# Multi-match query

**URL:** <https://discuss.elastic.co/t/multi-match-query/134838>\
**Category:** Elasticsearch\
**Created:** [June 6, 2018, 3:31pm UTC](https://discuss.elastic.co/t/multi-match-query/134838 "2018-06-06T15:31:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![pli](https://avatars.discourse-cdn.com/v4/letter/p/85e7bf/32.png) [@pli](https://discuss.elastic.co/u/pli)\
**Post date:** [June 6, 2018, 3:31pm UTC](https://discuss.elastic.co/t/multi-match-query/134838/1 "2018-06-06T15:31:58Z")

</div>

Hi All,  
I try to find a value ( from different field" ) in two index. ( and return false if the value is not present in the two indexes.  
here is my examples.  
I have an index ( known\_issues ) filled with the current error already identified

by ex: 2 issues

```
    POST /known_issues/doc
    {
      "id": "issue1",
      "description": "file not found"
    }

POST /known_issues/doc
{
  "id": "issue2",
  "description": "syntax error"
}

```

and another index with the log of each test.

```
POST /test_log/doc
{
  "id": "id1",
  "test_case": "a test case",
  "result": "syntax error"
}

POST /test_log/doc
{
  "id": "id2",
  "test_case": "another test case",
  "result": "success"
}

```

I would like to find by a query , all tests ( from test\_log) with an issue already identified ( from known\_issues )

my query is :

```
GET /known_issues,test_log/_search
{
  "query": {
       "multi_match": {
          "query": "syntax error",
          "type": "phrase", 
          "fields": [
            "description",
            "result"
          ],
          "operator": "and" 
        }         
 }
}

```

I'm really happy, the request finds 2 hits, one in each index.

```
{
  "took": 0,
   ....
  },
  "hits": {
    **"total": 2,**
    "hits": [
      {
        "_index": "known_issues",
        "_source": {
          "id": "issue2",
          "description": "syntax error"
        }
      },
      {
        "_index": "test_log",
        "_source": {
          "id": "id1",
          "test_case": "a test case",
          "result": "syntax error"
        }
      }
    ]
  }
}

```

BUT ☹  
, this request returns 1 hit , it there is no entries in known\_issues index ! why ?!  
the operator "and" did not do what i was expecting.  
ex :

`delete known_issues`

```
POST /known_issues/doc
{
  "id": "issue1",
  "description": "file not found"
}

POST /known_issues/doc
{
  "id": "issue2",
  "description": "syntax_ERROR"
}

my query returns : 
{
  "took": 0,
  "timed_out": false,
  "_shards": {...},
  "hits": {
    **"total": 1,**
    "max_score": 0.5753642,
    "hits": [
      {
        "_index": "test_log",
        "_type": "doc",
        "_id": "MkOK1WMBOroXuELibpK5",
        "_score": 0.5753642,
        "_source": {
          "id": "id1",
          "test_case": "a test case",
          "result": "syntax error"
        }
      }
    ]
  }
}

```

I tested with a bool, must ,should, etc etc .... nothing work!  
Shall i change my idea ? in a python script, i can get all known issues and make a query for each test\_log ? but i lose the power of ES;  
Any help , will be welcome  
Thanks  
Philippe.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 6, 2018, 3:52pm UTC](https://discuss.elastic.co/t/multi-match-query/134838/2 "2018-06-06T15:52:47Z")

</div>

Have a look at this:

```auto
POST _analyze
{
  "text": ["syntax_ERROR"]
}
POST _analyze
{
  "text": ["syntax ERROR"]
}

```

This is producing:

```auto
# POST _analyze
{
  "tokens": [
    {
      "token": "syntax_error",
      "start_offset": 0,
      "end_offset": 12,
      "type": "<ALPHANUM>",
      "position": 0
    }
  ]
}

# POST _analyze
{
  "tokens": [
    {
      "token": "syntax",
      "start_offset": 0,
      "end_offset": 6,
      "type": "<ALPHANUM>",
      "position": 0
    },
    {
      "token": "error",
      "start_offset": 7,
      "end_offset": 12,
      "type": "<ALPHANUM>",
      "position": 1
    }
  ]
}

```

As you can see, what is indexed or searched is totally different.  
As you indexed basically `syntax` and `error`, obviously `syntax_error` does not match any of those 2 terms.

---

<div class="post-metadata">

**Author:** ![pli](https://avatars.discourse-cdn.com/v4/letter/p/85e7bf/32.png) [@pli](https://discuss.elastic.co/u/pli)\
**Post date:** [June 7, 2018, 8:22am UTC](https://discuss.elastic.co/t/multi-match-query/134838/3 "2018-06-07T08:22:36Z")

</div>

Thank David,

I understand you example.  
but what I don't understand it's why the query find 1 hits.  
The fact I put a different imput in know\_issues is normal. it was to make an example where nothing matches. I was expecting 0 hits.

What I want is :  
If a result in test\_log AND description in known\_issue matches , my query shall return TRUE  
BUT , if any input in know\_issues matches , my query shall return FALSE

I use the type "phrase" , in order to match exactly the exact string. the descriotion/result is not only a simple 'syntax error" but it can be a long text.

/philippe.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 7, 2018, 8:27pm UTC](https://discuss.elastic.co/t/multi-match-query/134838/4 "2018-06-07T20:27:40Z")

</div>

> [@pli](#):
>
> but what I don't understand it's why the query find 1 hits.

Because the document matches. You are searching for `syntax error` and `test_log/doc/MkOK1WMBOroXuELibpK5` is:

```
{
      "id": "id1",
      "test_case": "a test case",
      "result": "syntax error"
}

```

> [@pli](#):
>
> What I want is :  
> If a result in test\_log AND description in known\_issue matches , my query shall return TRUE  
> BUT , if any input in know\_issues matches , my query shall return FALSE

You can not do joins in elasticsearch so this is not really doable in one request IMO.  
It's always better to perform the join at index time while injecting your data.

For example, index:

```auto
POST /test_log/doc
{
  "id": "id1",
  "test_case": "a test case",
  "result": "syntax error",
  "known": true
}

POST /test_log/doc
{
  "id": "id2",
  "test_case": "another test case",
  "result": "success",
  "known": false
}

```

How to compute `known`? Well. By doing lookups at index time.  
I described something like this (not the same use case though) in a recent blog post: [Enriching Your Postal Addresses With the Elastic Stack - Part 2 | Elastic Blog](https://www.elastic.co/blog/enriching-your-postal-addresses-with-the-elastic-stack-part-2)

May be that could help.

---

<div class="post-metadata">

**Author:** ![pli](https://avatars.discourse-cdn.com/v4/letter/p/85e7bf/32.png) [@pli](https://discuss.elastic.co/u/pli)\
**Post date:** [June 8, 2018, 2:02pm UTC](https://discuss.elastic.co/t/multi-match-query/134838/5 "2018-06-08T14:02:03Z")

</div>

Thank you David, It 's working fine !!!!

During indexation of test\_log, I search if a known\_issue matches the error log.  
I adapted your example to my case.

Have a nice week-end !  
Best regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2018, 2:02pm UTC](https://discuss.elastic.co/t/multi-match-query/134838/6 "2018-07-06T14:02:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
