# Newbie query question

**URL:** <https://discuss.elastic.co/t/newbie-query-question/9242>\
**Category:** Elasticsearch\
**Created:** [October 4, 2012, 3:52pm UTC](https://discuss.elastic.co/t/newbie-query-question/9242 "2012-10-04T15:52:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Steve\_3](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@Steve\_3](https://discuss.elastic.co/u/Steve_3)\
**Post date:** [October 4, 2012, 3:52pm UTC](https://discuss.elastic.co/t/newbie-query-question/9242/1 "2012-10-04T15:52:38Z")

</div>

Hi all:

Just getting started with ElasticSearch. I've taken some log4j output  
and inserted it into ElasticSearch to give me some data to play with,  
which looks like the following:

{  
total: 34,  
max\_score: 1,  
hits: [  
{  
\_index: "tomcat",  
\_type: "base",  
\_id: "an\_id",  
\_score: 1,  
\_source: {  
loggerName: "stuff",  
message: "stuff",  
level: "stuff",  
timestamp: "stuff",  
thread: "stuff"  
}  
},

So, now I'm trying to actually query / sort this data. I'm building a  
JSON request that looks like:

q = {  
"from": offset,  
"size": numItems,  
"sort" : [  
"level" : { "order" : "asc" }  
],  
"query" : {  
"term" : { "level" : targetLevel }  
}  
}

And execute the request with:

$.getJSON(myUrl, q, function(rData) {  
console.log(rData);  
});

However, what I get back is an unordered list of every log item,  
rather than the sorted list that I'm looking for.

I've also tried:

q = {  
"from": offset,  
"size": numItems,  
"sort" : [  
"level"  
],  
"query" : {  
"term" : { "level" : targetLevel }  
}  
}

and a number of other variations, but haven't had much success.  
Neither the search nor the sort seem to work.

I'm sure I must be making an obvious mistake. That said, if anyone  
could point me in the right direction here, it would be greatly  
appreciated 🙂

Also, related question: is there a simple way to ask ElasticSearch to  
be verbose about how / why it's filtering and sorting its results?

Thanks all!

--

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 4, 2012, 3:59pm UTC](https://discuss.elastic.co/t/newbie-query-question/9242/2 "2012-10-04T15:59:31Z")

</div>

Not sure if it's your concern, but there is this part of documentation about sorting on string values:

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

When sorting, the relevant sorted field values are loaded into memory. This means that per shard, there should be enough memory to contain them. For string based types, the field sorted on should not be analyzed / tokenized. For numeric types, if possible, it is recommended to explicitly set the type to six\_hun types (like short,integer and float).

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 4 oct. 2012 à 17:52, Steve [cubic1271@gmail.com](mailto:cubic1271@gmail.com) a écrit :

> Hi all:
> 
> Just getting started with Elasticsearch. I've taken some log4j output  
> and inserted it into Elasticsearch to give me some data to play with,  
> which looks like the following:
> 
> {  
> total: 34,  
> max\_score: 1,  
> hits: [  
> {  
> \_index: "tomcat",  
> \_type: "base",  
> \_id: "an\_id",  
> \_score: 1,  
> \_source: {  
> loggerName: "stuff",  
> message: "stuff",  
> level: "stuff",  
> timestamp: "stuff",  
> thread: "stuff"  
> }  
> },
> 
> So, now I'm trying to actually query / sort this data. I'm building a  
> JSON request that looks like:
> 
> q = {  
> "from": offset,  
> "size": numItems,  
> "sort" : [  
> "level" : { "order" : "asc" }  
> ],  
> "query" : {  
> "term" : { "level" : targetLevel }  
> }  
> }
> 
> And execute the request with:
> 
> $.getJSON(myUrl, q, function(rData) {  
> console.log(rData);  
> });
> 
> However, what I get back is an unordered list of every log item,  
> rather than the sorted list that I'm looking for.
> 
> I've also tried:
> 
> q = {  
> "from": offset,  
> "size": numItems,  
> "sort" : [  
> "level"  
> ],  
> "query" : {  
> "term" : { "level" : targetLevel }  
> }  
> }
> 
> and a number of other variations, but haven't had much success.  
> Neither the search nor the sort seem to work.
> 
> I'm sure I must be making an obvious mistake. That said, if anyone  
> could point me in the right direction here, it would be greatly  
> appreciated 🙂
> 
> Also, related question: is there a simple way to ask Elasticsearch to  
> be verbose about how / why it's filtering and sorting its results?
> 
> Thanks all!
> 
> --

--

---

<div class="post-metadata">

**Author:** ![Raffaele\_Sena](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raffaele_sena/32/1759_2.png) [@Raffaele\_Sena](https://discuss.elastic.co/u/Raffaele_Sena)\
**Post date:** [October 4, 2012, 4:07pm UTC](https://discuss.elastic.co/t/newbie-query-question/9242/3 "2012-10-04T16:07:27Z")

</div>

for the second part of your question, just add "explain":true to your  
json object. You'll get more information than you asked for, but it  
may give you some clues.

