# Matching phrase in a elasticsearch query

**URL:** <https://discuss.elastic.co/t/matching-phrase-in-a-elasticsearch-query/124904>\
**Category:** Elasticsearch\
**Created:** [March 21, 2018, 5:01am UTC](https://discuss.elastic.co/t/matching-phrase-in-a-elasticsearch-query/124904 "2018-03-21T05:01:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aniketkk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aniketkk/32/96814_2.png) [@aniketkk](https://discuss.elastic.co/u/aniketkk)\
**Post date:** [March 21, 2018, 5:01am UTC](https://discuss.elastic.co/t/matching-phrase-in-a-elasticsearch-query/124904/1 "2018-03-21T05:01:42Z")

</div>

Hi, I am trying to do a query where the timestamp is 27/Feb/2018. The Elasticsearch version is 1.5

My query looks like this

```
{
	"query": {
		"multi_match": {
			"query": "27/Feb/2018",
			"fields": ["timestamp"],
			"minimum_should_match": "100%"
		}
	}
}

```

But I am getting results where a document looks like this

```
      {
            "_index": "pyramid-dev",
            "_type": "request-logs",
            "_id": "AWGKTEccLurs6cVv0N0H",
            "_score": 11.130073,
            "_source": {
                "path": "/var/log/nginx/access.log",
                "timestamp": "02/Feb/2018:14:45:27 +0000"
            }
        }

```

As you can see it is not 27/Feb but still I am getting the result as 27 is present in the field.

How to solve this?

I tried using phrase query but it says  
`IllegalStateException[field \"timestamp\" was indexed without position data; cannot run PhraseQuery (term=27)]`

And I cant use prefix query also as there is no **not\_analyzed** version of it.  
The timestamp field is a string.

Please help me how to solve this.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 21, 2018, 6:22am UTC](https://discuss.elastic.co/t/matching-phrase-in-a-elasticsearch-query/124904/2 "2018-03-21T06:22:44Z")

</div>

You should better make `timestamp` field as a `date` datatype.  
Change your mapping and reindex.

---

<div class="post-metadata">

**Author:** ![aniketkk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aniketkk/32/96814_2.png) [@aniketkk](https://discuss.elastic.co/u/aniketkk)\
**Post date:** [March 21, 2018, 6:27am UTC](https://discuss.elastic.co/t/matching-phrase-in-a-elasticsearch-query/124904/3 "2018-03-21T06:27:11Z")

</div>

Hi @dadoonet. I agree that it should have been a date field. But I don't have the authority to change the mappings. THere are multiple teams using it and have no control over it.

Is there any to get what I want through the query?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 21, 2018, 6:51am UTC](https://discuss.elastic.co/t/matching-phrase-in-a-elasticsearch-query/124904/4 "2018-03-21T06:51:54Z")

</div>

May be searching with "+Feb +27" but that will give strange results as well like when 27 is the minute number.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2018, 6:52am UTC](https://discuss.elastic.co/t/matching-phrase-in-a-elasticsearch-query/124904/5 "2018-04-18T06:52:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
