# \[multi\_match\] unknown token \[START\_ARRAY\] after \[query\]

**URL:** <https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415>\
**Category:** Elasticsearch\
**Created:** [March 26, 2025, 11:54am UTC](https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415 "2025-03-26T11:54:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![anujtom](https://avatars.discourse-cdn.com/v4/letter/a/f4b2a3/32.png) [@anujtom](https://discuss.elastic.co/u/anujtom)\
**Post date:** [March 26, 2025, 11:54am UTC](https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415/1 "2025-03-26T11:54:43Z")

</div>

Hi,

I am trying to fetch fields within same attribute to send response.

Fetch "abc" "yui" pattern from full\_message attribute.

GET /my\_index/\_search  
{  
"query": {  
"multi\_match": {  
"query": ["abc" , "yui"] ,  
"fields": "full\_message"  
}  
}  
}

Response:-

{  
"error": {  
"root\_cause": [  
{  
"type": "parsing\_exception",  
"reason": "[multi\_match] unknown token [START\_ARRAY] after [query]",  
"line": 4,  
"col": 18  
}  
],  
"type": "parsing\_exception",  
"reason": "[multi\_match] unknown token [START\_ARRAY] after [query]",  
"line": 4,  
"col": 18  
},  
"status": 400  
}

Can someone please help

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [March 26, 2025, 12:10pm UTC](https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415/2 "2025-03-26T12:10:59Z")

</div>

Hi @anujtom Welcome!

The query is incorrect, try as the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-multi-match-query.html) says:

```auto
GET /_search
{
  "query": {
    "multi_match" : {
      "query": "this is a test", 
      "fields": ["subject", "message"] 
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![anujtom](https://avatars.discourse-cdn.com/v4/letter/a/f4b2a3/32.png) [@anujtom](https://discuss.elastic.co/u/anujtom)\
**Post date:** [May 20, 2025, 11:36am UTC](https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415/3 "2025-05-20T11:36:57Z")

</div>

Hi,

GET /index1/\_search  
{  
"size": 10000,  
"query": {  
"bool": {  
"filter": [  
{  
"match\_phrase": {  
"agent.name": ["localhost1","localhost2",""localhost3"]  
}  
}  
]  
}  
},  
"fields": [  
"full\_message",  
"agent.name"  
],  
"\_source": false  
}

I am trying to return full\_message and agent\_name from all the hosts(localhost1, localhost2...localhostN) but it seems array input not working with match\_phrase

Below is the error:-

{  
"error": {  
"root\_cause": [  
{  
"type": "x\_content\_parse\_exception",  
"reason": "[1:122] [bool] failed to parse field [filter]"  
}  
],  
"type": "x\_content\_parse\_exception",  
"reason": "[1:122] [bool] failed to parse field [filter]",  
"caused\_by": {  
"type": "illegal\_argument\_exception",  
"reason": "Expected text at 1:122 but found START\_ARRAY"  
}  
},  
"status": 400  
}

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [May 20, 2025, 12:26pm UTC](https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415/4 "2025-05-20T12:26:37Z")

</div>

Hi,

There seems to be a syntax error for below : 2 quotes instead of 1  
""localhost3"

```auto
GET /index1/_search
{
"size": 10000,
"query": {
"bool": {
"filter": [
{
"match_phrase": {
"agent.name": ["localhost1","localhost2",""localhost3"]
}
}
]
}
},
"fields": [
"full_message",
"agent.name"
],
"_source": false
}

```

Thanks!!

---

<div class="post-metadata">

**Author:** ![anujtom](https://avatars.discourse-cdn.com/v4/letter/a/f4b2a3/32.png) [@anujtom](https://discuss.elastic.co/u/anujtom)\
**Post date:** [May 20, 2025, 12:57pm UTC](https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415/5 "2025-05-20T12:57:23Z")

</div>

Not working even after removing wrong syntax by mistake:-

GET /index1/\_search  
{  
"size": 10000,  
"query": {  
"bool": {  
"filter": [  
{  
"match\_phrase": {  
"agent.name": ["localhost1","localhost2","localhost3"]  
}  
}  
]  
}  
},  
"fields": [  
"full\_message",  
"agent.name"  
],  
"\_source": false  
}

My simple ask is to return full\_message and agent\_name field from all the Hosts which mentioned in match\_phrase condition  
Error:-

{  
"error": {  
"root\_cause": [  
{  
"type": "x\_content\_parse\_exception",  
"reason": "[1:122] [bool] failed to parse field [filter]"  
}  
],  
"type": "x\_content\_parse\_exception",  
"reason": "[1:122] [bool] failed to parse field [filter]",  
"caused\_by": {  
"type": "illegal\_argument\_exception",  
"reason": "Expected text at 1:122 but found START\_ARRAY"  
}  
},  
"status": 400  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 20, 2025, 1:14pm UTC](https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415/6 "2025-05-20T13:14:48Z")

</div>

I don't think I have ever seen `match_phrase` used with an array. Maybe try to a `bool` query with 3 separate `match_phrase` queries under `should` clauses?
