# How to filter by sub-property?

**URL:** <https://discuss.elastic.co/t/how-to-filter-by-sub-property/12138>\
**Category:** Elasticsearch\
**Created:** [May 27, 2013, 7:05pm UTC](https://discuss.elastic.co/t/how-to-filter-by-sub-property/12138 "2013-05-27T19:05:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rui\_Lopes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rui_lopes/32/2310_2.png) [@Rui\_Lopes](https://discuss.elastic.co/u/Rui_Lopes)\
**Post date:** [May 27, 2013, 7:05pm UTC](https://discuss.elastic.co/t/how-to-filter-by-sub-property/12138/1 "2013-05-27T19:05:49Z")

</div>

Hi,

I have documents alike:

{  
"properties": {  
"MessageId": "9a4e6f25-8493-4aea-9bd1-a5204adc5d70"  
}  
}

How do I make a query by the properties.MessageId?

I've tried:

POST [http://localhost:9200/www/logs/\_search](http://localhost:9200/www/logs/_search)

{  
"query": {  
"filtered": {  
"filter": {  
"term": {  
"properties.MessageId": "9a4e6f25-8493-4aea-9bd1-a5204adc5d70"  
}  
}  
}  
},  
"from": 0,  
"size": 1000  
}

but it does not return any document...

But doing a:

GET  
[http://localhost:9200/www/log/\_search?size=1000&q=properties.MessageId:9a4e6f25-8493-4aea-9bd1-a5204adc5d70](http://localhost:9200/www/log/_search?size=1000&q=properties.MessageId:9a4e6f25-8493-4aea-9bd1-a5204adc5d70)

does work... so how's the correct \_search syntax?

Thanks!

-- RGL

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![simonw\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simonw_2/32/1130_2.png) [@simonw\_2](https://discuss.elastic.co/u/simonw_2)\
**Post date:** [May 28, 2013, 7:51am UTC](https://discuss.elastic.co/t/how-to-filter-by-sub-property/12138/2 "2013-05-28T07:51:35Z")

</div>

the problem here is that your term filter is not passed through an analyzer  
while the query use do below is. So the analyzer that is used splits on the  
dash `-` and that is why you don't find anything. In other words the filter  
looks for "9a4e6f25-8493-4aea-9bd1-a5204adc5d70" as a single string and the  
query does ("9a4e6f25" OR "8493" OR "4aea-9bd1" OR "a5204adc5d70").

I guess in your case you want this field to be "not\_analyzed" in the  
mapping then the term filter works find.

simon  
On Monday, May 27, 2013 9:05:49 PM UTC+2, Rui Lopes wrote:

> Hi,
> 
> I have documents alike:
> 
> {  
> "properties": {  
> "MessageId": "9a4e6f25-8493-4aea-9bd1-a5204adc5d70"  
> }  
> }
> 
> How do I make a query by the properties.MessageId?
> 
> I've tried:
> 
> POST [http://localhost:9200/www/logs/\_search](http://localhost:9200/www/logs/_search)
> 
> {  
> "query": {  
> "filtered": {  
> "filter": {  
> "term": {  
> "properties.MessageId": "9a4e6f25-8493-4aea-9bd1-a5204adc5d70"  
> }  
> }  
> }  
> },  
> "from": 0,  
> "size": 1000  
> }
> 
> but it does not return any document...
> 
> But doing a:
> 
> GET  
> [http://localhost:9200/www/log/\_search?size=1000&q=properties.MessageId:9a4e6f25-8493-4aea-9bd1-a5204adc5d70](http://localhost:9200/www/log/_search?size=1000&q=properties.MessageId:9a4e6f25-8493-4aea-9bd1-a5204adc5d70)
> 
> does work... so how's the correct \_search syntax?
> 
> Thanks!
> 
> -- RGL

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Rui\_Lopes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rui_lopes/32/2310_2.png) [@Rui\_Lopes](https://discuss.elastic.co/u/Rui_Lopes)\
**Post date:** [May 28, 2013, 11:54am UTC](https://discuss.elastic.co/t/how-to-filter-by-sub-property/12138/3 "2013-05-28T11:54:57Z")

</div>

That was it! Thanks!

-- RGL

On Monday, May 27, 2013 8:05:49 PM UTC+1, Rui Lopes wrote:

> Hi,
> 
> I have documents alike:
> 
> {  
> "properties": {  
> "MessageId": "9a4e6f25-8493-4aea-9bd1-a5204adc5d70"  
> }  
> }
> 
> How do I make a query by the properties.MessageId?
> 
> I've tried:
> 
> POST [http://localhost:9200/www/logs/\_search](http://localhost:9200/www/logs/_search)
> 
> {  
> "query": {  
> "filtered": {  
> "filter": {  
> "term": {  
> "properties.MessageId": "9a4e6f25-8493-4aea-9bd1-a5204adc5d70"  
> }  
> }  
> }  
> },  
> "from": 0,  
> "size": 1000  
> }
> 
> but it does not return any document...
> 
> But doing a:
> 
> GET  
> [http://localhost:9200/www/log/\_search?size=1000&q=properties.MessageId:9a4e6f25-8493-4aea-9bd1-a5204adc5d70](http://localhost:9200/www/log/_search?size=1000&q=properties.MessageId:9a4e6f25-8493-4aea-9bd1-a5204adc5d70)
> 
> does work... so how's the correct \_search syntax?
> 
> Thanks!
> 
> -- RGL

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:34am UTC](https://discuss.elastic.co/t/how-to-filter-by-sub-property/12138/4 "2017-07-06T02:34:24Z")

</div>


