# How to force elastic to make an and between should and filter (not an or query)

**URL:** <https://discuss.elastic.co/t/how-to-force-elastic-to-make-an-and-between-should-and-filter-not-an-or-query/125983>\
**Category:** Elasticsearch\
**Created:** [March 28, 2018, 6:21pm UTC](https://discuss.elastic.co/t/how-to-force-elastic-to-make-an-and-between-should-and-filter-not-an-or-query/125983 "2018-03-28T18:21:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Michael\_Gang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_michael_gang/32/114738_2.png) [@David\_Michael\_Gang](https://discuss.elastic.co/u/David_Michael_Gang)\
**Post date:** [March 28, 2018, 6:21pm UTC](https://discuss.elastic.co/t/how-to-force-elastic-to-make-an-and-between-should-and-filter-not-an-or-query/125983/1 "2018-03-28T18:21:18Z")

</div>

Hi,  
I want to get a message on all failed pods in the last 10 minutes.  
What i am getting now is all the messages of the pods failed or messages in the last 10 minutes.  
How can this be fixed. I tried to understand how i can apply the data [from the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/6.1/query-filter-context.html) here but without success. Here is the json of my watcher.  
Thanks a lot!

```
{
  "trigger": {
"schedule": {
  "interval": "5m"
}
  },
  "input": {
"search": {
  "request": {
    "search_type": "query_then_fetch",
    "indices": [
      "metricbeat-6.2.2-*"
    ],
    "types": [],
    "body": {
      "size": 0,
      "query": {
        "bool": {
          "should": [
            {
              "terms": {
                "kubernetes.pod.status.phase": [
                  "failed"
                ]
              }
            },
            {
              "terms": {
                "kubernetes.pod.status.ready": [
                  "failed"
                ]
              }
            }
          ],
          "filter": [
            {
              "range": {
                "@timestamp": {
                  "gte": "now-600s"
                }
              }
            }
          ]
            
        }
      }
    }
  }
}
  },
  "condition": {
"compare": {
  "ctx.payload.hits.total": {
    "gte": 2
  }
}
  },
  "actions": {
"my-logging-action": {
  "logging": {
    "level": "info",
    "text": "There are {{ctx.payload.hits.total}} messages that pods have problems."
  }
}
  }
}
```

---

<div class="post-metadata">

**Author:** ![David\_Michael\_Gang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_michael_gang/32/114738_2.png) [@David\_Michael\_Gang](https://discuss.elastic.co/u/David_Michael_Gang)\
**Post date:** [March 28, 2018, 6:49pm UTC](https://discuss.elastic.co/t/how-to-force-elastic-to-make-an-and-between-should-and-filter-not-an-or-query/125983/2 "2018-03-28T18:49:02Z")

</div>

Update: This is a solution which worked for me:  
The key was that bool can be nested in should and must. Somehow i did not get this when reading the documentation

```
{
  "trigger": {
    "schedule": {
      "interval": "5m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "metricbeat-6.2.2-*"
        ],
        "types": [],
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "must": [
                {
                  "bool": {
                    "should": [
                      {
                        "terms": {
                          "kubernetes.pod.status.phase": [
                            "failed"
                          ]
                        }
                      },
                      {
                        "terms": {
                          "kubernetes.pod.status.ready": [
                            "failed"
                          ]
                        }
                      }
                    ]
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-10m"
                    }
                  }
                }
              ]
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 2
      }
    }
  },
  "actions": {
    "my-logging-action": {
      "logging": {
        "level": "info",
        "text": "There are {{ctx.payload.hits.total}} messages that pods have problems."
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2018, 6:49pm UTC](https://discuss.elastic.co/t/how-to-force-elastic-to-make-an-and-between-should-and-filter-not-an-or-query/125983/3 "2018-04-25T18:49:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
