# Need to get the field having only null value using query

**URL:** <https://discuss.elastic.co/t/need-to-get-the-field-having-only-null-value-using-query/54686>\
**Category:** Elasticsearch\
**Created:** [July 5, 2016, 5:56am UTC](https://discuss.elastic.co/t/need-to-get-the-field-having-only-null-value-using-query/54686 "2016-07-05T05:56:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![prasad.ram1431](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Post date:** [July 5, 2016, 5:56am UTC](https://discuss.elastic.co/t/need-to-get-the-field-having-only-null-value-using-query/54686/1 "2016-07-05T05:56:36Z")

</div>

Hi,  
I am new to Elastic Search. Kindly help me on below issue.  
By using the below query, still I am getting the field having value, which should not happen. Kindly suggest the solution for this issue,

{  
"query": {  
"filtered": {  
"filter": {  
"not": {  
"filter": {  
"missing": {  
"field": "resolved"  
}  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 5, 2016, 7:09am UTC](https://discuss.elastic.co/t/need-to-get-the-field-having-only-null-value-using-query/54686/2 "2016-07-05T07:09:57Z")

</div>

Please format your code as explained at [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21)

Then provide a full script which reproduce your issue as shown in the same link.

---

<div class="post-metadata">

**Author:** ![prasad.ram1431](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Post date:** [July 5, 2016, 7:31am UTC](https://discuss.elastic.co/t/need-to-get-the-field-having-only-null-value-using-query/54686/3 "2016-07-05T07:31:22Z")

</div>

Below is the updated query with proper syntax, in the below query we should be getting only the documents which has resolved = "" or resolved = null, which is not happening, I am even getting the resolved = 'abc'. Kindly let me know if I am missing anything or is there any other way to fix this  
POST: /index/type/\_search

{  
"query": {  
"filtered": {  
"filter": {  
"not": {  
"filter": {  
"missing": {  
"field": "resolved"  
}  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 5, 2016, 8:04am UTC](https://discuss.elastic.co/t/need-to-get-the-field-having-only-null-value-using-query/54686/4 "2016-07-05T08:04:59Z")

</div>

Did you read the documentation I linked to? About formatting?

Here is a script which shows this in action:

```auto
DELETE index
PUT index/type/1
{
  "foo": "bar"
}
PUT index/type/2
{
  "foo": null
}
PUT index/type/3
{
  "foo": ""
}
PUT index/type/4
{
  "other": 1
}
GET index/_search
{
  "query": {
    "bool": {
      "must_not": {
        "exists": {
          "field": "foo"
        }
      }
    }
  }
}

```

Note that it's for 5.0.

It gives:

```auto
{
  "took": 1,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "failed": 0
  },
  "hits": {
    "total": 2,
    "max_score": 1,
    "hits": [
      {
        "_index": "index",
        "_type": "type",
        "_id": "2",
        "_score": 1,
        "_source": {
          "foo": null
        }
      },
      {
        "_index": "index",
        "_type": "type",
        "_id": "4",
        "_score": 1,
        "_source": {
          "other": 1
        }
      }
    ]
  }
}

```

So when the field is `null` or is not provided, the `missing` filter (replaced in 5.0 with `must_not` `exists` filter) gives expected results.  
Obviously `"foo":""` means that you provided something which is empty. Technically it's not a missing field or a missing value.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:38pm UTC](https://discuss.elastic.co/t/need-to-get-the-field-having-only-null-value-using-query/54686/5 "2017-07-05T22:38:18Z")

</div>


