# How to query multiple fileds in Kibana

**URL:** <https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611>\
**Category:** Elasticsearch\
**Tags:** kql-kibana-query-language\
**Created:** [June 8, 2022, 12:34am UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611 "2022-06-08T00:34:46Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 12:34am UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/1 "2022-06-08T00:34:46Z")

</div>

Hi,  
I am trying to query kibana for multiple fields where the servicename is serviceworker and the correlationId is one of many. My understanding is using terms is the best option here but I cannot get this query to work regardless of where I place the condition.

```auto
GET unity/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2020-04-01",
              "lte": "2022-05-01"
            }
          }
        }
      ], 
      "should": [
        {
          "match": {
            "serviceName": "Serviceworker"
          }
        }
      ],
      "must": [
        {
          "terms": {
            "correlationId": [
              "085178d5-e782-4ad9-a56a-5c08d906686d",
              "01b4ac00-1c67-4056-a571-455f9fd1c296"
            ]
            
          }
          
        }
        
        
      ]
    }
    
  }
  
}

```

What am I missing here?  
Thank you

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 9:06am UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/2 "2022-06-08T09:06:13Z")

</div>

Hi,  
Could explain more about "I cannot get this query to work"?  
What i the result (or error) and what is your expected result?

In addition, the `terms` query is query for multiple "terms" and what do you mean by "query multiple **fields**"?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [June 8, 2022, 9:08am UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/3 "2022-06-08T09:08:21Z")

</div>

If there are no results returned, I suggest to narrow the problem by removing parts of the query, does it work with with the @timestamp range filter? adding the should match for the serviceName ...

---

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 11:57am UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/4 "2022-06-08T11:57:30Z")

</div>

Hi Tom,  
What I meant is I am not getting any results but if I search these records in KIbana using  
`correlationId :"085178d5-e782-4ad9-a56a-5c08d906686d" AND serviceName: "Serviceworker"` I get the expected document. By multiple fields I meant I wanted to get all the documents with `serviceName: "Serviceworker" ` and correlationId is one of the of the items in specified in the terms. Like an join in SQL.  
Running this query in the devTools, returns

```auto
{
  "took" : 2613,
  "timed_out" : false,
  "_shards" : {
    "total" : 110,
    "successful" : 110,
    "skipped" : 105,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  }
}

```

---

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 11:59am UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/5 "2022-06-08T11:59:27Z")

</div>

Hi Matw,  
I tried removing the date range completely and I still didn't get any results. I even reduced it to one item in the terms that I know exists but even that returned nothing

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 2:08pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/6 "2022-06-08T14:08:49Z")

</div>

> [@dev9](#):
>
> Like an join in SQL.

It's confusing. I suppose the condition you explained is "WHERE \*\*\* AND \*\*\*" and not JOIN.

Anyway, your query looks ok to query `correlationId :"085178d5-e782-4ad9-a56a-5c08d906686d" AND serviceName: "Serviceworker"`. Something is strange. Have you checked each single query in should and must query:

```auto
{
          "match": {
            "serviceName": "Serviceworker"
          }
        }

```

and

```auto
{
          "terms": {
            "correlationId": [
              "085178d5-e782-4ad9-a56a-5c08d906686d",
              "01b4ac00-1c67-4056-a571-455f9fd1c296"
            ]
            
          }
          
        }

```

work as you intended?

---

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 2:24pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/7 "2022-06-08T14:24:42Z")

</div>

I am sorry, I don't understand what you mean by `Have you checked each single query in should and must query`. I have confirmed these documents exists. If I switch the query like

```auto
GET unity/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2020-04-01",
              "lte": "2022-07-01"
            }
          }
        }
      ], 
      "must": [
        {
          "match": {
            "serviceName": "Serviceworker"
          }
        }
      ],
      "should": [
        {
          "terms": {
            "correlationId": [
              "085178d5-e782-4ad9-a56a-5c08d906686d",
              "01b4ac00-1c67-4056-a571-455f9fd1c296"
            ]
            
          }
          
        }
        
        
      ]
    }
    
  }
  
}

```

This switch causes the query to return documents with servicename = serviceworker but the correlationIds are not correct

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 2:28pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/8 "2022-06-08T14:28:32Z")

</div>

How about

```auto
GET unity/_search
{
  "query": {
      "match": {
        "serviceName": "Serviceworker"
    }  
  }
}

```

and

```auto
GET unity/_search
{
"query":{
          "terms": {
            "correlationId": [
              "085178d5-e782-4ad9-a56a-5c08d906686d",
              "01b4ac00-1c67-4056-a571-455f9fd1c296"
            ]
            
          }
          
        }
}

```

?

