# How to search through ingest attachments

**URL:** <https://discuss.elastic.co/t/how-to-search-through-ingest-attachments/185703>\
**Category:** Elasticsearch\
**Created:** [June 13, 2019, 4:44pm UTC](https://discuss.elastic.co/t/how-to-search-through-ingest-attachments/185703 "2019-06-13T16:44:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fedoroko](https://avatars.discourse-cdn.com/v4/letter/f/977dab/32.png) [@fedoroko](https://discuss.elastic.co/u/fedoroko)\
**Post date:** [June 13, 2019, 4:44pm UTC](https://discuss.elastic.co/t/how-to-search-through-ingest-attachments/185703/1 "2019-06-13T16:44:34Z")

</div>

Hello, i'm installed elastic and ingest plagin but can't understand how to search through indexed attachments. Can you please explain how to build search query for attachments content?

```
PUT _ingest/pipeline/attachment?pretty
{
 "description" : "Extract attachment information from arrays",
 "processors" : [
   {
     "foreach": {
       "field": "attachments",
       "processor": {
         "attachment": {
           "target_field": "_ingest._value.attachment",
           "field": "_ingest._value.data"
         }
       }
     }
   }
 ]
}

PUT article/_doc/1?pipeline=attachment&pretty
{
 "attachments" : [
   {
      "filename" : "test_1.txt",
      "data" : "UEsDBBQACAgIACtHzU4AAAAAAAAAA *****"
    }
 ]
}

GET article/_doc/1?pretty
{
    "_index": "article",
    "_type": "_doc",
    "_id": "1",
    "_version": 2,
    "_seq_no": 39,
    "_primary_term": 3,
    "found": true,
    "_source": {
        "attachments": [
            {
                "filename": "test_1.txt",
                "data": "UEsDBBQACAgIACtHzU4AAAAAAAAAAAAAA *****",
                "attachment": {
                    "content_type": "application/vnd.openxmlformats-officedocument.wordprocessingml.document",
                    "language": "hu",
                    "content": "Hello, find me!",
                    "content_length": 16
                }
            }
        ]
    }
}

```

Then trying

```
GET article/_search
{
  "query": {
    "match": {
      "attachments(or content or attachment etc)": {
        "query": "hello"
      }
    }
  }
}

```

But return 0 hits

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [June 13, 2019, 9:52pm UTC](https://discuss.elastic.co/t/how-to-search-through-ingest-attachments/185703/2 "2019-06-13T21:52:02Z")

</div>

You need to fully specify the path within the document to the field you want to search. Try adjusting your query to:

```auto
GET article/_search
{
  "query": {
    "match": {
      "attachments.attachment.content": {
        "query": "hello"
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2019, 10:02pm UTC](https://discuss.elastic.co/t/how-to-search-through-ingest-attachments/185703/3 "2019-07-11T22:02:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
