# Nested bool queries return an error

**URL:** <https://discuss.elastic.co/t/nested-bool-queries-return-an-error/122531>\
**Category:** Elasticsearch\
**Created:** [March 5, 2018, 2:30pm UTC](https://discuss.elastic.co/t/nested-bool-queries-return-an-error/122531 "2018-03-05T14:30:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![WoJ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/woj/32/4518_2.png) [@WoJ](https://discuss.elastic.co/u/WoJ)\
**Post date:** [March 5, 2018, 2:30pm UTC](https://discuss.elastic.co/t/nested-bool-queries-return-an-error/122531/1 "2018-03-05T14:30:39Z")

</div>

Hello everyone,

I am building a search query which dynamically adds a set of constraints (`bool`) to the query. The general expected structure is as follows

```
OR (

AND (
    condition
    condition
    ...
)

AND (
    condition
    condition
    ...
)

)

```

In other words I have a set (one or more) of conditions which must all be met (`AND` above). There may be several of such sets, any of them should be enough for the final match (the `OR` above).

An example of such structure, as generated by my code (this is the full API query, the generated part is `"bool"`). It is [available online for easier reading](https://jsoneditoronline.org/?id=ae47348645bc20828df7392217640cd5)

```
{
  "query": {
    "bool": {
      "must": [
        {
          "bool": {
            "should": [
              {
                "bool": {
                  "must": [
                    {
                      "term": {
                        "attack_ip": "10.89.7.117"
                      }
                    },
                    {
                      "term": {
                        "sentinel_port": "17"
                      }
                    }
                  ]
                }
              },
              {
                "bool": {
                  "must": [
                    {
                      "term": {
                        "attack_ip": "10.89.7.118"
                      }
                    }
                  ]
                }
              }
            ]
          }
        },
        {
          "range": {
            "eventtime": {
              "gte": "2018-03-05T13:55:27.927+01:00"
            }
          }
        }
      ]
    },
    "size": 0,
    "aggs": {
      "src": {
        "terms": {
          "field": "attack_ip",
          "size": 1000
        },
        "aggs": {
          "dst": {
            "terms": {
              "field": "sentinel_hostname_lan",
              "size": 2000
            }
          }
        }
      }
    }
  }
}

```

My understanding of this query was:

> - if `"attack_ip === 10.89.7.117"` and `"sentinel_port === 17"`
> - or
> - if `"attack_ip === 10.89.7.118"`
> 
> AND
> 
> - match the `range`

the entry will match

Unfortunately I get upon calling Elasticsearch the error

```
"error": {
    "root_cause": [
      {
        "type": "parsing_exception",
        "reason": "[bool] malformed query, expected [END_OBJECT] but found [FIELD_NAME]",
        "line": 1,
        "col": 177
      }
    ],
    "type": "parsing_exception",
    "reason": "[bool] malformed query, expected [END_OBJECT] but found [FIELD_NAME]",
    "line": 1,
    "col": 177
  },
  "status": 400
}

```

What does this error mean?

(initially asked on [SO](https://stackoverflow.com/questions/49111067/how-to-nest-bool-queries))

---

<div class="post-metadata">

**Author:** ![WoJ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/woj/32/4518_2.png) [@WoJ](https://discuss.elastic.co/u/WoJ)\
**Post date:** [March 7, 2018, 11:45am UTC](https://discuss.elastic.co/t/nested-bool-queries-return-an-error/122531/2 "2018-03-07T11:45:54Z")

</div>

The error ended up being the `query` section encompassing the `aggs` one, while they should be at the same level.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2018, 11:45am UTC](https://discuss.elastic.co/t/nested-bool-queries-return-an-error/122531/3 "2018-04-04T11:45:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
