# How to use filters in a query

**URL:** <https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990>\
**Category:** Elasticsearch\
**Tags:** eql-elastic-query-language\
**Created:** [February 11, 2022, 2:53pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990 "2022-02-11T14:53:56Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![MrFantastic2022](https://avatars.discourse-cdn.com/v4/letter/m/e68b1a/32.png) [@MrFantastic2022](https://discuss.elastic.co/u/MrFantastic2022)\
**Post date:** [February 11, 2022, 2:53pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/1 "2022-02-11T14:53:56Z")

</div>

Hello.  
I am working with Elasticsearch 6.8.0 and am trying to follow the example on this page [filter](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/query-filter-context.html) but cannot get the filter clause to produce the results I want. I am working with the sample dataset in the **bank** index and am trying to do something like the SQL statement _ **SELECT firstname, lastname FROM BANK WHERE STATE = 'IL';** _. My query looks like this:

```auto
GET /bank/_search
{
  "query": {
    "bool" : {
      "must: {
        "query_string": {
          "default_field": "state",
          "query": "MD"
        }
      },
      "filter": {
        "term": {
          "gender": "F"
        }
      }
    }
  }
}

```

If I remove the **filter** clause, I get quite a few hits; with the **filter** clause, I get zero. What is going on with the filter?

Thanks in advance to all who respond.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 11, 2022, 3:34pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/2 "2022-02-11T15:34:18Z")

</div>

your query (typo: only add " after must) worked well.

Response:

```auto
{
  "took" : 5,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 10,
      "relation" : "eq"
    },
    "max_score" : 3.5588508,
    "hits" : [
      {
        "_index" : "bank",
        "_type" : "_doc",
        "_id" : "HgZp6X4Bf0nakUP8t9-m",
        "_score" : 3.5588508,
        "_source" : {
          "account_number" : 126,
          "balance" : 3607,
          "firstname" : "Effie",
          "lastname" : "Gates",
          "age" : 39,
          "gender" : "F",
          "address" : "620 National Drive",
          "employer" : "Digitalus",
          "email" : "effiegates@digitalus.com",
          "city" : "Blodgett",
          "state" : "MD"
        }
      },...

```

---

<div class="post-metadata">

**Author:** ![MrFantastic2022](https://avatars.discourse-cdn.com/v4/letter/m/e68b1a/32.png) [@MrFantastic2022](https://discuss.elastic.co/u/MrFantastic2022)\
**Post date:** [February 11, 2022, 9:16pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/3 "2022-02-11T21:16:28Z")

</div>

Thank you! I will correct the typo and try again on Monday - headed out for the day in a few minutes! 😃

---

<div class="post-metadata">

**Author:** ![MrFantastic2022](https://avatars.discourse-cdn.com/v4/letter/m/e68b1a/32.png) [@MrFantastic2022](https://discuss.elastic.co/u/MrFantastic2022)\
**Post date:** [February 14, 2022, 2:33pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/4 "2022-02-14T14:33:45Z")

</div>

Hi, Tomo - the typo exists in the code I typed into the post, since I can't copy the code from the Kibana console, as it is on a separate network. Having said that, the original code which _DOES NOT_ work _HAS_ the operator **"must"** properly quoted. Is there anything else I can look at? Thanks!

---

<div class="post-metadata">

**Author:** ![MrFantastic2022](https://avatars.discourse-cdn.com/v4/letter/m/e68b1a/32.png) [@MrFantastic2022](https://discuss.elastic.co/u/MrFantastic2022)\
**Post date:** [February 14, 2022, 2:36pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/5 "2022-02-14T14:36:32Z")

</div>

Another puzzling result: when I remove the filter, I get 28 hits but see only 10 entries. Why is that?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 14, 2022, 2:40pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/6 "2022-02-14T14:40:53Z")

</div>

Elasticsearch returns only top 10 hits by default.

---

<div class="post-metadata">

**Author:** ![MrFantastic2022](https://avatars.discourse-cdn.com/v4/letter/m/e68b1a/32.png) [@MrFantastic2022](https://discuss.elastic.co/u/MrFantastic2022)\
**Post date:** [February 14, 2022, 2:51pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/7 "2022-02-14T14:51:52Z")

</div>

Thank you, that's what I thought. Is there a parameter I can set which controls it for this particular search? I see such a parameter in other search types, like in the Java API with the size() method.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 14, 2022, 3:09pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/8 "2022-02-14T15:09:50Z")

</div>

See [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-search.html). `size` is that.

---

<div class="post-metadata">

**Author:** ![MrFantastic2022](https://avatars.discourse-cdn.com/v4/letter/m/e68b1a/32.png) [@MrFantastic2022](https://discuss.elastic.co/u/MrFantastic2022)\
**Post date:** [February 14, 2022, 3:12pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/9 "2022-02-14T15:12:50Z")

</div>

Okay, I'll look in the docs I'm working with. That link points to the latest ES; I'm on 6.8 at the moment.

---

<div class="post-metadata">

**Author:** ![MrFantastic2022](https://avatars.discourse-cdn.com/v4/letter/m/e68b1a/32.png) [@MrFantastic2022](https://discuss.elastic.co/u/MrFantastic2022)\
**Post date:** [February 14, 2022, 6:24pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/10 "2022-02-14T18:24:41Z")

</div>

Is there anything else I can look at to see what is going on here? Thanks!

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 14, 2022, 11:01pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/11 "2022-02-14T23:01:38Z")

</div>

You can google "Elasticsearch 6.8 size" to find [From / Size | Elasticsearch Guide [6.8] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/search-request-from-size.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2022, 11:01pm UTC](https://discuss.elastic.co/t/how-to-use-filters-in-a-query/296990/12 "2022-03-14T23:01:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
