# Filtered query returning unwanted results

**URL:** <https://discuss.elastic.co/t/filtered-query-returning-unwanted-results/17626>\
**Category:** Elasticsearch\
**Created:** [May 20, 2014, 3:43pm UTC](https://discuss.elastic.co/t/filtered-query-returning-unwanted-results/17626 "2014-05-20T15:43:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yarin](https://avatars.discourse-cdn.com/v4/letter/y/6a8cbe/32.png) [@yarin](https://discuss.elastic.co/u/yarin)\
**Post date:** [May 20, 2014, 3:43pm UTC](https://discuss.elastic.co/t/filtered-query-returning-unwanted-results/17626/1 "2014-05-20T15:43:05Z")

</div>

Hello,

We've been using elasticsearch for a while now in my company and we  
recently discovered that certain queries are returning unwanted results.

I've created a gist [https://gist.github.com/yairnm/14bca137879212cf64f2](https://gist.github.com/yairnm/14bca137879212cf64f2)that  
recreates the problem on a newly index without mapping

The use case is quite simple, I have the following document:  
{  
"collected" : {  
"etag" : ""KOlSfwGpwASvJB5lLGkjWDc36DY/R9KZ-VQJQP18W3NNaJcSpQlPgaY"",  
"is\_success" : true,  
"action\_type" : "password"  
},  
"timestamp" : 1399820164000,  
"instanceId" : 0,  
"collected\_event" : true,  
"tenantId" : 2,  
"eventType" : 589825  
}

And I try to run a filtered query, that has terms and query\_string:  
{  
"filter" : {  
"and" : [{  
"term" : {  
"tenantId" : 2  
}  
}, {  
"not" : {  
"term" : {  
"eventType" : 589844  
}  
}  
}, {  
"not" : {  
"term" : {  
"collected\_event" : false  
}  
}  
}  
]  
},  
"query" : {  
"query\_string" : {  
"query" : ""sfoun"",  
"lenient" : true,  
"fields" : ["collected.\*"]  
}  
}  
}

I expect the filtered query to yield zero results since the document  
doesn't meet with the query\_string.

You can try and replace the text in query\_string to anything you like but  
still get the results.  
My guess is that I'm missing out something or I don't fully understand how  
queries work.

Thanks in advance,  
Yarin.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0f1bdb3c-2c8a-48ab-8572-0b6bba71302e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0f1bdb3c-2c8a-48ab-8572-0b6bba71302e%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![yarin](https://avatars.discourse-cdn.com/v4/letter/y/6a8cbe/32.png) [@yarin](https://discuss.elastic.co/u/yarin)\
**Post date:** [May 20, 2014, 3:44pm UTC](https://discuss.elastic.co/t/filtered-query-returning-unwanted-results/17626/2 "2014-05-20T15:44:54Z")

</div>

One side note, if I change the query\_string fields to be either  
'collected.etag' or 'collected.action\_type' the document is filtered  
properly.  
If I include 'collected.'is\_success' I still get the document.

On Tuesday, May 20, 2014 6:43:05 PM UTC+3, Yarin Miran wrote:

> Hello,
> 
> We've been using elasticsearch for a while now in my company and we  
> recently discovered that certain queries are returning unwanted results.
> 
> I've created a gist [https://gist.github.com/yairnm/14bca137879212cf64f2](https://gist.github.com/yairnm/14bca137879212cf64f2)that  
> recreates the problem on a newly index without mapping
> 
> The use case is quite simple, I have the following document:  
> {  
> "collected" : {  
> "etag" : ""KOlSfwGpwASvJB5lLGkjWDc36DY/R9KZ-VQJQP18W3NNaJcSpQlPgaY"",  
> "is\_success" : true,  
> "action\_type" : "password"  
> },  
> "timestamp" : 1399820164000,  
> "instanceId" : 0,  
> "collected\_event" : true,  
> "tenantId" : 2,  
> "eventType" : 589825  
> }
> 
> And I try to run a filtered query, that has terms and query\_string:  
> {  
> "filter" : {  
> "and" : [{  
> "term" : {  
> "tenantId" : 2  
> }  
> }, {  
> "not" : {  
> "term" : {  
> "eventType" : 589844  
> }  
> }  
> }, {  
> "not" : {  
> "term" : {  
> "collected\_event" : false  
> }  
> }  
> }  
> ]  
> },  
> "query" : {  
> "query\_string" : {  
> "query" : ""sfoun"",  
> "lenient" : true,  
> "fields" : ["collected.\*"]  
> }  
> }  
> }
> 
> I expect the filtered query to yield zero results since the document  
> doesn't meet with the query\_string.
> 
> You can try and replace the text in query\_string to anything you like but  
> still get the results.  
> My guess is that I'm missing out something or I don't fully understand how  
> queries work.
> 
> Thanks in advance,  
> Yarin.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/72ca01a8-2a49-4588-ad7b-65f58b68504f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/72ca01a8-2a49-4588-ad7b-65f58b68504f%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:28am UTC](https://discuss.elastic.co/t/filtered-query-returning-unwanted-results/17626/3 "2017-07-06T01:28:06Z")

</div>