Then check both

```auto
GET unity/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2020-04-01",
              "lte": "2022-07-01"
            }
          }
        }
      ], 
      "must": [
        {
          "match": {
            "serviceName": "Serviceworker"
          }
        }
      ]
    }
    
  }
  
}

```

and

```auto
GET unity/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2020-04-01",
              "lte": "2022-07-01"
            }
          }
        }
      ], 
      "should": [
        {
          "terms": {
            "correlationId": [
              "085178d5-e782-4ad9-a56a-5c08d906686d",
              "01b4ac00-1c67-4056-a571-455f9fd1c296"
            ]
            
          }
          
        }
        
        
      ]
    }
    
  }
  
}

```

work well.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 2:34pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/9 "2022-06-08T14:34:33Z")

</div>

The first query worked well with my test.

```auto
PUT test_multiple_fields_query
{
  "mappings": {
    "properties": {
      "correlationId":{
      "type":"keyword"
    },
    
    "serviceName":{
      "type":"keyword"
    }
    }
    
  }
}

POST test_multiple_fields_query/_doc
{
  "@timestamp": "2021-01-01",
  "serviceName": "Serviceworker",
  "correlationId": 
              "085178d5-e782-4ad9-a56a-5c08d906686d"
}

GET test_multiple_fields_query/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2020-04-01",
              "lte": "2022-07-01"
            }
          }
        }
      ], 
      "must": [
        {
          "match": {
            "serviceName": "Serviceworker"
          }
        }
      ],
      "should": [
        {
          "terms": {
            "correlationId": [
              "085178d5-e782-4ad9-a56a-5c08d906686d",
              "01b4ac00-1c67-4056-a571-455f9fd1c296"
            ]
            
          }
          
        }
        
        
      ]
    }
    
  }
  
}

```

---

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 2:40pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/10 "2022-06-08T14:40:46Z")

</div>

This works and return the correct results based on the specified search term `"serviceName": "Serviceworker"`. I can see the results are correct. However, this query

```auto
GET unity/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2020-04-01",
              "lte": "2022-07-01"
            }
          }
        }
      ], 
      "should": [
        {
          "terms": {
            "correlationId": [
              "085178d5-e782-4ad9-a56a-5c08d906686d",
              "01b4ac00-1c67-4056-a571-455f9fd1c296"
            ]
            
          }
          
        }
        
        
      ]
    }
    
  }
  
}

```

Returns invalid results. in fact, it doesn't return any document with the specified correlationId specified in the terms. I get records but none of them matches the Ids specified.

Thank you for your help

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 2:43pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/11 "2022-06-08T14:43:37Z")

</div>

Could you share samples which I can copy and paste to Dev tools (just like my last post) and reproduce the "invalid" results?

---

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 2:55pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/12 "2022-06-08T14:55:13Z")

