# Logstash-filter-elasticsearch query

**URL:** <https://discuss.elastic.co/t/logstash-filter-elasticsearch-query/97538>\
**Category:** Logstash\
**Created:** [August 18, 2017, 8:42am UTC](https://discuss.elastic.co/t/logstash-filter-elasticsearch-query/97538 "2017-08-18T08:42:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![user1](https://avatars.discourse-cdn.com/v4/letter/u/5daacb/32.png) [@user1](https://discuss.elastic.co/u/user1)\
**Post date:** [August 18, 2017, 8:42am UTC](https://discuss.elastic.co/t/logstash-filter-elasticsearch-query/97538/1 "2017-08-18T08:42:27Z")

</div>

Hi,

Am having problem in logstash-filter-elaticsearch query :

We already have an index stored under elasticsearch.

on run time we like to enrich the data under logstash by elasticsearch look up.

GET citylist/\_search  
{  
"query" : {  
"match\_phrase" : {  
"ct\_name" : "xxxx"  
}  
}  
}

It gives the result on kibana.

Under logstash conf:

```
    if [citypresent]{
    elasticsearch {
            hosts => ["localhost:9200/citylist/data"]
             index => "citylist"

```

# query=\> "ct\_name:'%{citypresent}'"

```
             query=>'{"query" : {"match_phrase" : {"ct_name" : "%{[citypresent]}"}}}'
             fields=>["newcity"]
            }
    }

```

Getting : [2] "\_elasticsearch\_lookup\_failure"

[logstash.filters.elasticsearch] Failed to query elasticsearch for previous event {:index=\>"citylist", :query=\>"{"query" : {"match\_phrase" : {"ct\_name" : "%{[citypresent]}"}}}"

:error=\>#\<Elasticsearch::Transport::Transport::Errors::BadRequest: [400] {"error":{"root\_cause":[{"type":"query\_shard\_exception","reason":"Failed to parse query [{"query" : {"match\_phrase" : {"ct\_name" : "%{[p\_input\_city]}"}}}]"

"type":"search\_phase\_execution\_exception","reason":"all shards failed","phase":"query","grouped":true,"failed\_shards":[{"shard":0,"index":"citylist","node":"EpDQwDa\_R7iB5utOLiK23Q","reason":{"type":"query\_shard\_exception","reason":"Failed to parse query [{"query" : {"match\_phrase" : {"ct\_name" : "%{[citypresent]}"}}}]","index\_uuid":"OuuhVn8aScqYUCI\_3Vq\_0Q","index":"citylist","caused\_by":{"type":"parse\_exception","reason":"Cannot parse '{"query" : {"match\_phrase" : {"ct\_name" : "%{[citypresent]}"}}}': Encountered " \<RANGE\_GOOP\> ": "" at line 1, column 9.\nWas expecting:\n "TO" ...\n ","caused\_by":{"type":"parse\_exception","reason":"Encountered " \<RANGE\_GOOP\> ": "" at line 1, column 9.\nWas expecting:\n "TO" ...\n "}}}}]},"status":400}\>}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2017, 8:42am UTC](https://discuss.elastic.co/t/logstash-filter-elasticsearch-query/97538/2 "2017-09-15T08:42:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
