Ted_Karmel)\
**Post date:** [August 31, 2010, 10:47am UTC](https://discuss.elastic.co/t/filtered-and-query/3278/3 "2010-08-31T10:47:16Z")

</div>

Thank you Shay for the prompt reply. Wrapping in a query element  
makes design sense when considering this allows other useful  
parameters to be incorporated (like from/size makes pagination a  
cinch).

I no longer get an error. But I do not get the result I expect. I am  
searching for all the tweets by the user kimchy that contain the term  
"search" in the message. There is such a tweet. But, when I make the  
search request with the following JSON, I get no hits as a return:

{  
"query": {  
"filtered" : {  
"query" : {  
"term" : { "user" : "kimchy" }  
},  
"filter" : {  
"and" : {  
"query": {  
"term" : { "message" : "whatever" }  
} }  
}  
}  
}  
}

On Tue, Aug 31, 2010 at 10:17 AM, Shay Banon  
[shay.banon@elasticsearch.com](mailto:shay.banon@elasticsearch.com) wrote:

> The below json just realtes to the query part of the search request. You  
> need to wrap it in a "query" element, for example:  
> {  
> "query" : {  
> "filtered" " {...}  
> },  
> "from" : ...  
> }
> 
> (I put the from there to show that there are other things a search request  
> can have, such as from/size, facets and so on, and thats why there is the  
> "query" element).  
> -shay.banon  
> On Tue, Aug 31, 2010 at 2:30 AM, Ted Karmel [ted.karmel@gmail.com](mailto:ted.karmel@gmail.com) wrote:
> 
> > Hi,
> > 
> > The documentation is very clear and comprehensive. But I run into an  
> > error when trying to do a query with an AND filter for values on  
> > different keys. I do a POST on  
> > [http://localhost:9200/twitter/tweet/\_search](http://localhost:9200/twitter/tweet/_search) I base myself on the  
> > following documentation :
> > 
> > [http://www.elasticsearch.com/docs/elasticsearch/rest\_api/query\_dsl/filtered\_query/](http://www.elasticsearch.com/docs/elasticsearch/rest_api/query_dsl/filtered_query/)
> > 
> > The JSON of the query I make is :
> > 
> > {  
> > "filtered" : {  
> > "query" : {  
> > "term" : { "user" : "kimchy" }  
> > },  
> > "filter" : {  
> > "and" : {  
> > "term" : { "message" : "search" }  
> > }  
> > }  
> > }  
> > }
> > 
> > The error message I get starts with :  
> > {"error":"SearchPhaseExecutionException[Failed to execute phase  
> > [query], total failure; shardFailures  
> > {[6eaf3f5a-f1da-4c5b-9af6-cb1e146ed655][twitter][3]:  
> > SearchParseException[[twitter][3]: query[null],from[-1],size[-1]:  
> > Parse Failure [Failed to parse
> > 
> > Any suggestions to overcome my stupidity?

---

<div class="post-metadata">

**Author:** ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)\
**Post date:** [August 31, 2010, 11:07am UTC](https://discuss.elastic.co/t/filtered-and-query/3278/4 "2010-08-31T11:07:33Z")

</div>

On Tue, 2010-08-31 at 12:47 +0200, Ted Karmel wrote:

> I no longer get an error. But I do not get the result I expect. I am  
> searching for all the tweets by the user kimchy that contain the term  
> "search" in the message. There is such a tweet. But, when I make the  
> search request with the following JSON, I get no hits as a return:

Try this:

{  
"query": {  
"filtered" : {  
"query" : {  
"field": {  
"message": "whatever"  
}  
},  
"filter" : {  
"term" : { "user" : "kimchy" }  
}  
}  
}  
}

clint

---

<div class="post-metadata">

**Author:** ![Paul\_Loy](https://avatars.discourse-cdn.com/v4/letter/p/ad7895/32.png) [@Paul\_Loy](https://discuss.elastic.co/u/Paul_Loy)\
**Post date:** [August 31, 2010, 11:12am UTC](https://discuss.elastic.co/t/filtered-and-query/3278/5 "2010-08-31T11:12:29Z")

</div>

is that because the query on the "message" field is for "whatever" rather  
than "search"?

On Tue, Aug 31, 2010 at 12:07 PM, Clinton Gormley  
[clinton@iannounce.co.uk](mailto:clinton@iannounce.co.uk)wrote:

> On Tue, 2010-08-31 at 12:47 +0200, Ted Karmel wrote:
> 
> > I no longer get an error. But I do not get the result I expect. I am  
> > searching for all the tweets by the user kimchy that contain the term  
> > "search" in the message. There is such a tweet. But, when I make the  
> > search request with the following JSON, I get no hits as a return:
> 
> Try this:
> 
> {  
> "query": {  
> "filtered" : {  
> "query" : {  
> "field": {  
> \* "message": "whatever"\*  
> }  
> },  
> "filter" : {  
> "term" : { "user" : "kimchy" }  
> }  
> }  
> }  
> }
> 
> clint

## --

Paul Loy  
[paul@keteracel.com](mailto:paul@keteracel.com)  
[http://www.keteracel.com/paul](http://www.keteracel.com/paul)

---

<div class="post-metadata">

**Author:** ![Ted\_Karmel](https://avatars.discourse-cdn.com/v4/letter/t/e9a140/32.png) [@Ted\_Karmel](https://discuss.elastic.co/u/Ted_Karmel)\
**Post date:** [August 31, 2010, 11:35am UTC](https://discuss.elastic.co/t/filtered-and-query/3278/6 "2010-08-31T11:35:31Z")

</div>

Hi Clint,

Thank you very much for that. It works! But not sure how... field  
replaces the AND filter? Would it work for more than two fields? In  
any case, thanks...

