# How to ignore malformed query for IP property

**URL:** <https://discuss.elastic.co/t/how-to-ignore-malformed-query-for-ip-property/283221>\
**Category:** Elasticsearch\
**Created:** [September 2, 2021, 10:20pm UTC](https://discuss.elastic.co/t/how-to-ignore-malformed-query-for-ip-property/283221 "2021-09-02T22:20:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hZhYNXaCbgkgjyFBJ](https://avatars.discourse-cdn.com/v4/letter/h/d78d45/32.png) [@hZhYNXaCbgkgjyFBJ](https://discuss.elastic.co/u/hZhYNXaCbgkgjyFBJ)\
**Post date:** [September 2, 2021, 10:20pm UTC](https://discuss.elastic.co/t/how-to-ignore-malformed-query-for-ip-property/283221/1 "2021-09-02T22:20:39Z")

</div>

Hi there, I have an Elasticsearch index whose mapping has two properties - one is of type _keyword_ and the other is of type _ip_:

```auto
"mappings": {
            "properties": {
                "user_id": {
                    "type": "keyword"
                },
                "ip_address": {
                    "type": "ip"
                }
           }
}

```

The documents in this index contain valid IP addresses in the _ip\_address_ property. I'd like to issue a search query for this index that searches for both fields with the same query text, as shown below. The search query text (_foo_ in the example below) could either be found in the _user\_id_ property or it could be an IP:

```auto
/* Here, foo is a sample query text - it could be a user ID or an IP */
"query": {
        "bool": {
            "should": [
                {
                    "term": {
                        "user_id": {
                            "value": "foo"
                        }
                    }
                },
                {
                    "term": {
                        "ip_address": {
                            "value": "foo"
                        }
                    }
                }
            ]
        }
    }

```

If I run the above query as-is, I get the error below, which makes sense as _foo_ is not a valid IP. Is there a way I can supply both _user\_id_ and _ip\_address_ properties in the query and avoid this error when the query text is not a valid IP? In case the query text is not a valid IP, the search can simply "ignore" the _ip\_address_ property and just search in the _user\_id_ property.

```auto
    "error": {
        "root_cause": [
            {
                "type": "query_shard_exception",
                "reason": "failed to create query: 'foo' is not an IP string literal.",
            }
        ],
        "type": "search_phase_execution_exception",
       ...

```

I'd like to be able to supply both _user\_id_ and _ip\_address_ properties in the query without worrying about whether the query text is a valid IP or not. Alternatively, I could validate whether the query text is a valid IP and if it isn't, exclude the `ip_address` property in the query - but I'd prefer to not do this if possible.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 3, 2021, 3:12pm UTC](https://discuss.elastic.co/t/how-to-ignore-malformed-query-for-ip-property/283221/2 "2021-09-03T15:12:52Z")

</div>

While this might not work with the `term`, maybe try with the [match query](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/query-dsl-match-query.html) using the `lenient` field. I don't necessarily recommned this though 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2021, 3:12pm UTC](https://discuss.elastic.co/t/how-to-ignore-malformed-query-for-ip-property/283221/3 "2021-10-01T15:12:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
