# Match\_all vs \*:\*

**URL:** <https://discuss.elastic.co/t/match-all-vs/4069>\
**Category:** Elasticsearch\
**Created:** [March 9, 2011, 9:04pm UTC](https://discuss.elastic.co/t/match-all-vs/4069 "2011-03-09T21:04:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lee\_Parker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lee_parker/32/3250_2.png) [@Lee\_Parker](https://discuss.elastic.co/u/Lee_Parker)\
**Post date:** [March 9, 2011, 9:04pm UTC](https://discuss.elastic.co/t/match-all-vs/4069/1 "2011-03-09T21:04:02Z")

</div>

Is there any performance difference between using the match\_all query vs a  
query\_string of "_:_"?

I ask because I'm trying to get a list of documents which match a set of  
fields, but want to match all documents. The full query looks like this:

{  
"query": {  
"filtered": {  
"query": {  
"query\_string": {  
"query": "_:_",  
"default\_operator": "AND"  
}  
},  
"filter": {  
"bool": {  
"must": [{  
"term": {  
"campaign\_id": "1"  
}  
}, {  
"terms": {  
"hash": ["4f7b7b2f105b8b6951f919e657ca6509",  
"e44036caa080c94b91aab963bfccc8c8"]  
}  
}]  
}  
}  
}  
},  
"size": 30,  
"from": 0,  
"sort": [{  
"date": {  
"reverse": true  
}  
}, "\_score"]  
}

or

{  
"query": {  
"filtered": {  
"query": {  
"match\_all": {}  
},  
"filter": {  
"bool": {  
"must": [{  
"term": {  
"campaign\_id": "1"  
}  
}, {  
"terms": {  
"hash": ["4f7b7b2f105b8b6951f919e657ca6509",  
"e44036caa080c94b91aab963bfccc8c8"]  
}  
}]  
}  
}  
}  
},  
"size": 30,  
"from": 0,  
"sort": [{  
"date": {  
"reverse": true  
}  
}, "\_score"]  
}

## Lee

"It doesn't matter whether you are liberal or conservative, but it's  
dangerous to always think with exclamation points instead of question  
marks."  
by Marty Beckerman

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [March 10, 2011, 6:12am UTC](https://discuss.elastic.co/t/match-all-vs/4069/2 "2011-03-10T06:12:50Z")

</div>

No, there isn't a big difference (just the parsing of the query\_string). Note, I suggest you use and filter and not bool filter, uses less memory.  
On Wednesday, March 9, 2011 at 11:04 PM, Lee Parker wrote:  
Is there any performance difference between using the match\_all query vs a query\_string of "_:_"?

> I ask because I'm trying to get a list of documents which match a set of fields, but want to match all documents. The full query looks like this:
> 
> {  
> "query": {  
> "filtered": {  
> "query": {  
> "query\_string": {  
> "query": "_:_",  
> "default\_operator": "AND"  
> }  
> },  
> "filter": {  
> "bool": {  
> "must": [{  
> "term": {  
> "campaign\_id": "1"  
> }  
> }, {  
> "terms": {  
> "hash": ["4f7b7b2f105b8b6951f919e657ca6509", "e44036caa080c94b91aab963bfccc8c8"]  
> }  
> }]  
> }  
> }  
> }  
> },  
> "size": 30,  
> "from": 0,  
> "sort": [{  
> "date": {  
> "reverse": true  
> }  
> }, "\_score"]  
> }
> 
> or
> 
> {  
> "query": {  
> "filtered": {  
> "query": {  
> "match\_all": {}  
> },  
> "filter": {  
> "bool": {  
> "must": [{  
> "term": {  
> "campaign\_id": "1"  
> }  
> }, {  
> "terms": {  
> "hash": ["4f7b7b2f105b8b6951f919e657ca6509", "e44036caa080c94b91aab963bfccc8c8"]  
> }  
> }]  
> }  
> }  
> }  
> },  
> "size": 30,  
> "from": 0,  
> "sort": [{  
> "date": {  
> "reverse": true  
> }  
> }, "\_score"]  
> }
> 
> ## Lee
> 
> "It doesn't matter whether you are liberal or conservative, but it's dangerous to always think with exclamation points instead of question marks."  
> by Marty Beckerman

---

<div class="post-metadata">

**Author:** ![Lee\_Parker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lee_parker/32/3250_2.png) [@Lee\_Parker](https://discuss.elastic.co/u/Lee_Parker)\
**Post date:** [March 31, 2011, 3:52pm UTC](https://discuss.elastic.co/t/match-all-vs/4069/3 "2011-03-31T15:52:38Z")

</div>

I'm using bool here because I may need to filter on multiple fields. Is it  
possible to do that without using bool? The documentation doesn't specify  
this and if I tried to add more than one filter to the request, it didn't  
parse.