Paul,  
The term whatever was just included afterwards to troubleshoot (no  
such tweet includes that term). I just copied and pasted the JSON.  
My bad... 🙂

On Tue, Aug 31, 2010 at 1:12 PM, Paul Loy [keteracel@gmail.com](mailto:keteracel@gmail.com) wrote:

> is that because the query on the "message" field is for "whatever" rather  
> than "search"?
> 
> On Tue, Aug 31, 2010 at 12:07 PM, Clinton Gormley [clinton@iannounce.co.uk](mailto:clinton@iannounce.co.uk)  
> wrote:
> 
> > On Tue, 2010-08-31 at 12:47 +0200, Ted Karmel wrote:
> > 
> > > I no longer get an error. But I do not get the result I expect. I am  
> > > searching for all the tweets by the user kimchy that contain the term  
> > > "search" in the message. There is such a tweet. But, when I make the  
> > > search request with the following JSON, I get no hits as a return:
> > 
> > Try this:
> > 
> > {  
> > "query": {  
> > "filtered" : {  
> > "query" : {  
> > "field": {  
> > "message": "whatever"  
> > }  
> > },  
> > "filter" : {  
> > "term" : { "user" : "kimchy" }  
> > }  
> > }  
> > }  
> > }
> > 
> > clint
> 
> ## --
> 
> Paul Loy  
> [paul@keteracel.com](mailto:paul@keteracel.com)  
> [http://www.keteracel.com/paul](http://www.keteracel.com/paul)

---

<div class="post-metadata">

**Author:** ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)\
**Post date:** [August 31, 2010, 11:46am UTC](https://discuss.elastic.co/t/filtered-and-query/3278/7 "2010-08-31T11:46:48Z")

</div>

On Tue, 2010-08-31 at 13:35 +0200, Ted Karmel wrote:

> Hi Clint,
> 
> Thank you very much for that. It works! But not sure how... field  
> replaces the AND filter? Would it work for more than two fields? In  
> any case, thanks...

No, the query in this case is "show me all docs which contain the word  
'whatever' in the 'message' field"

You could equally have used:

"query: {  
"query\_string": {  
"query": "whatever",  
"default\_field": "message"  
}  
}

It's important to put the part that affects the relevance (or score) of  
the query into the 'query' bit. So if you searched for "foo bar" then  
docs with "foo" and "bar" would be more relevant than docs with just  
"foo" or just "bar".

Then, you only want posts by the user 'kimchy'. So that is a filter. It  
doesn't need to be scored. Either, this post is by kimchy, or it isn't.

So you put that into the filter. Filters are more efficient, because  
they don't need to be scored, and they can be cached.

You don't need an 'and' filter in this case, because you only have one  
filter.

If you wanted to say:

filter by:

- user == kimchy
- AND created \> '2010-01-01'

then you would use an 'and' filter.

clint

---

<div class="post-metadata">

**Author:** ![Ted\_Karmel](https://avatars.discourse-cdn.com/v4/letter/t/e9a140/32.png) [@Ted\_Karmel](https://discuss.elastic.co/u/Ted_Karmel)\
**Post date:** [August 31, 2010, 3:13pm UTC](https://discuss.elastic.co/t/filtered-and-query/3278/8 "2010-08-31T15:13:02Z")

</div>

Thanks Clint. That info is quite useful - especially for how I will  
set up schemas later on.

Cheers

On Tue, Aug 31, 2010 at 1:46 PM, Clinton Gormley  
[clinton@iannounce.co.uk](mailto:clinton@iannounce.co.uk) wrote:

> On Tue, 2010-08-31 at 13:35 +0200, Ted Karmel wrote:
> 
> > Hi Clint,
> > 
> > Thank you very much for that. It works! But not sure how... field  
> > replaces the AND filter? Would it work for more than two fields? In  
> > any case, thanks...
> 
> No, the query in this case is "show me all docs which contain the word  
> 'whatever' in the 'message' field"
> 
> You could equally have used:
> 
> "query: {  
> "query\_string": {  
> "query": "whatever",  
> "default\_field": "message"  
> }  
> }
> 
> It's important to put the part that affects the relevance (or score) of  
> the query into the 'query' bit. So if you searched for "foo bar" then  
> docs with "foo" and "bar" would be more relevant than docs with just  
> "foo" or just "bar".
> 
> Then, you only want posts by the user 'kimchy'. So that is a filter. It  
> doesn't need to be scored. Either, this post is by kimchy, or it isn't.
> 
> So you put that into the filter. Filters are more efficient, because  
> they don't need to be scored, and they can be cached.
> 
> You don't need an 'and' filter in this case, because you only have one  
> filter.
> 
> If you wanted to say:
> 
> filter by:
> 
> - user == kimchy
> - AND created \> '2010-01-01'
> 
> then you would use an 'and' filter.
> 
> clint

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:20am UTC](https://discuss.elastic.co/t/filtered-and-query/3278/9 "2017-07-06T04:20:03Z")

</div>