</div>

Here is one of the returned documents. Note that the correlationid `159ad2fc-0144-4d7c-a3d2-1539666cd7cf` is not in the terms array.

```auto
{
        "_index" : "unity-2022.05.28-000044",
        "_type" : "_doc",
        "_id" : "8rUnCIEBz8iVD5dbH4b3",
        "_score" : 5.886705,
        "_ignored" : [
          "message.keyword"
        ],
        "_source" : {
          "@timestamp" : "2022-05-28T00:53:08.353Z",
          "ecs" : {
            "version" : "1.12.0"
          },
          "serviceComponent" : null,
          "serverIp" : "192.168.0.1",
          "requestId" : null,
          "result" : "Checkin successful.",
          "serviceVersion" : "2.0.0",
          "category" : "SERVICE",
          "details" : "Service instance registered: default.serviceworker.prod.2.0.0.7957389e4b0f08ecd7d4cdb2f9bde808",
          "serverPort" : {REMOVED},
          "serviceProcessId" : 6468,
          "serviceRealm" : null,
          "resultReason" : null,
          "serviceEnvironment" : "X",
          "severity" : "info",
          "class" : "INSTANCE.REGISTRATION",
          "action" : "put",
          "duration" : 0,
          "host" : {
            "name" : "PSERVER_ONE"
          },
          "identity" : "SYSTEM",
          "serviceName" : "Serviceworker",
          "schemaVersion" : 1,
          "correlationId" : "159ad2fc-0144-4d7c-a3d2-1539666cd7cf",
          "messageRole" : null,
          "requestRole" : null,
          "input" : {
            "type" : "log"
          },
          "target" : "{REMOVED}",
          "msource" : "registry.ts",
          "serverName" : "SERVER_ONE",
          "identityDelegate" : null,
          "dataClassification" : "CONFIDENTIAL",
          "timestamp" : "2022-05-28T00:53:07.193Z",
          "agent" : {
            "hostname" : "SERVER_ONE",
            "ephemeral_id" : "94258ab1-6508-406b-a434-4729e1abb9cb",
            "id" : "3d9b3d93-8f87-4156-8f8e-1edf2e31d3cc",
            "name" : "SERVER_ONE",
            "type" : "filebeat",
            "version" : "7.16.2"
          },
          "correlationRole" : "PARTICIPANT",
          "clientIp" : null,
          "log" : {
            "offset" : 6753369,
            "file" : {
              "path" : "LOG FILE PATH"
            }
          },
          "message" : """{"schemaVersion":1,"timestamp":"2022-05-28T00:53:07.193Z","severity":"info","details":"Service instance registered: default.serviceworker.prod.2.0.0.7957389e4b0f08ecd7d4cdb2f9bde808","clientIp":null,"serverName":"SERVER_ONE","serverIp":"192.168.0.1","serviceComponent":null,"serviceProcessId":6468,"serviceRealm":null,"identity":"SYSTEM","identityDelegate":null,"correlationId":"159ad2fc-0144-4d7c-a3d2-1539666cd7cf","correlationRole":"PARTICIPANT","requestId":null,"requestRole":null,"messageId":null,"messageRole":null,"category":"SERVICE","class":"INSTANCE.REGISTRATION","action":"put","target":"instance","result":"Checkin successful.","dataClassification":"CONFIDENTIAL","resultReason":null,"duration":0,"source":"registry.ts","serverPort":33018,"serviceName":"serviceworker","serviceVersion":"2.0.0","serviceEnvironment":"X"}""",
          "messageId" : null
        }
      }

```

The top part is

```auto
{
  "took" : 3804,
  "timed_out" : false,
  "_shards" : {
    "total" : 110,
    "successful" : 110,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 10000,
      "relation" : "gte"
    },
    "max_score" : 5.886705,
    "hits" : [
      {
        "_index" : "unity-2022.05.28-000044",
        "_type" : "_doc",
        "_id" : "k7UjCIEBz8iVD5dbdWZL",
        "_score" : 5.886705,
        "_ignored" : [
          "message.keyword"
        ],

```

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 3:43pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/13 "2022-06-08T15:43:39Z")

</div>

I meant samples which I can copy and paste to Dev tools to create index, index documents and query them.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 4:15pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/14 "2022-06-08T16:15:54Z")

</div>

Sorry, I found the reason.

> **[Boolean query | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html#bool-min-should-match)**

> If the bool query includes at least one should clause and no must or filter clauses, the default value is 1. Otherwise, the default value is 0.

the default minimum\_should\_parameter is 0 with must or filter clause.

set the terms query in must or filter clause or set minimum\_should\_parameter as 1.

