# Multiple range queries within "should" clause

**URL:** <https://discuss.elastic.co/t/multiple-range-queries-within-should-clause/75735>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 20, 2017, 12:47pm UTC](https://discuss.elastic.co/t/multiple-range-queries-within-should-clause/75735 "2017-02-20T12:47:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![emirozer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emirozer/32/15694_2.png) [@emirozer](https://discuss.elastic.co/u/emirozer)\
**Post date:** [February 20, 2017, 12:47pm UTC](https://discuss.elastic.co/t/multiple-range-queries-within-should-clause/75735/1 "2017-02-20T12:47:16Z")

</div>

Hi!

I wanted to ask here first before opening an issue in github as i am not %100 sure i am doing the correct thing.

I use the hosted elastic cloud from you. es version is 5.1.2

Utilizing the following mapping:

```auto
{
  "template": "infra_metrics-*",
  "settings": {
    "index": {
      "refresh_interval": "5s"
    }
  },
  "mappings": {
    "_default_": {
      "dynamic_templates": [
        {
          "strings": {
            "match": "*",
            "match_mapping_type": "string",
            "mapping": { "type": "string", "doc_values": true, "index": "not_analyzed" }
          }
        }
      ],
      "_all": { "enabled": false },
      "_source": { "enabled": true },
      "properties": {
        "timestamp": { "type": "date", "doc_values": true},
        "source_vm": { "type": "keyword", "doc_values": true },
        "cpu_user_percentage": { "type": "float", "doc_values": true },
        "cpu_sys_percentage": { "type": "float", "doc_values": true },
        "cpu_wait_percentage": { "type": "float", "doc_values": true },
        "mem_percentage": { "type": "float", "doc_values": true },
        "ephemeral_disk_percentage": { "type": "float", "doc_values": true },
        "persistent_disk_percentage": { "type": "float", "doc_values": true },
        "system_disk_percentage": { "type": "float", "doc_values": true },
        "swap_percentage": { "type": "float", "doc_values": true }
      }
    }
  }
}

```

I create the following watch

```auto
{
    "trigger": {
        "schedule": {
            "interval": "5m"
        }
    },
    "input": {
        "search": {
            "request": {
                "indices": [
                    "infra_metrics-*"
                ],
                "body": {
                    "query": {
                        "bool": {
                            "filter": {
                                "range": {
                                    "timestamp": {
                                        "from": "now-5m",
                                        "to": "now"
                                    }
                                }
                            },
                            "should": [
                                {
                                    "range": {
                                        "cpu_sys_percentage": {
                                            "gte": 80.0
                                        }
                                    }
                                },
                                {
                                    "range": {
                                        "cpu_user_percentage": {
                                            "gte": 80.0
                                        }
                                    }
                                },
                                {
                                    "range": {
                                        "cpu_wait_percentage": {
                                            "gte": 80.0
                                        }
                                    }
                                }
                            ]
                        }
                    }
                }
            }
        }
    },
    "condition": {
        "compare": {
            "ctx.payload.hits.total": {
                "gt": 0
            }
        }
    }

```

I removed the last action part.

So what happens is that this watch executes and returns all the datapoints in the timestamp filter i applied.  
Its like all the should ranges are ignored.

if i swap **should with must** the watch works as expected.

Am i doing something wrong? basically i want to trigger an email if one of these values go above 80.0

Thx,

Emir

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 20, 2017, 9:37pm UTC](https://discuss.elastic.co/t/multiple-range-queries-within-should-clause/75735/2 "2017-02-20T21:37:53Z")

</div>

Hey,

the main question is, what do you expect, when you configure the `should` query? It seems you expect that all conditions have to match, however this is what the `must` query is for. The `should`query contributes to score. You may want to check out the documentation for the bool query [https://www.elastic.co/guide/en/elasticsearch/reference/5.2/query-dsl-bool-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.2/query-dsl-bool-query.html) - which states, that if you have a `filter`clause, all parts of a should query become optional.

--Alex

---

<div class="post-metadata">

**Author:** ![emirozer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emirozer/32/15694_2.png) [@emirozer](https://discuss.elastic.co/u/emirozer)\
**Post date:** [February 22, 2017, 2:07pm UTC](https://discuss.elastic.co/t/multiple-range-queries-within-should-clause/75735/3 "2017-02-22T14:07:45Z")

</div>

Well i didn't know about it being a contributor to the score. as far as the documentation goes, i expect **should** to behave **exactly** like SQL **OR**

So, In the above watch, when i run it, i expect the following:

- Return search results if there is a hit of one or more conditions in the should block

What do i get:

- All entries of that index within the timestamp range i give.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 22, 2017, 3:07pm UTC](https://discuss.elastic.co/t/multiple-range-queries-within-should-clause/75735/4 "2017-02-22T15:07:51Z")

</div>

Hey,

there's the catch. It does not behave at all like an SQL OR. The above linked [docs](https://www.elastic.co/guide/en/elasticsearch/reference/5.2/query-dsl-bool-query.html) state

> In a boolean query with no must or filter clauses, one or more should clauses must match a document.

As you specified a `filter` in the bool query, none of the should clauses have to match. The interesting part for you however is the next note about a bool query in a filter context. If you put a new bool query with the filter and should clauses inside of the `filter`, then the query will behave as you expect.

--Alex

---

<div class="post-metadata">

**Author:** ![emirozer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emirozer/32/15694_2.png) [@emirozer](https://discuss.elastic.co/u/emirozer)\
**Post date:** [February 22, 2017, 3:14pm UTC](https://discuss.elastic.co/t/multiple-range-queries-within-should-clause/75735/5 "2017-02-22T15:14:24Z")

</div>

thank you @spinscale that clarifies it for me!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2017, 3:14pm UTC](https://discuss.elastic.co/t/multiple-range-queries-within-should-clause/75735/6 "2017-03-22T15:14:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
