# Must not apply in must query result

**URL:** <https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042>\
**Category:** Elasticsearch\
**Created:** [April 16, 2019, 9:29am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042 "2019-04-16T09:29:55Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dilip\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dilip_kumar/32/15459_2.png) [@Dilip\_Kumar](https://discuss.elastic.co/u/Dilip_Kumar)\
**Post date:** [April 16, 2019, 9:29am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/1 "2019-04-16T09:29:56Z")

</div>

Need to filter apply document having must FE=5 but if some FE=5 also having FE=17, then ignore those document. Please suggest

"query": {  
"bool": {  
"must": [  
{  
"term": {  
"FE": {  
"value": "5"  
}  
}  
},  
{  
"range": {  
"DT": {  
"gte": "2019-04-16",  
"lte": "2019-04-16"  
}  
}  
}  
],  
"must\_not": [  
{  
"term": {  
"FE": {  
"value": "17"  
}  
}  
}  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 16, 2019, 10:38am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/2 "2019-04-16T10:38:51Z")

</div>

Can't really tell but it looks ok.

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.

If you can't make it work I suggest that you provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

A full reproduction script will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.

---

<div class="post-metadata">

**Author:** ![Dilip\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dilip_kumar/32/15459_2.png) [@Dilip\_Kumar](https://discuss.elastic.co/u/Dilip_Kumar)\
**Post date:** [April 16, 2019, 10:47am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/3 "2019-04-16T10:47:54Z")

</div>

```
ok i will take care , this query is ok but result is not coming accordingly,
suppose some document having data like this :slight_smile:`

```

` { CID=1,FE=5 }  
{ CID=1,FE=17 }  
{ CID=2,FE=5 }

Suppose i have three documents, i need CID only those documents having FE=5 only and not require those having FE=5 and FE17 both

When i have applied my query both records are coming.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 16, 2019, 2:23pm UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/4 "2019-04-16T14:23:02Z")

</div>

As I said. Provide a script someone can start from to help you.

---

<div class="post-metadata">

**Author:** ![Dilip\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dilip_kumar/32/15459_2.png) [@Dilip\_Kumar](https://discuss.elastic.co/u/Dilip_Kumar)\
**Post date:** [April 17, 2019, 4:33am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/5 "2019-04-17T04:33:12Z")

</div>

I have some records having RE =5 and RE =17 , I need those records only having RE=5 but not those having RE=5 and RE=17 both. Please help:

My sample records :  
{

```
    "_source": {
      "RE": "17",
      "RT": "278",
      "PT": "2019-04-16T02:28:01",
      "DT": "2019-04-16T02:15:18",
      "ZI": "221853184142816817"
    }
  },
  {

    "_source": {
      "RE": "5",
      "RT": "278",
      "PT": "2019-04-16T02:28:01",
      "DT": "2019-04-16T02:15:18",
      "ZI": "221853184142816817"
    }
  },
  {

    "_source": {
      "RE": "5",
      "RT": "278",
      "PT": "2019-04-16T14:28:01",
      "DT": "2019-04-16T14:15:18",
      "ZI": "2218531841428168"
    }
  },
  {
    "_source": {
      "RE": "5",
      "RT": "270",
      "PT": "2019-04-15T14:28:01",
      "DT": "2019-04-15T14:15:18",
      "ZI": "2218531841428168"
    }
  }

```

My query is  
{  
"query": {  
"bool": {  
"must": {  
"bool": {  
"must\_not": [  
{  
"term": {  
"RE": "17"  
}  
}  
],  
"must": [  
{  
"term": {  
"RE": "5"  
}  
}  
]  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 17, 2019, 7:51am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/6 "2019-04-17T07:51:25Z")

</div>

I'd probably replace the first `must` by a `should`.

Then inside have 2 queries:

- the bool one you already defined
- a term query on RE=5

---

<div class="post-metadata">

**Author:** ![Dilip\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dilip_kumar/32/15459_2.png) [@Dilip\_Kumar](https://discuss.elastic.co/u/Dilip_Kumar)\
**Post date:** [April 17, 2019, 9:02am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/7 "2019-04-17T09:02:06Z")

</div>

> [@dadoonet](#):
>
> term query on RE=5

Thanks for reply , But please help me for query structure

---

<div class="post-metadata">

**Author:** ![Dilip\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dilip_kumar/32/15459_2.png) [@Dilip\_Kumar](https://discuss.elastic.co/u/Dilip_Kumar)\
**Post date:** [April 17, 2019, 10:26am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/8 "2019-04-17T10:26:06Z")

</div>

Hi dadoonet, please view updated query according to your instruction, but still that records is coming having 17 and 5 both

> ```
> "query": {
> "bool": {
> "should": [
> {
> "bool": {
> "must": [
> {
> "term": {
> "RE": "5"
> }
> }
> ]
> }
> },
> {
> "bool": {
> "must": [
> {
> "term": {
> "RE": "5"
> }
> }
> ],
> "must_not": [
> {
> "term": {
> "RE": {
> "value": "17"
> }
> }
> }
> ]
> }
> }
> ]
> }
> }
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 17, 2019, 10:50am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/9 "2019-04-17T10:50:05Z")

</div>

Could you provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

A full reproduction script will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.

