# Inconsistent results when searching/deleting documents containing quotes

**URL:** <https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698>\
**Category:** Kibana\
**Tags:** eql-elastic-query-language\
**Created:** [May 26, 2022, 10:27am UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698 "2022-05-26T10:27:47Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![bizmate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bizmate/32/24977_2.png) [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Post date:** [May 26, 2022, 10:27am UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/1 "2022-05-26T10:27:47Z")

</div>

# ES question

in my document i have ....

> "message": "10.42.224.236 - 26/May/2022:06:15:58 +0000 "GET /index.php" 200"

and i would like to match from GET to 200.  
If i query with

```auto
GET /index_prod*/_search
{
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "multi_match": {
            "type": "phrase",
            "query": "\"GET /index.php\" 200",
            "lenient": true
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  },
  "sort" : [
    { "@timestamp" : "desc" }
  ]
}

```

I get matches

```auto
hits" : {
    "total" : {
      "value" : 10000,
      "relation" : "gte"
    },

```

and i am sure there are more than 10k because in Kibana i see many more but if i try to delete

```auto
POST /index_prod*/_delete_by_query
{
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "multi_match": {
            "type": "phrase",
            "query": "\"GET /index.php\" 200",
            "lenient": true
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

```

I get

```auto
  "total" : 0,
  "deleted" : 0,

```

I have also trying to put the multi\_match part inside the must part but that makes no difference. What am i doing wrong?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [May 28, 2022, 1:03pm UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/2 "2022-05-28T13:03:54Z")

</div>

The \_search query still returns the over 10000 docs??  
Don't you execute the \_delete\_by\_query twice to get 0 result?

---

<div class="post-metadata">

**Author:** ![bizmate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bizmate/32/24977_2.png) [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Post date:** [May 28, 2022, 2:07pm UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/3 "2022-05-28T14:07:15Z")

</div>

@Tomo_M no i do not run the delete twice. The delete just does not work and it deletes nothing

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [May 28, 2022, 2:19pm UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/4 "2022-05-28T14:19:32Z")

</div>

Hmm. It worked for me.  
I have no idea about what is the difference...

```auto
PUT test_delete

POST test_delete/_doc/
{
  "message": "10.42.224.236 - 26/May/2022:06:15:58 +0000 \"GET /index.php\" 200"
}

GET test_delet*/_search
{
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "multi_match": {
            "type": "phrase",
            "query": "\"GET /index.php\" 200",
            "lenient": true
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

POST test_delet*/_delete_by_query
{
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "multi_match": {
            "type": "phrase",
            "query": "\"GET /index.php\" 200",
            "lenient": true
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }
}

GET test_delete/_search
{
  "query":{
    "match_all":{}
  }
}

```

---

<div class="post-metadata">

**Author:** ![bizmate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bizmate/32/24977_2.png) [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Post date:** [May 28, 2022, 2:53pm UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/5 "2022-05-28T14:53:40Z")

</div>

I dont know what to say other than it doesnt here and deletes are not working at all.

My version of ES is

```auto
{
name: "71a.....cd77",
cluster_name: "50994......ses",
cluster_uuid: "o2yzk......eRvToA",
version: {
number: "7.10.2",
build_flavor: "oss",
build_type: "tar",
build_hash: "unknown",
build_date: "2022-02-10T09:41:23.620550Z",
build_snapshot: false,
lucene_version: "8.7.0",
minimum_wire_compatibility_version: "6.8.0",
minimum_index_compatibility_version: "6.0.0-beta1"
},
tagline: "You Know, for Search"
}

```

It is an instance on AWS. Would this behave differently from yours?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [May 28, 2022, 3:38pm UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/6 "2022-05-28T15:38:13Z")

</div>

Could you share the whole queries (\_search and \_deleet\_by\_query) and their responses?

I tried in on-premise environment of 7.16.

---

<div class="post-metadata">

**Author:** ![bizmate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bizmate/32/24977_2.png) [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Post date:** [May 28, 2022, 5:06pm UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/7 "2022-05-28T17:06:08Z")

</div>

I think i got somewhere by playing around. If i run the delete queries with the \* in the name of the index it does not run them or finds matches

I have indexes named as

/vendor\_myapp\_prod-filebeat-7.14.0-2022.05  
/vendor\_myapp\_prod-filebeat-7.14.0-2022.04  
etc

i can share the queries but at this point that i spotted it working when the full index name is used I am wondering if there is something in configuration that does not allow it to delete on a index name with wildcards. \_search works with wildcards

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [May 29, 2022, 12:01am UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/8 "2022-05-29T00:01:30Z")

</div>

Sounds great to hear you find that. As [document](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-delete-by-query.html), `<target>` of \_delete\_by\_query sould supports wildcards. The behavior is strange and maybe beyond me. I suppose you may organize the situation and report it as a bug.

---

<div class="post-metadata">

**Author:** ![bizmate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bizmate/32/24977_2.png) [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Post date:** [May 30, 2022, 1:02pm UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/9 "2022-05-30T13:02:11Z")

</div>

I tried this sequence of commands and for the delete works in this case, so I am not really sure why it would not in my actual live indexes.

```auto
POST test_delete-filebeat-7.14.0-2022.05/_doc/
{
  "message": "10.42.224.236 - 26/May/2022:06:15:58 +0000 \"GET /index.php\" 200",
  "@timestamp" : "2022-05-30T12:56:07.985Z"
}

POST test_delete-filebeat-7.14.0-2022.04/_doc/
{
  "message": "10.42.224.236 - 26/May/2022:06:15:58 +0000 \"GET /index.php\" 200",
  "@timestamp" : "2022-04-30T12:56:07.985Z"
}

GET /test_delete*/_search
{
  "query": {
    "bool": {
      "must": [{
          "multi_match": {
            "type": "phrase",
            "query": "\"GET /index.php\" 200",
            "lenient": true
          }
        }],
      "filter": [
        
      ],
      "should": [],
      "must_not": []
    }
  },
  "sort" : [
    { "@timestamp" : "desc" }
  ]
}

POST /test_delete*/_delete_by_query
{
  "query": {
    "bool": {
      "must": [{
          "multi_match": {
            "type": "phrase",
            "query": "\"GET /index.php\" 200",
            "lenient": true
          }
        }],
      "filter": [],
      "should": [],
      "must_not": []
    }
  }
}

```

I actually added the first record twice so the result of the delete is

```auto
{
  "took" : 28,
  "timed_out" : false,
  "total" : 3,
  "deleted" : 3,
  "batches" : 1,
  "version_conflicts" : 0,
  "noops" : 0,
  "retries" : {
    "bulk" : 0,
    "search" : 0
  },
  "throttled_millis" : 0,
  "requests_per_second" : -1.0,
  "throttled_until_millis" : 0,
  "failures" : []
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2022, 1:02pm UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698/10 "2022-06-27T13:02:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
