# "key:value" searches

**URL:** <https://discuss.elastic.co/t/key-value-searches/7351>\
**Category:** Elasticsearch\
**Created:** [April 16, 2012, 3:45pm UTC](https://discuss.elastic.co/t/key-value-searches/7351 "2012-04-16T15:45:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shane\_Witbeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shane_witbeck/32/2803_2.png) [@Shane\_Witbeck](https://discuss.elastic.co/u/Shane_Witbeck)\
**Post date:** [April 16, 2012, 3:45pm UTC](https://discuss.elastic.co/t/key-value-searches/7351/1 "2012-04-16T15:45:49Z")

</div>

I've noticed that searches for documents that contain a string such as  
key:value return unwanted results. For example, a search on:

"key:value"

returns results that include key AND value (eg. "key-value") but not  
results that ONLY contain "key:value"

I've tried various combinations using a query\_string query and escaping but  
keep getting the unwanted results. It seems as though the escaped colon  
removes it completely?

What's the best way to query on "key:value" and only return results that  
contain "key:value"?

I'm using 0.19.1 and the standard analyzer

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 16, 2012, 3:57pm UTC](https://discuss.elastic.co/t/key-value-searches/7351/2 "2012-04-16T15:57:34Z")

</div>

I think you should use a keyword analyzer for that field.

My 2 cents  
David.

Le 16 avril 2012 à 17:45, Shane Witbeck [shane@digitalsanctum.com](mailto:shane@digitalsanctum.com) a écrit  
:

> documents that contain a string such as key:value return unwanted results.  
> For example, a search on:
> 
> "key:value"
> 
> returns results that include key AND value (eg. "key-value") but not  
> results that ONLY contain "key:value"
> 
> I've tried various combinations using a query\_string query and escaping but  
> keep getting the unwanted results. It seems as though the escaped colon  
> removes it completely?
> 
> What's the best way to query on "key:value" and only return results that  
> contain "key:value"?
> 
> I'm using 0.19.1 and the standard analyzer

--  
David Pilato  
[http://dev.david.pilato.fr/](http://dev.david.pilato.fr/)  
Twitter : @dadoonet

---

<div class="post-metadata">

**Author:** ![Shane\_Witbeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shane_witbeck/32/2803_2.png) [@Shane\_Witbeck](https://discuss.elastic.co/u/Shane_Witbeck)\
**Post date:** [April 16, 2012, 4:20pm UTC](https://discuss.elastic.co/t/key-value-searches/7351/3 "2012-04-16T16:20:05Z")

</div>

Would a keyword analyzer still be appropriate if the "key:value" string is  
not the only text in the field? In my case, the field in question is text  
from a forum post.

As an aside, is there a reference that explains in detail the different  
analyzers and when to use them? I'm looking for more detail than what's in  
the [elasticsearch.org](http://elasticsearch.org) docs.

Thanks,  
Shane

On Monday, April 16, 2012 11:57:34 AM UTC-4, David Pilato wrote:

> I think you should use a keyword analyzer for that field.
> 
> My 2 cents
> 
> David.
> 
> Le 16 avril 2012 à 17:45, Shane Witbeck [shane@digitalsanctum.com](mailto:shane@digitalsanctum.com) a  
> écrit :
> 
> I've noticed that searches for documents that contain a string such as  
> key:value return unwanted results. For example, a search on:
> 
> "key:value"
> 
> returns results that include key AND value (eg. "key-value") but not  
> results that ONLY contain "key:value"
> 
> I've tried various combinations using a query\_string query and escaping  
> but keep getting the unwanted results. It seems as though the escaped colon  
> removes it completely?
> 
> What's the best way to query on "key:value" and only return results that  
> contain "key:value"?
> 
> I'm using 0.19.1 and the standard analyzer
> 
> --  
> David Pilato  
> [http://dev.david.pilato.fr/](http://dev.david.pilato.fr/)  
> Twitter : @dadoonet

On Monday, April 16, 2012 11:57:34 AM UTC-4, David Pilato wrote:

> I think you should use a keyword analyzer for that field.
> 
> My 2 cents
> 
> David.
> 
> Le 16 avril 2012 à 17:45, Shane Witbeck [shane@digitalsanctum.com](mailto:shane@digitalsanctum.com) a  
> écrit :
> 
> I've noticed that searches for documents that contain a string such as  
> key:value return unwanted results. For example, a search on:
> 
> "key:value"
> 
> returns results that include key AND value (eg. "key-value") but not  
> results that ONLY contain "key:value"
> 
> I've tried various combinations using a query\_string query and escaping  
> but keep getting the unwanted results. It seems as though the escaped colon  
> removes it completely?
> 
> What's the best way to query on "key:value" and only return results that  
> contain "key:value"?
> 
> I'm using 0.19.1 and the standard analyzer
> 
> --  
> David Pilato  
> [http://dev.david.pilato.fr/](http://dev.david.pilato.fr/)  
> Twitter : @dadoonet

---

<div class="post-metadata">

**Author:** ![AEvar\_Arnfjord\_Bjarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aevar_arnfjord_bjarm/32/2746_2.png) [@AEvar\_Arnfjord\_Bjarm](https://discuss.elastic.co/u/AEvar_Arnfjord_Bjarm)\
**Post date:** [April 16, 2012, 4:58pm UTC](https://discuss.elastic.co/t/key-value-searches/7351/4 "2012-04-16T16:58:05Z")

</div>

On Mon, Apr 16, 2012 at 18:20, Shane Witbeck [shane@digitalsanctum.com](mailto:shane@digitalsanctum.com) wrote:

> Would a keyword analyzer still be appropriate if the "key:value" string is  
> not the only text in the field? In my case, the field in question is text  
> from a forum post.

No, you either have to have an analyzer that tokenizes "key:value" as  
"key:value", and not "key", "value", or you need to issue something  
like a key AND value phrase query, or a bool/must query with both of  
them, but of course both of those will find stuff like "the key is a  
value" not just "key:value".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:32am UTC](https://discuss.elastic.co/t/key-value-searches/7351/5 "2017-07-06T03:32:25Z")

</div>


