# Newbie question on searching

**URL:** <https://discuss.elastic.co/t/newbie-question-on-searching/14589>\
**Category:** Elasticsearch\
**Created:** [November 25, 2013, 11:44pm UTC](https://discuss.elastic.co/t/newbie-question-on-searching/14589 "2013-11-25T23:44:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://discuss.elastic.co/u/Jim_Mellander)\
**Post date:** [November 25, 2013, 11:44pm UTC](https://discuss.elastic.co/t/newbie-question-on-searching/14589/1 "2013-11-25T23:44:47Z")

</div>

Hi:

For some reason I am having a lot of trouble wrapping my brain around  
the Elasticsearch query capability.

I am trying to match for multiple values in specified fields

Here is what I am trying, but it returns no records:

```
 {
            "query": {
                    "filtered": {
                            "query" : { "match_all" : {} },
                            "filter" : {
                                    "or" : [
                                            { "term" : { "field1":

```

"value1" }},  
{ "term" : { "field2":  
"value1" }},  
{ "term" : { "field1":  
"value2" }},  
{ "term" : { "field2":  
"value2" }}  
]  
}  
}  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 26, 2013, 8:34am UTC](https://discuss.elastic.co/t/newbie-question-on-searching/14589/2 "2013-11-26T08:34:13Z")

</div>

Hi Jim,

Any chance that you could gist a full curl recreation to understand your concern?  
See [http://www.elasticsearch.org/help/](http://www.elasticsearch.org/help/)

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 26 novembre 2013 at 00:44:52, Jim Mellander ([jmellander@lbl.gov](mailto:jmellander@lbl.gov)) a écrit:

Hi:

For some reason I am having a lot of trouble wrapping my brain around  
the Elasticsearch query capability.

I am trying to match for multiple values in specified fields

Here is what I am trying, but it returns no records:

{  
"query": {  
"filtered": {  
"query" : { "match\_all" : {} },  
"filter" : {  
"or" : [  
{ "term" : { "field1":  
"value1" }},  
{ "term" : { "field2":  
"value1" }},  
{ "term" : { "field1":  
"value2" }},  
{ "term" : { "field2":  
"value2" }}  
]  
}  
}  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://discuss.elastic.co/u/Jim_Mellander)\
**Post date:** [November 26, 2013, 5:45pm UTC](https://discuss.elastic.co/t/newbie-question-on-searching/14589/3 "2013-11-26T17:45:10Z")

</div>

Thanks David:

I am using the official python api, but I performed the curl search,  
per the help page:

$ cat x  
#!/bin/sh

curl -XGET '[http://localhost:9200/\*/conn/\_search](http://localhost:9200/*/conn/_search)' -d '{  
"query": {  
"filtered": {  
"query": {"match\_all": {}},  
"filter": {  
"or": [  
{"term": {"field1": "value1"}},  
{"term": {"field2": "value1"}},  
{"term": {"field1": "value2"}},  
{"term": {"field2": "value2"}}  
]  
}  
}  
}  
}'

$./x  
{"took":15,"timed\_out":false,"\_shards":{"total":240,"successful":240,"failed":0},"hits":{"total":0,"max\_score":null,"hits":}}

Then, without the filter:

$ cat y  
#!/bin/sh

curl -XGET '[http://localhost:9200/\*/conn/\_search](http://localhost:9200/*/conn/_search)' -d '{  
"query": {  
"filtered": {  
"query": {"match\_all": {}}  
}  
}  
}'

$ ./y

{"took":10,"timed\_out":false,"\_shards":{"total":240,"successful":240,"failed":0},"hits":{"total":52470,"max\_score":1.0,"hits":[  
 ]}}

(and I verified that field1 and field2 are populated with and there  
are records with value1 and value2 in those fields)

Thanks for taking the time to look at this - I assume there is  
something wrong with the syntax of the query that is non-obvious (at  
least to me).

P.S. - I searched in vain for a 'Elasticsearch for Dummies' resource -  
the missing ingredient for me being a clear step-by-step methodology  
and explanation of building queries for various operations - I'm  
fairly certain that there are some fundamentals that I am missing, in  
particular the hierarchy of the various options and how they interact.

