# Multi match query searching on fields not specified

**URL:** <https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711>\
**Category:** Elasticsearch\
**Created:** [September 5, 2015, 2:39am UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711 "2015-09-05T02:39:34Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_D\_Ament](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_d_ament/32/764_2.png) [@John\_D\_Ament](https://discuss.elastic.co/u/John_D_Ament)\
**Post date:** [September 5, 2015, 2:39am UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/1 "2015-09-05T02:39:34Z")

</div>

I've setup index settings on my cluster that include an ngram analyzer. The definition looks like

```
{
  "index": {
    "analysis": {
      "filter": {
        "ngrams_filter": {
          "type": "nGram",
          "min_gram": 2,
          "max_gram": 20
        }
      },
      "analyzer": {
        "ngrams_analyzer": {
          "type": "custom",
          "tokenizer": "standard",
          "filter": [
            "lowercase",
            "ngrams_filter"
          ]
        }
      }
    }
  }
}

```

After adding references to this analyzer in my mappings, my multi match queries began returning weird results. Specifically, I index documents that look like

```
{
  "foo": {
    "type": "bob",
    "value": "sam"
  }
}

```

My multimatch is set to query explicitly on "foo.value", when I search on sa/sam it works, however since applying these settings searches for bo/bob return matches as well. If I'm only searching on foo.value I wouldn't expect this.

Any idea?

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [September 5, 2015, 3:04am UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/2 "2015-09-05T03:04:56Z")

</div>

Any chance you can show a complete example with mappings, queries and results?

---

<div class="post-metadata">

**Author:** ![John\_D\_Ament](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_d_ament/32/764_2.png) [@John\_D\_Ament](https://discuss.elastic.co/u/John_D_Ament)\
**Post date:** [September 5, 2015, 3:42pm UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/3 "2015-09-05T15:42:54Z")

</div>

Sure. This is what the mapping looks like

```
"someType": {
  "_id": {
    "path": "objectId"
  },
  "properties": {
    "record": {
      "type": "object",
      "properties": {
        "fields": {
          "type": "object",
          "properties": {
            "Title": {
              "type": "object",
              "properties": {
                "value": {
                  "type": "string",
                  "analyzer": "ngrams_analyzer"
                },
                "className": {
                  "type": "string",
                  "include_in_all": false,
                  "index": "no"
                }
              }
            },
            "comments": {
              "type": "object",
              "properties": {
                "value": {
                  "type": "string",
                  "analyzer": "ngrams_analyzer"
                },
                "className": {
                  "type": "string",
                  "include_in_all": false,
                  "index": "no"
                }
              }
            }
          }
        }
      }
    }
  }
}

```

"className" is the attribute I referred to previously. My query is

```
{
  "multi_match": {
    "query" : "FooBar"
    "fields" : ["record.fields.*.value"]
    }
}

```

In this case, FooBar only appears in the className attribute, not the body of title or comments fields. If the explain helps let me know.

---

<div class="post-metadata">

**Author:** ![John\_D\_Ament](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_d_ament/32/764_2.png) [@John\_D\_Ament](https://discuss.elastic.co/u/John_D_Ament)\
**Post date:** [September 5, 2015, 6:13pm UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/4 "2015-09-05T18:13:17Z")

</div>

I just realized after posting this that the scores for this case were all extremely low. It seems like ES is finding partial matches on the search, but nothing concrete. To work around I"m going to set the min score to .5 to see how it goes.

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [September 5, 2015, 7:07pm UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/5 "2015-09-05T19:07:54Z")

</div>

So you are searching for `FooBar` and it give you back `bob`? Or these are completely unrelated examples? Sorry, I still cannot figure out what you are trying to do and what does and doesn't work. I would be glad to help if I could easily recreate the issue on my machine. Please see [https://www.elastic.co/help](https://www.elastic.co/help) for some suggestions about how to make your questions easier to understand. Thanks!

---

<div class="post-metadata">

**Author:** ![John\_D\_Ament](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_d_ament/32/764_2.png) [@John\_D\_Ament](https://discuss.elastic.co/u/John_D_Ament)\
**Post date:** [September 8, 2015, 11:22am UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/6 "2015-09-08T11:22:15Z")

</div>

Yes, this is the verbatim search content/terms. It's purposefully stupid sounding, but I did verify the issue exists with this content.

As best as I can tell, we're getting a very low score because a substring of "FooBar" matches against "bob", particular the "ob" parts. I'm not sure if this is the intended behavior for ngrams (to also break up the search term) but this is the only thing I can surmise. I would have expected a 0 score, but if it is breaking up the search term into ngrams as well this makes some sense to me.

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [September 8, 2015, 12:10pm UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/7 "2015-09-08T12:10:06Z")

</div>

Ok, now it makes more sense. Indeed, by default the same analyzer is used for both indexing and searching. So, during search the search term will be tokenized into n-grams and because by default mutli\_match applies "OR" [operator](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-match-query.html#_boolean) to all tokens it will match any field that has at least one matching n-gram present. In order to solve this problem you need to [replace](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-core-types.html#string) the search analyzer with an analyzer without the ngram filter.

---

<div class="post-metadata">

**Author:** ![John\_D\_Ament](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_d_ament/32/764_2.png) [@John\_D\_Ament](https://discuss.elastic.co/u/John_D_Ament)\
**Post date:** [September 8, 2015, 2:21pm UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/8 "2015-09-08T14:21:40Z")

</div>

How would I specify what analyzer to use for search? I'm assuming that this is against the search term only?

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [September 8, 2015, 2:26pm UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/9 "2015-09-08T14:26:17Z")

</div>

Sorry, just realized that the replace link that I posted above was pointing to a wrong page. The search analyzer can be set by using `search_analyzer` parameters in the field mapping. So in your case it would look like this:

```
"comments": {
    "type": "object",
    "properties": {
        "value": {
            "type": "string",
            "analyzer": "ngrams_analyzer",
            "search_analyzer": "standard"
        },
        "className": {
            "type": "string",
            "include_in_all": false,
            "index": "no"
        }
    }
}

```

See the search\_analyzer parameter in the [string mapping documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-core-types.html#string) for more information

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:51pm UTC](https://discuss.elastic.co/t/multi-match-query-searching-on-fields-not-specified/28711/10 "2017-07-05T23:51:38Z")

</div>