## Lee

"It doesn't matter whether you are liberal or conservative, but it's  
dangerous to always think with exclamation points instead of question  
marks."  
by Marty Beckerman  
On Thu, Mar 10, 2011 at 12:12 AM, Shay Banon  
[shay.banon@elasticsearch.com](mailto:shay.banon@elasticsearch.com)wrote:

> No, there isn't a big difference (just the parsing of the query\_string). Note,  
> I suggest you use and filter and not bool filter, uses less memory.
> 
> On Wednesday, March 9, 2011 at 11:04 PM, Lee Parker wrote:
> 
> Is there any performance difference between using the match\_all query vs a  
> query\_string of "_:_"?
> 
> I ask because I'm trying to get a list of documents which match a set of  
> fields, but want to match all documents. The full query looks like this:
> 
> {  
> "query": {  
> "filtered": {  
> "query": {  
> "query\_string": {  
> "query": "_:_",  
> "default\_operator": "AND"  
> }  
> },  
> "filter": {  
> "bool": {  
> "must": [{  
> "term": {  
> "campaign\_id": "1"  
> }  
> }, {  
> "terms": {  
> "hash": ["4f7b7b2f105b8b6951f919e657ca6509",  
> "e44036caa080c94b91aab963bfccc8c8"]  
> }  
> }]  
> }  
> }  
> }  
> },  
> "size": 30,  
> "from": 0,  
> "sort": [{  
> "date": {  
> "reverse": true  
> }  
> }, "\_score"]  
> }
> 
> or
> 
> {  
> "query": {  
> "filtered": {  
> "query": {  
> "match\_all": {}  
> },  
> "filter": {  
> "bool": {  
> "must": [{  
> "term": {  
> "campaign\_id": "1"  
> }  
> }, {  
> "terms": {  
> "hash": ["4f7b7b2f105b8b6951f919e657ca6509",  
> "e44036caa080c94b91aab963bfccc8c8"]  
> }  
> }]  
> }  
> }  
> }  
> },  
> "size": 30,  
> "from": 0,  
> "sort": [{  
> "date": {  
> "reverse": true  
> }  
> }, "\_score"]  
> }
> 
> ## Lee
> 
> "It doesn't matter whether you are liberal or conservative, but it's  
> dangerous to always think with exclamation points instead of question  
> marks."  
> by Marty Beckerman

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [March 31, 2011, 4:21pm UTC](https://discuss.elastic.co/t/match-all-vs/4069/4 "2011-03-31T16:21:00Z")

</div>

I meant `and` filter: [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/and-filter.html) (And also `or` and `not`).  
On Thursday, March 31, 2011 at 5:52 PM, Lee Parker wrote:

> I'm using bool here because I may need to filter on multiple fields. Is it possible to do that without using bool? The documentation doesn't specify this and if I tried to add more than one filter to the request, it didn't parse.
> 
> ## Lee
> 
> "It doesn't matter whether you are liberal or conservative, but it's dangerous to always think with exclamation points instead of question marks."  
> by Marty Beckerman  
> On Thu, Mar 10, 2011 at 12:12 AM, Shay Banon [shay.banon@elasticsearch.com](mailto:shay.banon@elasticsearch.com) wrote:
> 
> > No, there isn't a big difference (just the parsing of the query\_string). Note, I suggest you use and filter and not bool filter, uses less memory.  
> > On Wednesday, March 9, 2011 at 11:04 PM, Lee Parker wrote:
> > 
> > > Is there any performance difference between using the match\_all query vs a query\_string of "_:_"?
> > > 
> > > I ask because I'm trying to get a list of documents which match a set of fields, but want to match all documents. The full query looks like this:
> > > 
> > > {  
> > > "query": {  
> > > "filtered": {  
> > > "query": {  
> > > "query\_string": {  
> > > "query": "_:_",  
> > > "default\_operator": "AND"  
> > > }  
> > > },  
> > > "filter": {  
> > > "bool": {  
> > > "must": [{  
> > > "term": {  
> > > "campaign\_id": "1"  
> > > }  
> > > }, {  
> > > "terms": {  
> > > "hash": ["4f7b7b2f105b8b6951f919e657ca6509", "e44036caa080c94b91aab963bfccc8c8"]  
> > > }  
> > > }]  
> > > }  
> > > }  
> > > }  
> > > },  
> > > "size": 30,  
> > > "from": 0,  
> > > "sort": [{  
> > > "date": {  
> > > "reverse": true  
> > > }  
> > > }, "\_score"]  
> > > }
> > > 
> > > or
> > > 
> > > {  
> > > "query": {  
> > > "filtered": {  
> > > "query": {  
> > > "match\_all": {}  
> > > },  
> > > "filter": {  
> > > "bool": {  
> > > "must": [{  
> > > "term": {  
> > > "campaign\_id": "1"  
> > > }  
> > > }, {  
> > > "terms": {  
> > > "hash": ["4f7b7b2f105b8b6951f919e657ca6509", "e44036caa080c94b91aab963bfccc8c8"]  
> > > }  
> > > }]  
> > > }  
> > > }  
> > > }  
> > > },  
> > > "size": 30,  
> > > "from": 0,  
> > > "sort": [{  
> > > "date": {  
> > > "reverse": true  
> > > }  
> > > }, "\_score"]  
> > > }
> > > 
> > > ## Lee
> > > 
> > > "It doesn't matter whether you are liberal or conservative, but it's dangerous to always think with exclamation points instead of question marks."  
> > > by Marty Beckerman

