# How to use AND operator inside Match

**URL:** <https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507>\
**Category:** Kibana\
**Created:** [September 14, 2019, 5:28pm UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507 "2019-09-14T17:28:08Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fosiul\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fosiul_alam/32/43335_2.png) [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Post date:** [September 14, 2019, 5:28pm UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/1 "2019-09-14T17:28:08Z")

</div>

Hi  
I am using dev Tools , Bellow Query works fine in Kibana Discover

```auto
log.file.path:*MY.log* AND "[COMMAND:HEARTBEAT]" AND "[CHARGING:0]"

```

but when i am doing the same in Dev tools, its only taking the HEARTBEAT but its showing all data where Charging 0 and 1, but I just need 0

```auto

GET filebeat-*/_search
 {
  "size": 1000,
  "query": {
    
   "bool": {
      "must": [
        {"match": { "log.file.path":"MYlog"}},
        {"match": { "message": "'[COMMAND:HEARTBEAT]' AND '[CHARGING:0]'"}}   
      
          
		    
        
      ],
      "filter": {
        "range": {
          "@timestamp": {
          "gte": "now-15m"
         
      }
        }
      }
    }
           
  
  }
}	

```

Thanks for the help

---

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [September 15, 2019, 4:23pm UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/2 "2019-09-15T16:23:27Z")

</div>

You need to specify operator in separate field.  
Do you seek here in two fields? If that is the case, you need to use multi\_match  
If you want to stick with boolean query, try must and must not CHARGING:1

```auto
GET filebeat-*/_search
 {
  "size": 1000,
  "query": {
    
   "bool": {
      "must": [
        {"match": { "log.file.path":"MYlog"}},
        {"match": { "message": "'[COMMAND:HEARTBEAT]' AND '[CHARGING:0]'"}}   
      
          
		    
        
      ],
      "filter": {
        "range": {
          "@timestamp": {
          "gte": "now-15m"
         
      }
        }
      }
    }
           
  
  }
}	

```

---

<div class="post-metadata">

**Author:** ![Fosiul\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fosiul_alam/32/43335_2.png) [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Post date:** [September 15, 2019, 5:00pm UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/3 "2019-09-15T17:00:44Z")

</div>

hi Thanks

My Logs are like this

```auto

[COMMAND:HEARTBEAT],[GPS STATUS:true],[INFO:false],[SIGNAL:false],[ENGINE:0],[DOOR:0],[LON:0],[LAT:0],[SPEED:0.0],[HEADING:-1.0],[BATTERY:100.0%],[CHARGING:0]

```

````auto

[COMMAND:HEARTBEAT],[GPS STATUS:true],[INFO:false],[SIGNAL:false],[ENGINE:0],[DOOR:0],[LON:0],[LAT:0],[SPEED:0.0],[HEADING:-1.0],[BATTERY:100.0%],[CHARGING:1]
```
so How do i set it ? I need record where [COMMAND:HEARTBEAT] AND [CHARGING:0] , I dont need the logs where [COMMAND:HEARTBEAT] AND [CHARGING:1]

Thanks
````

---

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [September 15, 2019, 5:38pm UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/4 "2019-09-15T17:38:33Z")

</div>

@Fosiul_Alam do you have it in separate fields or this is one "message" field?

---

<div class="post-metadata">

**Author:** ![Fosiul\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fosiul_alam/32/43335_2.png) [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Post date:** [September 15, 2019, 5:58pm UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/5 "2019-09-15T17:58:02Z")

</div>

Hi  
i am using logstash so i am same log in 2 different way

````auto
{
  "_index": "filebeat-7.2.0-2019.09.14",
  "_type": "_doc",
  "_id": "Aps9MW0BBmrGS9dAswgZ",
  "_version": 1,
  "_score": null,
  "_source": {
    "ecs": {
      "version": "1.0.0"
    },
    "@version": "1",
    "message": "[COMMAND:HEARTBEAT],[GPS STATUS:true],[INFO:false],[SIGNAL:false],[ENGINE:0],[DOOR:0],[LON:0],[LAT:0],[SPEED:0.0],[HEADING:-1.0],[BATTERY:100.0%],[CHARGING:0],[O&E:CONNECTED]",
	
	
	"GPS-LOG": {
      "O&E": "CONNECTED",
      "GPS POS": "true",
      "ENGINE": "0",
      "COMMAND": "HEARTBEAT",
      "GSM_SIGNAL": "75",
      
      "CHARGING": "0",
      "HEADING": "-1.0",
      "FUEL": "0.0V/0.0%",
      "SPEED": "0.0",
      "GPS STATUS": "true",
      "ALARM": "NONE",
      "BATTERY": "100.0%",
      "TIMESTAMP": "null",
      "LON": "0",
      "LAT": "0",
      "DOOR": "0",
      "SERIAL": "1670",
      "SIGNAL": "false",
      "INFO": "false",
      "GPS_SATS": "11"
    },
	```

from this 2 type of logs, Which ever is Easy to get.
my Real logs from server is like this 

````

```
18:15:53,909 DEBUG [com.] (default-threads - 57) (338)>[TIMESTAMP:Sun Sep 15 18:15:53 UTC 2019],[COMMAND:INFO],[GPS STATUS:true],[INFO:true],[SIGNAL:false],[ENGINE:0],[DOOR:0],[LON:90],[LAT:23],[SPEED:0.0],[HEADING:240.0],[BATTERY:83.0%],[CHARGING:0],[O&E:CONNECTED],[GSM_SIGNAL:100],[GPS_SATS:8],[GPS POS:true],[FUEL:0.0V/0.0%],[ALARM:NONE],[SERIAL:03AA]

```

```auto

Thanks
```

---

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [September 16, 2019, 8:47am UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/6 "2019-09-16T08:47:48Z")

</div>

@Fosiul_Alam I would try something like that:

```
GET / filebeat-7.2.0-2019.09.14/_search
{
"query": {
  "bool": {
    "must": [
      {
        "match": {
          "command": "heartbeat"
        }
      }
    ],
    "must_not": [
      { 
        "match": {
       "charging": "1"
      }
      }
    ]
  }
}
}
```

---

<div class="post-metadata">

**Author:** ![Fosiul\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fosiul_alam/32/43335_2.png) [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Post date:** [September 16, 2019, 12:49pm UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/7 "2019-09-16T12:49:18Z")

</div>

Hi  
this giving every log ...  
nothing related to only logs where  
[COMMAND:HEARTBEAT] AND [CHARGING:0]

---

<div class="post-metadata">

**Author:** ![Fosiul\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fosiul_alam/32/43335_2.png) [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Post date:** [September 16, 2019, 1:26pm UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/8 "2019-09-16T13:26:03Z")

</div>

Hi  
By using Term, I am able to get the result  
Thanks

---

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [September 20, 2019, 10:07am UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/9 "2019-09-20T10:07:57Z")

</div>

Nice to see you've done that 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2019, 10:08am UTC](https://discuss.elastic.co/t/how-to-use-and-operator-inside-match/199507/10 "2019-10-18T10:08:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
