# Managing queries in Elasticsearch Logstash filter plugin

**URL:** <https://discuss.elastic.co/t/managing-queries-in-elasticsearch-logstash-filter-plugin/141888>\
**Category:** Elasticsearch\
**Created:** [July 27, 2018, 7:21am UTC](https://discuss.elastic.co/t/managing-queries-in-elasticsearch-logstash-filter-plugin/141888 "2018-07-27T07:21:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 27, 2018, 7:21am UTC](https://discuss.elastic.co/t/managing-queries-in-elasticsearch-logstash-filter-plugin/141888/1 "2018-07-27T07:21:14Z")

</div>

Hi,

I'm opening this topic as a follow-up to this one: [Elasticsearch query sort order index](https://discuss.elastic.co/t/elasticsearch-query-sort-order-index/137419/3)  
My main documentation reference for using Elasticsearch queries in Logstash is [https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html)

What I would like to understand, is how to manage queries templates to control search results.  
Here's an example: let's assume we have three daily indices:

- `logstash-data-2018.07.27`
- `logstash-data-2018.07.26`
- `logstash-data-2018.07.25`

If we use this filter here:

```
filter {
    elasticsearch {
	    hosts => ["elasticsearch:9200"]
	    index => ["logstash-data-*"]
	    query => "object:%{[data_object]}"
	    result_size => 1
        fields => {"some_field_in_logstash-data" => "some_field"}
    }
}

```

If `data_object = 12345678`, from my understanding, Logstash is using this query template here:

```
{
  "query": {
    "match": {
      "object": {
        "query": "12345678",
        "type": "phrase"
      }
    }
  }
}

```

So, if logstash-data-\* has multiple entries like for instance: `12345678, 123456789, 12345678A`  
All of them will match and Logstash will simply take the first result.

What I would like to achieve is for Logstash to look for the _exact match_.  
Is it possible to achieve this by using this query template here?

```
{
  "query": {
    "match": {
      "object.keyword": {
        "query": "12345678",
        "type": "phrase"
      }
    }
  }
}

```

And where I should put this template in order to use the configuration option `query_template => "template.json"`?

Thank you

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2018, 9:39am UTC](https://discuss.elastic.co/t/managing-queries-in-elasticsearch-logstash-filter-plugin/141888/2 "2018-07-27T09:39:29Z")

</div>

> [@espogian](#):
>
> If `data_object = 12345678` , from my understanding, Logstash is using this query template here...

Hmmm. Actually I believe it calls:

```auto
GET logstash-data-*/_search?q=object:12345678

```

If you want to search on `object.keyword`, may be just do:

```auto
filter {
    elasticsearch {
	    hosts => ["elasticsearch:9200"]
	    index => ["logstash-data-*"]
	    query => "object.keyword:%{[data_object]}"
	    result_size => 1
        fields => {"some_field_in_logstash-data" => "some_field"}
    }
}

```

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 27, 2018, 10:04am UTC](https://discuss.elastic.co/t/managing-queries-in-elasticsearch-logstash-filter-plugin/141888/3 "2018-07-27T10:04:11Z")

</div>

Thank you @dadoonet, just one more clarification please: if Elasticsearch finds more than one entry, given that `result_size => 1`, which will be the sorting order?  
Is it correct to assume that the default is `"sort" : [{ "@timestamp" : "desc" }]`?

[Edit] I tested the query

`GET logstash-data-*/_search?q=object:12345678`

Against my actual Elasticsearch indexes, and I receive the multiple results in a sort-of random ordering (they are apparently ordered by `"_score"` but not by @timestamp or index name)

[Edit2] I think I need this query:

```
GET logstash-data-*/_search
{
  "size": 1,
  "sort" : [{ "@timestamp" : "desc" }],
  "query": {
    "match": {
      "object.keyword": {
        "query": "12345678"
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 27, 2018, 10:55am UTC](https://discuss.elastic.co/t/managing-queries-in-elasticsearch-logstash-filter-plugin/141888/4 "2018-07-27T10:55:45Z")

</div>

Yes. It's by default sorted on `_score`.

If you wish to pass a more complex query, use a `query_template`.

I shared an example here:

> **[Enriching Your Postal Addresses With the Elastic Stack - Part 2
	  	 | Elastic](https://www.elastic.co/blog/enriching-your-postal-addresses-with-the-elastic-stack-part-2)**
>
> This blog post is part 2 of a series of 3: Importing BANO dataset with Logstash Using Logstash to lookup for addresses in BANO index Using Logstash to enrich an existing dataset with BANO In the previ...

```auto
elasticsearch {
  query_template => "search-by-name.json"
  index => ".bano"
  fields => {
    "location" => "[location]"
    "address" => "[address]"
  }
  remove_field => ["headers", "host", "@version", "@timestamp"]
}

```

```auto
{
  "size": 1,
  "query":{
    "bool": {
      "should": [
        {
          "match": {
            "address.number": "%{[address][number]}"
          }
        },
        {
          "match": {
            "address.street_name": "%{[address][street_name]}"
          }
        },
        {
          "match": {
            "address.city": "%{[address][city]}"
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 27, 2018, 11:44am UTC](https://discuss.elastic.co/t/managing-queries-in-elasticsearch-logstash-filter-plugin/141888/5 "2018-07-27T11:44:33Z")

</div>

@dadoonet thank you so much for your time, your answers have been really helpful!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2018, 11:44am UTC](https://discuss.elastic.co/t/managing-queries-in-elasticsearch-logstash-filter-plugin/141888/6 "2018-08-24T11:44:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