On Thu, Oct 4, 2012 at 8:52 AM, Steve [cubic1271@gmail.com](mailto:cubic1271@gmail.com) wrote:

> Hi all:
> 
> Just getting started with Elasticsearch. I've taken some log4j output  
> and inserted it into Elasticsearch to give me some data to play with,  
> which looks like the following:
> 
> {  
> total: 34,  
> max\_score: 1,  
> hits: [  
> {  
> \_index: "tomcat",  
> \_type: "base",  
> \_id: "an\_id",  
> \_score: 1,  
> \_source: {  
> loggerName: "stuff",  
> message: "stuff",  
> level: "stuff",  
> timestamp: "stuff",  
> thread: "stuff"  
> }  
> },
> 
> So, now I'm trying to actually query / sort this data. I'm building a  
> JSON request that looks like:
> 
> q = {  
> "from": offset,  
> "size": numItems,  
> "sort" : [  
> "level" : { "order" : "asc" }  
> ],  
> "query" : {  
> "term" : { "level" : targetLevel }  
> }  
> }
> 
> And execute the request with:
> 
> $.getJSON(myUrl, q, function(rData) {  
> console.log(rData);  
> });
> 
> However, what I get back is an unordered list of every log item,  
> rather than the sorted list that I'm looking for.
> 
> I've also tried:
> 
> q = {  
> "from": offset,  
> "size": numItems,  
> "sort" : [  
> "level"  
> ],  
> "query" : {  
> "term" : { "level" : targetLevel }  
> }  
> }
> 
> and a number of other variations, but haven't had much success.  
> Neither the search nor the sort seem to work.
> 
> I'm sure I must be making an obvious mistake. That said, if anyone  
> could point me in the right direction here, it would be greatly  
> appreciated 🙂
> 
> Also, related question: is there a simple way to ask Elasticsearch to  
> be verbose about how / why it's filtering and sorting its results?
> 
> Thanks all!
> 
> --

--

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 4, 2012, 4:10pm UTC](https://discuss.elastic.co/t/newbie-query-question/9242/4 "2012-10-04T16:10:35Z")

</div>

Explain will give you clues on how score is computed. IMHO, you won't get details why some results are filtered or not.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 4 oct. 2012 à 18:07, Raffaele Sena [raff367@gmail.com](mailto:raff367@gmail.com) a écrit :

> for the second part of your question, just add "explain":true to your  
> json object. You'll get more information than you asked for, but it  
> may give you some clues.
> 
> On Thu, Oct 4, 2012 at 8:52 AM, Steve [cubic1271@gmail.com](mailto:cubic1271@gmail.com) wrote:
> 
> > Hi all:
> > 
> > Just getting started with Elasticsearch. I've taken some log4j output  
> > and inserted it into Elasticsearch to give me some data to play with,  
> > which looks like the following:
> > 
> > {  
> > total: 34,  
> > max\_score: 1,  
> > hits: [  
> > {  
> > \_index: "tomcat",  
> > \_type: "base",  
> > \_id: "an\_id",  
> > \_score: 1,  
> > \_source: {  
> > loggerName: "stuff",  
> > message: "stuff",  
> > level: "stuff",  
> > timestamp: "stuff",  
> > thread: "stuff"  
> > }  
> > },
> > 
> > So, now I'm trying to actually query / sort this data. I'm building a  
> > JSON request that looks like:
> > 
> > q = {  
> > "from": offset,  
> > "size": numItems,  
> > "sort" : [  
> > "level" : { "order" : "asc" }  
> > ],  
> > "query" : {  
> > "term" : { "level" : targetLevel }  
> > }  
> > }
> > 
> > And execute the request with:
> > 
> > $.getJSON(myUrl, q, function(rData) {  
> > console.log(rData);  
> > });
> > 
> > However, what I get back is an unordered list of every log item,  
> > rather than the sorted list that I'm looking for.
> > 
> > I've also tried:
> > 
> > q = {  
> > "from": offset,  
> > "size": numItems,  
> > "sort" : [  
> > "level"  
> > ],  
> > "query" : {  
> > "term" : { "level" : targetLevel }  
> > }  
> > }
> > 
> > and a number of other variations, but haven't had much success.  
> > Neither the search nor the sort seem to work.
> > 
> > I'm sure I must be making an obvious mistake. That said, if anyone  
> > could point me in the right direction here, it would be greatly  
> > appreciated 🙂
> > 
> > Also, related question: is there a simple way to ask Elasticsearch to  
> > be verbose about how / why it's filtering and sorting its results?
> > 
> > Thanks all!
> > 
> > --
> 
> --