---

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 4:35pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/15 "2022-06-08T16:35:48Z")

</div>

I had tried that last night and just did that again

```auto
GET unity/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2020-04-01",
              "lte": "2022-07-01"
            }
          }
        }
      ], 
      "must": [
        {
          "match": {
            "serviceName": "Serviceworker"
          }
        }
      ],
      "should": [
        {
          "terms": {
            "correlationId": [
              "085178d5-e782-4ad9-a56a-5c08d906686d",
              "01b4ac00-1c67-4056-a571-455f9fd1c296"
            ]
            
            
          }
          
        }
        
        
        
      ],
      "minimum_should_match": 1
    }
    
  }
  
}

```

returns

```auto
{
  "took" : 2233,
  "timed_out" : false,
  "_shards" : {
    "total" : 110,
    "successful" : 110,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  }
}

```

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 5:15pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/16 "2022-06-08T17:15:11Z")

</div>

It returned hits with my test index.

```auto
GET test_multiple_fields_query/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2020-04-01",
              "lte": "2022-07-01"
            }
          }
        }
      ], 
      "must": [
        {
          "match": {
            "serviceName": "Serviceworker"
          }
        }
      ],
      "should": [
        {
          "terms": {
            "correlationId": [
              "085178d5-e782-4ad9-a56a-5c08d906686d",
              "01b4ac00-1c67-4056-a571-455f9fd1c296"
            ]
          }
        }
      ],
      "minimum_should_match": 1
    }
  }
}

```

```auto
{
  "took" : 1,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 1,
      "relation" : "eq"
    },
    "max_score" : 1.287682,
    "hits" : [
      {
        "_index" : "test_multiple_fields_query",
        "_type" : "_doc",
        "_id" : "czS8Q4EBf0nakUP8WpBP",
        "_score" : 1.287682,
        "_source" : {
          "@timestamp" : "2021-01-01",
          "serviceName" : "Serviceworker",
          "correlationId" : "085178d5-e782-4ad9-a56a-5c08d906686d"
        }
      }
    ]
  }
}

```

Therefore the query itself should be ok.

Again, could you share samples which I can copy and paste to Dev tools (to create index, index documents and query them) and reproduce the "invalid" results?

---

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 5:30pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/17 "2022-06-08T17:30:15Z")

</div>

The index template

```auto
PUT _index_template/unity
{
  "template": {
    "settings": {
      "index": {
        "lifecycle": {
          "name": "unity_index_ilm_policy",
          "rollover_alias": "unity"
        },
        "number_of_shards": "5",
        "number_of_replicas": "1"
      }
    },
    "mappings": {
      "properties": {
        "serviceComponent": {
          "fielddata": true,
          "type": "text"
        },
        "serverName": {
          "fielddata": true,
          "type": "text"
        },
        "source": {
          "fielddata": true,
          "type": "text"
        },
        "serverPort": {
          "type": "integer"
        },
        "serviceProcessId": {
          "type": "integer"
        },
        "duration": {
          "type": "integer"
        },
        "identityDelegate": {
          "fielddata": true,
          "type": "text"
        },
        "result": {
          "fielddata": true,
          "type": "text"
        },
        "serviceVersion": {
          "fielddata": true,
          "type": "text"
        },
        "dataClassification": {
          "fielddata": true,
          "type": "text"
        },
        "identity": {
          "fielddata": true,
          "type": "text"
        },
        "requestId": {
          "fielddata": true,
          "type": "text"
        },
        "resultReason": {
          "fielddata": true,
          "type": "text"
        },
        "action": {
          "fielddata": true,
          "type": "text"
        },
        "correlationId": {
          "fielddata": true,
          "type": "text"
        },
        "details": {
          "fielddata": true,
          "type": "text"
        },
        "class": {
          "fielddata": true,
          "type": "text"
        },
        "serviceRealm": {
          "fielddata": true,
          "type": "text"
        },
        "messageId": {
          "fielddata": true,
          "type": "text"
        },
        "messageRole": {
          "fielddata": true,
          "type": "text"
        },
        "requestRole": {
          "fielddata": true,
          "type": "text"
        },
        "correlationRole": {
          "fielddata": true,
          "type": "text"
        },
        "serviceName": {
          "fielddata": true,
          "type": "text"
        },
        "target": {
          "fielddata": true,
          "type": "text"
        },
        "@timestamp": {
          "type": "date"
        },
        "clientIp": {
          "ignore_malformed": true,
          "type": "ip"
        },
        "serviceEnvironment": {
          "fielddata": true,
          "type": "text"
        },
        "serverIp": {
          "ignore_malformed": true,
          "type": "ip"
        },
        "xForwardedFor": {
          "ignore_malformed": true,
          "type": "ip"
        },
        "category": {
          "fielddata": true,
          "type": "text"
        }
      }
    }
  },
  "index_patterns": [
    "unity-*"
  ],
  "composed_of": [
    "severity",
    "schemaversion"
  ]
}