---

<div class="post-metadata">

**Author:** ![Lee\_Parker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lee_parker/32/3250_2.png) [@Lee\_Parker](https://discuss.elastic.co/u/Lee_Parker)\
**Post date:** [March 31, 2011, 4:25pm UTC](https://discuss.elastic.co/t/match-all-vs/4069/5 "2011-03-31T16:25:01Z")

</div>

Ahh. Can you nest "and" and "not" filters? I can't tell from the  
documentation if that is possible.

## Lee

"It doesn't matter whether you are liberal or conservative, but it's  
dangerous to always think with exclamation points instead of question  
marks."  
by Marty Beckerman  
On Thu, Mar 31, 2011 at 11:21 AM, Shay Banon  
[shay.banon@elasticsearch.com](mailto:shay.banon@elasticsearch.com)wrote:

> I meant `and` filter:  
> [Elastic — The Search AI Company | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/and-filter.html) (And  
> also `or` and `not`).
> 
> On Thursday, March 31, 2011 at 5:52 PM, Lee Parker wrote:
> 
> I'm using bool here because I may need to filter on multiple fields. Is it  
> possible to do that without using bool? The documentation doesn't specify  
> this and if I tried to add more than one filter to the request, it didn't  
> parse.
> 
> ## Lee
> 
> "It doesn't matter whether you are liberal or conservative, but it's  
> dangerous to always think with exclamation points instead of question  
> marks."  
> by Marty Beckerman  
> On Thu, Mar 10, 2011 at 12:12 AM, Shay Banon \<[shay.banon@elasticsearch.com](mailto:shay.banon@elasticsearch.com)
> 
> > wrote:
> 
> No, there isn't a big difference (just the parsing of the query\_string). Note,  
> I suggest you use and filter and not bool filter, uses less memory.
> 
> On Wednesday, March 9, 2011 at 11:04 PM, Lee Parker wrote:
> 
> Is there any performance difference between using the match\_all query vs a  
> query\_string of "_:_"?
> 
> I ask because I'm trying to get a list of documents which match a set of  
> fields, but want to match all documents. The full query looks like this:
> 
> {  
> "query": {  
> "filtered": {  
> "query": {  
> "query\_string": {  
> "query": "_:_",  
> "default\_operator": "AND"  
> }  
> },  
> "filter": {  
> "bool": {  
> "must": [{  
> "term": {  
> "campaign\_id": "1"  
> }  
> }, {  
> "terms": {  
> "hash": ["4f7b7b2f105b8b6951f919e657ca6509",  
> "e44036caa080c94b91aab963bfccc8c8"]  
> }  
> }]  
> }  
> }  
> }  
> },  
> "size": 30,  
> "from": 0,  
> "sort": [{  
> "date": {  
> "reverse": true  
> }  
> }, "\_score"]  
> }
> 
> or
> 
> {  
> "query": {  
> "filtered": {  
> "query": {  
> "match\_all": {}  
> },  
> "filter": {  
> "bool": {  
> "must": [{  
> "term": {  
> "campaign\_id": "1"  
> }  
> }, {  
> "terms": {  
> "hash": ["4f7b7b2f105b8b6951f919e657ca6509",  
> "e44036caa080c94b91aab963bfccc8c8"]  
> }  
> }]  
> }  
> }  
> }  
> },  
> "size": 30,  
> "from": 0,  
> "sort": [{  
> "date": {  
> "reverse": true  
> }  
> }, "\_score"]  
> }
> 
> ## Lee
> 
> "It doesn't matter whether you are liberal or conservative, but it's  
> dangerous to always think with exclamation points instead of question  
> marks."  
> by Marty Beckerman