--

---

<div class="post-metadata">

**Author:** ![Steve\_3](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@Steve\_3](https://discuss.elastic.co/u/Steve_3)\
**Post date:** [October 4, 2012, 5:42pm UTC](https://discuss.elastic.co/t/newbie-query-question/9242/5 "2012-10-04T17:42:55Z")

</div>

David / Raffaele:

Explain is useful. Thanks!

Also, thanks for the discussion so far. I've simplified my JSON to:

q = {  
"query" : {  
"term" : { "level" : "INFO" }  
},  
"explain" : true  
}

$.getJSON(sSource, q, function(rData) {  
console.log(rData);  
});

It looks like the query ES is running is effectively '_:_', because here's  
a snippet of the "explain" I get back from the above query:

{

- value: 1,
- description: "ConstantScore(NotDeleted(_:_)), product of:",
- 
## details: [

## { - value: 1, - description: "boost" },
{  
- value: 1,  
- description: "queryNorm"  
}  
]

}

Any further thoughts?

On Thursday, October 4, 2012 12:10:44 PM UTC-4, David Pilato wrote:

> Explain will give you clues on how score is computed. IMHO, you won't get  
> details why some results are filtered or not.
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 4 oct. 2012 à 18:07, Raffaele Sena \<[raf...@gmail.com](mailto:raf...@gmail.com) \<javascript:\>\> a  
> écrit :
> 
> > for the second part of your question, just add "explain":true to your  
> > json object. You'll get more information than you asked for, but it  
> > may give you some clues.
> > 
> > On Thu, Oct 4, 2012 at 8:52 AM, Steve \<[cubi...@gmail.com](mailto:cubi...@gmail.com) \<javascript:\>\>  
> > wrote:
> > 
> > > Hi all:
> > > 
> > > Just getting started with Elasticsearch. I've taken some log4j output  
> > > and inserted it into Elasticsearch to give me some data to play with,  
> > > which looks like the following:
> > > 
> > > {  
> > > total: 34,  
> > > max\_score: 1,  
> > > hits: [  
> > > {  
> > > \_index: "tomcat",  
> > > \_type: "base",  
> > > \_id: "an\_id",  
> > > \_score: 1,  
> > > \_source: {  
> > > loggerName: "stuff",  
> > > message: "stuff",  
> > > level: "stuff",  
> > > timestamp: "stuff",  
> > > thread: "stuff"  
> > > }  
> > > },
> > > 
> > > So, now I'm trying to actually query / sort this data. I'm building a  
> > > JSON request that looks like:
> > > 
> > > q = {  
> > > "from": offset,  
> > > "size": numItems,  
> > > "sort" : [  
> > > "level" : { "order" : "asc" }  
> > > ],  
> > > "query" : {  
> > > "term" : { "level" : targetLevel }  
> > > }  
> > > }
> > > 
> > > And execute the request with:
> > > 
> > > $.getJSON(myUrl, q, function(rData) {  
> > > console.log(rData);  
> > > });
> > > 
> > > However, what I get back is an unordered list of every log item,  
> > > rather than the sorted list that I'm looking for.
> > > 
> > > I've also tried:
> > > 
> > > q = {  
> > > "from": offset,  
> > > "size": numItems,  
> > > "sort" : [  
> > > "level"  
> > > ],  
> > > "query" : {  
> > > "term" : { "level" : targetLevel }  
> > > }  
> > > }
> > > 
> > > and a number of other variations, but haven't had much success.  
> > > Neither the search nor the sort seem to work.
> > > 
> > > I'm sure I must be making an obvious mistake. That said, if anyone  
> > > could point me in the right direction here, it would be greatly  
> > > appreciated 🙂
> > > 
> > > Also, related question: is there a simple way to ask Elasticsearch to  
> > > be verbose about how / why it's filtering and sorting its results?
> > > 
> > > Thanks all!
> > > 
> > > --
> > 
> > --

--

---

<div class="post-metadata">

**Author:** ![Steve\_3](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@Steve\_3](https://discuss.elastic.co/u/Steve_3)\
**Post date:** [October 4, 2012, 6:50pm UTC](https://discuss.elastic.co/t/newbie-query-question/9242/6 "2012-10-04T18:50:41Z")

</div>

Ah, I think I see.

