# Inconsistency with query\_string results

**URL:** <https://discuss.elastic.co/t/inconsistency-with-query-string-results/24866>\
**Category:** Elasticsearch\
**Created:** [July 3, 2015, 12:32pm UTC](https://discuss.elastic.co/t/inconsistency-with-query-string-results/24866 "2015-07-03T12:32:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arcimboldo](https://avatars.discourse-cdn.com/v4/letter/a/c77e96/32.png) [@Arcimboldo](https://discuss.elastic.co/u/Arcimboldo)\
**Post date:** [July 3, 2015, 12:32pm UTC](https://discuss.elastic.co/t/inconsistency-with-query-string-results/24866/1 "2015-07-03T12:32:12Z")

</div>

I encountered some strange behavior of the query\_string query:

I have an index with one type "objects" that contains one document with a default-analyzed string field called "content" that is empty. If I search with

```
GET /dbc_xyz/objects/_search
{
  "version": true,
  "query": {
    "query_string": {
      "default_field": "content",
      "default_operator": "AND",
      "query": "Term"
    }
  }
}

```

Elasticsearch as expected finds nothing. And if I change the query string to "-Term" it finds the empty document, also as I expected. However, when I tried to find out whether "-" takes precedence over OR, as is usually the case, I found this: "-Term OR Termtwo" returned nothing. If I search with "(-Term) OR Termtwo" again the empty document is found. So, I asked myself whether quite unusually "OR" takes precedence over "-". But when I tried "-(Term OR Termtwo)" the empty document was again returned. Only the "-Term OR Termtwo" tried first returned nothing.

I cannot make sense of this, is this possibly a bug? I use Elasticsearch 1.5.2

Best  
Heiko

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [July 4, 2015, 12:43am UTC](https://discuss.elastic.co/t/inconsistency-with-query-string-results/24866/2 "2015-07-04T00:43:33Z")

</div>

If a clause only contains a negated term, then Elasticsearch will  
implicitly create a match all query and the negated term (content:\*  
content:-Term) since Lucene does not handle purely negative clauses. The  
match all trick has always existed in Lucene, Elasticsearch just does it in  
the background.

I suspect the issue is with what Elasticsearch considers a purely negative  
clause in its parser. Never checked. I would suggest always adding the  
match all (_:_ or fieldname:\*) when using only negation explicitly to avoid  
any ambiguity.

Cheers,

Ivan

---

<div class="post-metadata">

**Author:** ![Arcimboldo](https://avatars.discourse-cdn.com/v4/letter/a/c77e96/32.png) [@Arcimboldo](https://discuss.elastic.co/u/Arcimboldo)\
**Post date:** [July 6, 2015, 7:47am UTC](https://discuss.elastic.co/t/inconsistency-with-query-string-results/24866/3 "2015-07-06T07:47:39Z")

</div>

Hi, Ivan,

thanks for your reply. However, this is not the situation I'm concerned about, as "-Term" gives me exactly the result I expect. And really, the workaround you cited is logically equivalent and would not explain differences in results. What I'm really confused about is when the clause does _not_ only contain a negated term. For example, if "-Term" yields one (of one in total) document, I would expect that, no matter what I "OR" with "-Term", I will get the same result. But if I use "-Term OR Termtwo" it yields an empty result - this doesn't make sense. So I wondered which of the two operators ("-", i.e. negation, and "OR") takes precedence over which, although I couldn't immediately see how this could make a difference. To my surprise, both possibilities, "(-Term) OR Termtwo" _and_ (the most unusual) "-(Term OR Termtwo)" yielded the same single document. For me this looks like a bug, as from the logic of it, it's wrong.

Cheers  
Heiko

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:03am UTC](https://discuss.elastic.co/t/inconsistency-with-query-string-results/24866/4 "2017-07-06T00:03:30Z")

</div>