---

<div class="post-metadata">

**Author:** ![Dilip\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dilip_kumar/32/15459_2.png) [@Dilip\_Kumar](https://discuss.elastic.co/u/Dilip_Kumar)\
**Post date:** [April 17, 2019, 10:54am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/10 "2019-04-17T10:54:15Z")

</div>

Yes please i have spent 2 days for this`{ "query": { "bool": { "should": [{ "bool": { "must": [ { "term": { "RE": "5" } }], "must_not": [{ "term": { "RE": { "value": "17" } } }] } } , { "bool": { "must": [{ "term": { "RE": "5" } }] } } ] } } }`

This records should not come because as you can see ZI=221853184142816817  
belongs to those having RE=17

```
 "_source": {
  "RE": "5",
  "RT": "278",
  "PT": "2019-04-16T02:28:01",
  "DT": "2019-04-16T02:15:18",
  "ZI": "221853184142816817"
}

```

},

---

<div class="post-metadata">

**Author:** ![Dilip\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dilip_kumar/32/15459_2.png) [@Dilip\_Kumar](https://discuss.elastic.co/u/Dilip_Kumar)\
**Post date:** [April 17, 2019, 11:56am UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/11 "2019-04-17T11:56:08Z")

</div>

Hi dadoonet please help for query structure

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 17, 2019, 2:30pm UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/12 "2019-04-17T14:30:05Z")

</div>

You have been wasting a lot of time not giving a script that reproduces your problem. But lucky you, although on holidays, I had some few spare minutes to write one for you.

```auto
DELETE test
PUT test/_doc/1
{
  "RE": "5"
}
PUT test/_doc/2
{
  "RE": "17"
}
GET test/_search
{
  "query": {
    "bool": {
      "should": [
        {
          "bool": {
            "must": [
              {
                "term": {
                  "RE": "5"
                }
              }
            ],
            "must_not": [
              {
                "term": {
                  "RE": {
                    "value": "17"
                  }
                }
              }
            ]
          }
        },
        {
          "term": {
            "RE": "5"
          }
        }
      ]
    }
  }
}

```

This gives:

```auto
{
  "took" : 13,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 1,
    "max_score" : 0.5753642,
    "hits" : [
      {wish
        "_index" : "test",
        "_type" : "_doc",
        "_id" : "1",
        "_score" : 0.5753642,
        "_source" : {
          "RE" : "5"
        }
      }
    ]
  }
}

```

If this is not what you want, or what you have, and if you need further help, please provide a similar script as I just did if you are looking for help. A script should be just as easy as a copy and paste in Kibana Dev Console and run.

---

<div class="post-metadata">

**Author:** ![Dilip\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dilip_kumar/32/15459_2.png) [@Dilip\_Kumar](https://discuss.elastic.co/u/Dilip_Kumar)\
**Post date:** [April 17, 2019, 2:49pm UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/13 "2019-04-17T14:49:20Z")

</div>

Thanks for valuable timedadoonet, but please insert sample doc i have given above then i run this query which is giving result  
"hits": [  
{  
"\_index": "campevents\_test",  
"\_type": "cmev",  
"\_id": "221853184142816817\_278\_5",  
"\_score": 0.5753642,  
"\_source": {  
"RE": "5",  
"RT": "278",  
"PT": "2019-04-16T02:28:01",  
"DT": "2019-04-16T02:15:18",  
"ZI": "221853184142816817"  
}  
},  
{  
"\_index": "campevents\_test",  
"\_type": "cmev",  
"\_id": "2218531841428168\_278\_5",  
"\_score": 0.36464313,  
"\_source": {  
"RE": "5",  
"RT": "278",  
"PT": "2019-04-16T14:28:01",  
"DT": "2019-04-16T14:15:18",  
"ZI": "2218531841428168"  
}  
},  
{  
"\_index": "campevents\_test",  
"\_type": "cmev",  
"\_id": "2218531841428168\_270\_5",  
"\_score": 0.36464313,  
"\_source": {  
"RE": "5",  
"RT": "270",  
"PT": "2019-04-15T14:28:01",  
"DT": "2019-04-15T14:15:18",  
"ZI": "2218531841428168"  
}  
}  
]

My expected result should not have this record  
"RE": "5",  
"RT": "278",  
"PT": "2019-04-16T02:28:01",  
"DT": "2019-04-16T02:15:18",  
"ZI": "221853184142816817"

because as you can see "ZI": "221853184142816817" this ZI also in RE=17 and now in Re=5 so , i don't need those records which is having both Re=5 and RE=17 both,

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 17, 2019, 3:09pm UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/14 "2019-04-17T15:09:45Z")

</div>

I can't help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2019, 3:15pm UTC](https://discuss.elastic.co/t/must-not-apply-in-must-query-result/177042/15 "2019-05-15T15:15:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