I'm making a GET request to \_search, but I'm not correctly putting the  
query DSL into the _body_ of the request. Thus, my query is being attached  
as a GET parameter instead of included as part of a request _body_.  
Because ES doesn't see any parameters it understands, it gives back the  
default '_:_', and I end up with something that isn't what I thought I  
asked for.

Guess I need to go back and read more of the manual 🙂

Thanks all!

On Thursday, October 4, 2012 1:42:55 PM UTC-4, cubic1271 wrote:

> David / Raffaele:
> 
> Explain is useful. Thanks!
> 
> Also, thanks for the discussion so far. I've simplified my JSON to:
> 
> q = {  
> "query" : {  
> "term" : { "level" : "INFO" }  
> },  
> "explain" : true  
> }
> 
> $.getJSON(sSource, q, function(rData) {  
> console.log(rData);  
> });
> 
> It looks like the query ES is running is effectively '_:_', because here's  
> a snippet of the "explain" I get back from the above query:
> 
> {
> 
> - value: 1,
> - description: "ConstantScore(NotDeleted(_:_)), product of:",
> - 
> ## details: [
> 
> ## { - value: 1, - description: "boost" },
> {  
> - value: 1,  
> - description: "queryNorm"  
> }  
> ]
> 
> }
> 
> Any further thoughts?
> 
> On Thursday, October 4, 2012 12:10:44 PM UTC-4, David Pilato wrote:
> 
> > Explain will give you clues on how score is computed. IMHO, you won't get  
> > details why some results are filtered or not.
> > 
> > --  
> > David 😉  
> > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > 
> > Le 4 oct. 2012 à 18:07, Raffaele Sena [raf...@gmail.com](mailto:raf...@gmail.com) a écrit :
> > 
> > > for the second part of your question, just add "explain":true to your  
> > > json object. You'll get more information than you asked for, but it  
> > > may give you some clues.
> > > 
> > > On Thu, Oct 4, 2012 at 8:52 AM, Steve [cubi...@gmail.com](mailto:cubi...@gmail.com) wrote:
> > > 
> > > > Hi all:
> > > > 
> > > > Just getting started with Elasticsearch. I've taken some log4j output  
> > > > and inserted it into Elasticsearch to give me some data to play with,  
> > > > which looks like the following:
> > > > 
> > > > {  
> > > > total: 34,  
> > > > max\_score: 1,  
> > > > hits: [  
> > > > {  
> > > > \_index: "tomcat",  
> > > > \_type: "base",  
> > > > \_id: "an\_id",  
> > > > \_score: 1,  
> > > > \_source: {  
> > > > loggerName: "stuff",  
> > > > message: "stuff",  
> > > > level: "stuff",  
> > > > timestamp: "stuff",  
> > > > thread: "stuff"  
> > > > }  
> > > > },
> > > > 
> > > > So, now I'm trying to actually query / sort this data. I'm building a  
> > > > JSON request that looks like:
> > > > 
> > > > q = {  
> > > > "from": offset,  
> > > > "size": numItems,  
> > > > "sort" : [  
> > > > "level" : { "order" : "asc" }  
> > > > ],  
> > > > "query" : {  
> > > > "term" : { "level" : targetLevel }  
> > > > }  
> > > > }
> > > > 
> > > > And execute the request with:
> > > > 
> > > > $.getJSON(myUrl, q, function(rData) {  
> > > > console.log(rData);  
> > > > });
> > > > 
> > > > However, what I get back is an unordered list of every log item,  
> > > > rather than the sorted list that I'm looking for.
> > > > 
> > > > I've also tried:
> > > > 
> > > > q = {  
> > > > "from": offset,  
> > > > "size": numItems,  
> > > > "sort" : [  
> > > > "level"  
> > > > ],  
> > > > "query" : {  
> > > > "term" : { "level" : targetLevel }  
> > > > }  
> > > > }
> > > > 
> > > > and a number of other variations, but haven't had much success.  
> > > > Neither the search nor the sort seem to work.
> > > > 
> > > > I'm sure I must be making an obvious mistake. That said, if anyone  
> > > > could point me in the right direction here, it would be greatly  
> > > > appreciated 🙂
> > > > 
> > > > Also, related question: is there a simple way to ask Elasticsearch to  
> > > > be verbose about how / why it's filtering and sorting its results?
> > > > 
> > > > Thanks all!
> > > > 
> > > > --
> > > 
> > > --

--

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:10am UTC](https://discuss.elastic.co/t/newbie-query-question/9242/7 "2017-07-06T03:10:04Z")

</div>