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [March 31, 2011, 4:54pm UTC](https://discuss.elastic.co/t/match-all-vs/4069/6 "2011-03-31T16:54:23Z")

</div>

Sure, within a not filter, for example, you can place any other filter. Within an and filter, you can place any number (and types) of other filters.  
On Thursday, March 31, 2011 at 6:25 PM, Lee Parker wrote:

> Ahh. Can you nest "and" and "not" filters? I can't tell from the documentation if that is possible.
> 
> ## Lee
> 
> "It doesn't matter whether you are liberal or conservative, but it's dangerous to always think with exclamation points instead of question marks."  
> by Marty Beckerman  
> On Thu, Mar 31, 2011 at 11:21 AM, Shay Banon [shay.banon@elasticsearch.com](mailto:shay.banon@elasticsearch.com) wrote:
> 
> > I meant `and` filter: [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/and-filter.html) (And also `or` and `not`).  
> > On Thursday, March 31, 2011 at 5:52 PM, Lee Parker wrote:
> > 
> > > I'm using bool here because I may need to filter on multiple fields. Is it possible to do that without using bool? The documentation doesn't specify this and if I tried to add more than one filter to the request, it didn't parse.
> > > 
> > > ## Lee
> > > 
> > > "It doesn't matter whether you are liberal or conservative, but it's dangerous to always think with exclamation points instead of question marks."  
> > > by Marty Beckerman  
> > > On Thu, Mar 10, 2011 at 12:12 AM, Shay Banon [shay.banon@elasticsearch.com](mailto:shay.banon@elasticsearch.com) wrote:
> > > 
> > > > No, there isn't a big difference (just the parsing of the query\_string). Note, I suggest you use and filter and not bool filter, uses less memory.  
> > > > On Wednesday, March 9, 2011 at 11:04 PM, Lee Parker wrote:
> > > > 
> > > > > Is there any performance difference between using the match\_all query vs a query\_string of "_:_"?
> > > > > 
> > > > > I ask because I'm trying to get a list of documents which match a set of fields, but want to match all documents. The full query looks like this:
> > > > > 
> > > > > {  
> > > > > "query": {  
> > > > > "filtered": {  
> > > > > "query": {  
> > > > > "query\_string": {  
> > > > > "query": "_:_",  
> > > > > "default\_operator": "AND"  
> > > > > }  
> > > > > },  
> > > > > "filter": {  
> > > > > "bool": {  
> > > > > "must": [{  
> > > > > "term": {  
> > > > > "campaign\_id": "1"  
> > > > > }  
> > > > > }, {  
> > > > > "terms": {  
> > > > > "hash": ["4f7b7b2f105b8b6951f919e657ca6509", "e44036caa080c94b91aab963bfccc8c8"]  
> > > > > }  
> > > > > }]  
> > > > > }  
> > > > > }  
> > > > > }  
> > > > > },  
> > > > > "size": 30,  
> > > > > "from": 0,  
> > > > > "sort": [{  
> > > > > "date": {  
> > > > > "reverse": true  
> > > > > }  
> > > > > }, "\_score"]  
> > > > > }
> > > > > 
> > > > > or
> > > > > 
> > > > > {  
> > > > > "query": {  
> > > > > "filtered": {  
> > > > > "query": {  
> > > > > "match\_all": {}  
> > > > > },  
> > > > > "filter": {  
> > > > > "bool": {  
> > > > > "must": [{  
> > > > > "term": {  
> > > > > "campaign\_id": "1"  
> > > > > }  
> > > > > }, {  
> > > > > "terms": {  
> > > > > "hash": ["4f7b7b2f105b8b6951f919e657ca6509", "e44036caa080c94b91aab963bfccc8c8"]  
> > > > > }  
> > > > > }]  
> > > > > }  
> > > > > }  
> > > > > }  
> > > > > },  
> > > > > "size": 30,  
> > > > > "from": 0,  
> > > > > "sort": [{  
> > > > > "date": {  
> > > > > "reverse": true  
> > > > > }  
> > > > > }, "\_score"]  
> > > > > }
> > > > > 
> > > > > ## Lee
> > > > > 
> > > > > "It doesn't matter whether you are liberal or conservative, but it's dangerous to always think with exclamation points instead of question marks."  
> > > > > by Marty Beckerman

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:09am UTC](https://discuss.elastic.co/t/match-all-vs/4069/7 "2017-07-06T04:09:03Z")

</div>


