# Implementing Blacklist with Terms Lookup

**URL:** <https://discuss.elastic.co/t/implementing-blacklist-with-terms-lookup/107920>\
**Category:** Elasticsearch\
**Created:** [November 16, 2017, 11:47am UTC](https://discuss.elastic.co/t/implementing-blacklist-with-terms-lookup/107920 "2017-11-16T11:47:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [November 16, 2017, 11:47am UTC](https://discuss.elastic.co/t/implementing-blacklist-with-terms-lookup/107920/1 "2017-11-16T11:47:03Z")

</div>

Hi all,

I have a set of documents representing data of a phone call, basically **from, to, duration**  
I want to implement a watcher that if a document with certain **from** number is being inserted an alarm is raised.  
So I decide to use terms lookup, which works fine. 🙂 when the from field matches exactly the value in the document used in the lookup.

Now I have a question. Is it possible to match those documents containing the values used in the lookup as a substring?  
The from field is of the type keyword .  
For example

```
PUT /temp_sbc2/blacklist/3
{
  "to_block" : ["376875"] 
}

```

If I have a document containing from : 3768755588 I want that a similar query to this

```
GET /temp_sbc2/_search
{
    "query" : {
        "terms" : {
            "from" : {
                "index" : "temp_sbc2",
                "type" : "blacklist",
                "id" : "3",
                "path" : "to_block"
            }
        }
    }
}

```

To return the document.

Thank you  
Regards!  
Anna

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [November 24, 2017, 9:14pm UTC](https://discuss.elastic.co/t/implementing-blacklist-with-terms-lookup/107920/2 "2017-11-24T21:14:16Z")

</div>

Terms lookup works only with the `terms` query. So, you would need to index the `from` field twice - one time as not analyzed field for normal lookup and another time with an analyzer with [edgeNGram](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/analysis-edgengram-tokenfilter.html) filter, so you can find it by prefix.

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [November 25, 2017, 11:36pm UTC](https://discuss.elastic.co/t/implementing-blacklist-with-terms-lookup/107920/3 "2017-11-25T23:36:14Z")

</div>

Thank you @Igor_Motov  
Regards  
Ana

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 23, 2017, 11:36pm UTC](https://discuss.elastic.co/t/implementing-blacklist-with-terms-lookup/107920/4 "2017-12-23T23:36:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