```

Unfortunately, our Dev Elastic environment is down now and I cannot create test documents in Production

---

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 5:53pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/18 "2022-06-08T17:53:37Z")

</div>

> [@Tomo\_M](#):
>
> ```auto
> GET test_multiple_fields_query/_search
> {
> "query": {
> "bool": {
> "filter": [
> {
> "range": {
> "@timestamp": {
> "gte": "2020-04-01",
> "lte": "2022-07-01"
> }
> }
> }
> ], 
> "must": [
> {
> "match": {
> "serviceName": "Serviceworker"
> }
> }
> ],
> "should": [
> {
> "terms": {
> "correlationId": [
> "085178d5-e782-4ad9-a56a-5c08d906686d",
> "01b4ac00-1c67-4056-a571-455f9fd1c296"
> ]
> }
> }
> 
> ```

Found an environment to run some tests on

```auto
GET unity-2022.05.29-000015/_doc/0dFvRIEBvv5zIOG6LLXF

POST unity/_doc
{
"ServiceName": "SERVICE_ONE",
"serverName" : "SERVER_ONE",
"correlationId" : "bbc4be64-d240-46fb-97f7-b1be9c11a6be"
}
POST unity/_doc
{
"ServiceName": "SERVICE_ONE",
"serverName" : "SERVER_ONE",
"correlationId" : "bbc4be64-d240-46fb-97f7-b1be9c11a6bc"
}

GET unity/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "2020-04-01",
              "lte": "2022-07-01"
            }
          }
        }
      ], 
      "must": [
        {
          "match": {
            "serviceName": "SERVICE_ONE"
          }
        }
      ],
      "should": [
        {
          "terms": {
            "correlationId": [
              "bbc4be64-d240-46fb-97f7-b1be9c11a6be",
              "bbc4be64-d240-46fb-97f7-b1be9c11a6bc"
            ]
          }
        }
      ],
      "minimum_should_match": 1
    }
  }
}

```

returned

```auto
{
  "took" : 36,
  "timed_out" : false,
  "_shards" : {
    "total" : 4,
    "successful" : 4,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  }
}

```

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [June 8, 2022, 6:58pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/19 "2022-06-08T18:58:07Z")

</div>

One problem is:

```auto
"correlationId": {
          "fielddata": true,
          "type": "text"
        }

```

You should use [keyword type family](https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html) mappings, if you want to use [term-level queries](https://www.elastic.co/guide/en/elasticsearch/reference/current/term-level-queries.html).

Within text field, each text is **analyzed** to tokens to be indexed. When use term-level query on text type field, each term should match on each tokens.

See the top WARNING of [this doc](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-term-query.html).

This is the example. You will realize what had happened.

```auto
PUT test_term_on_text
{
  "mappings": {
    "properties": {
      "text": {"type":"text"}
    }
  }
}

POST test_term_on_text/_doc
{
  "text": "foo bar"
}

GET test_term_on_text/_search
{
  "query":{
    "term":{
      "text": {
        "value": "foo"
      }
    }
  }
}

GET test_term_on_text/_search
{
  "query":{
    "term":{
      "text": {
        "value": "foo bar"
      }
    }
  }
}

```

`serverName` field should be keyword field. Using term query with keyword field should be better to guarantee exact match.

---

<div class="post-metadata">

**Author:** ![dev9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dev9/32/81258_2.png) [@dev9](https://discuss.elastic.co/u/dev9)\
**Post date:** [June 8, 2022, 7:15pm UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611/20 "2022-06-08T19:15:44Z")

</div>

Thanks Tom.  
One more question, I changed the field to a keyword and now when I preview the changes under index management, I see this

```auto
"serverName": {
      "eager_global_ordinals": false,
      "norms": false,
      "index": true,
      "store": false,
      "type": "keyword",
      "index_options": "docs",
      "split_queries_on_whitespace": false,
      "doc_values": true
    },

```

Do you see an issue with these settings?

[Next page](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611.md?page=2)
