# Generic search between docs added with Logstash or Filebeat

**URL:** <https://discuss.elastic.co/t/generic-search-between-docs-added-with-logstash-or-filebeat/225080>\
**Category:** Elasticsearch\
**Created:** [March 25, 2020, 11:25pm UTC](https://discuss.elastic.co/t/generic-search-between-docs-added-with-logstash-or-filebeat/225080 "2020-03-25T23:25:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jason26](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason26/32/54948_2.png) [@jason26](https://discuss.elastic.co/u/jason26)\
**Post date:** [March 25, 2020, 11:25pm UTC](https://discuss.elastic.co/t/generic-search-between-docs-added-with-logstash-or-filebeat/225080/1 "2020-03-25T23:25:25Z")

</div>

I don't have control over how the JSON logs I'm trying to search get added to ElasticSearch, but its always Filebeat or Logstash. Something I've noticed, is for a specific field Filebeat has the mapping:

```auto
            "signature": {
              "type": "keyword",
              "ignore_above": 1024
            },

```

but Logstash will use the mapping:

```auto
            "signature": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },

```

So for Logstash users I can use a basic query\_string,

```auto
"query_string": {
    "query": "HUNT"
}

```

and I'll get results where the signature query contains the string "HUNT".

However, for Filebeat I don't get substring matches. It will only match on the complete string, and at least in my test setup I also have to add the "fields" parameter to "query\_string" otherwise I get an error about "field expansion matches too many fields".

Is there a way to structure the query where it will match on a portion of the value, and work across the document indexed by Logstash OR Filebeat?

Thanks!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 26, 2020, 7:34am UTC](https://discuss.elastic.co/t/generic-search-between-docs-added-with-logstash-or-filebeat/225080/2 "2020-03-26T07:34:29Z")

</div>

You need to have a consistent mapping IMO.  
Check that the templates are the same for all index names.

---

<div class="post-metadata">

**Author:** ![jason26](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason26/32/54948_2.png) [@jason26](https://discuss.elastic.co/u/jason26)\
**Post date:** [March 27, 2020, 4:53pm UTC](https://discuss.elastic.co/t/generic-search-between-docs-added-with-logstash-or-filebeat/225080/3 "2020-03-27T16:53:49Z")

</div>

Within a given Elastic Search installation the mapping will be consistent. I'm more curious about making a query statements that will give me what I want without having to probe for the mapping in use.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2020, 4:54pm UTC](https://discuss.elastic.co/t/generic-search-between-docs-added-with-logstash-or-filebeat/225080/4 "2020-04-24T16:54:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