On Tue, Nov 26, 2013 at 12:34 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> Hi Jim,
> 
> Any chance that you could gist a full curl recreation to understand your  
> concern?  
> See [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)
> 
> --  
> David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
> @dadoonet | @elasticsearchfr
> 
> Le 26 novembre 2013 at 00:44:52, Jim Mellander ([jmellander@lbl.gov](mailto:jmellander@lbl.gov)) a écrit:
> 
> Hi:
> 
> For some reason I am having a lot of trouble wrapping my brain around  
> the Elasticsearch query capability.
> 
> I am trying to match for multiple values in specified fields
> 
> Here is what I am trying, but it returns no records:
> 
> {  
> "query": {  
> "filtered": {  
> "query" : { "match\_all" : {} },  
> "filter" : {  
> "or" : [  
> { "term" : { "field1":  
> "value1" }},  
> { "term" : { "field2":  
> "value1" }},  
> { "term" : { "field1":  
> "value2" }},  
> { "term" : { "field2":  
> "value2" }}  
> ]  
> }  
> }  
> }  
> }
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CADju%3Db4y5AnbY\_DkVXbFp0Fv%2Bxq7BVCi%2BbUZny1qcE32yAttdQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CADju%3Db4y5AnbY_DkVXbFp0Fv%2Bxq7BVCi%2BbUZny1qcE32yAttdQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 26, 2013, 7:46pm UTC](https://discuss.elastic.co/t/newbie-question-on-searching/14589/4 "2013-11-26T19:46:29Z")

</div>

There is no way to understand what is happening. I have no idea of what your docs look like. Mapping if any is unknown. That's the reason I gave you a link which explain in details what a curl recreation is.

Could you please follow the instructions?

It will help to run your script and try to understand what is happening without spending time on creating a test case.

Thanks.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 26 nov. 2013 à 18:45, Jim Mellander [jmellander@lbl.gov](mailto:jmellander@lbl.gov) a écrit :

Thanks David:

I am using the official python api, but I performed the curl search,  
per the help page:

$ cat x  
#!/bin/sh

curl -XGET '[http://localhost:9200/\*/conn/\_search](http://localhost:9200/*/conn/_search)' -d '{  
"query": {  
"filtered": {  
"query": {"match\_all": {}},  
"filter": {  
"or": [  
{"term": {"field1": "value1"}},  
{"term": {"field2": "value1"}},  
{"term": {"field1": "value2"}},  
{"term": {"field2": "value2"}}  
]  
}  
}  
}  
}'

$./x  
{"took":15,"timed\_out":false,"\_shards":{"total":240,"successful":240,"failed":0},"hits":{"total":0,"max\_score":null,"hits":}}

Then, without the filter:

$ cat y  
#!/bin/sh

curl -XGET '[http://localhost:9200/\*/conn/\_search](http://localhost:9200/*/conn/_search)' -d '{  
"query": {  
"filtered": {  
"query": {"match\_all": {}}  
}  
}  
}'

$ ./y

{"took":10,"timed\_out":false,"\_shards":{"total":240,"successful":240,"failed":0},"hits":{"total":52470,"max\_score":1.0,"hits":[  
 ]}}

(and I verified that field1 and field2 are populated with and there  
are records with value1 and value2 in those fields)

Thanks for taking the time to look at this - I assume there is  
something wrong with the syntax of the query that is non-obvious (at  
least to me).

P.S. - I searched in vain for a 'Elasticsearch for Dummies' resource -  
the missing ingredient for me being a clear step-by-step methodology  
and explanation of building queries for various operations - I'm  
fairly certain that there are some fundamentals that I am missing, in  
particular the hierarchy of the various options and how they interact.

> On Tue, Nov 26, 2013 at 12:34 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:  
> Hi Jim,
> 
> Any chance that you could gist a full curl recreation to understand your  
> concern?  
> See [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)
> 
> --  
> David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
> @dadoonet | @elasticsearchfr
> 
> Le 26 novembre 2013 at 00:44:52, Jim Mellander ([jmellander@lbl.gov](mailto:jmellander@lbl.gov)) a écrit:
> 
> Hi:
> 
> For some reason I am having a lot of trouble wrapping my brain around  
> the Elasticsearch query capability.
> 
> I am trying to match for multiple values in specified fields
> 
> Here is what I am trying, but it returns no records:
> 
> {  
> "query": {  
> "filtered": {  
> "query" : { "match\_all" : {} },  
> "filter" : {  
> "or" : [  
> { "term" : { "field1":  
> "value1" }},  
> { "term" : { "field2":  
> "value1" }},  
> { "term" : { "field1":  
> "value2" }},  
> { "term" : { "field2":  
> "value2" }}  
> ]  
> }  
> }  
> }  
> }
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CADju%3Db4y5AnbY\_DkVXbFp0Fv%2Bxq7BVCi%2BbUZny1qcE32yAttdQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CADju%3Db4y5AnbY_DkVXbFp0Fv%2Bxq7BVCi%2BbUZny1qcE32yAttdQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5BB9A2A3-2364-461B-8E5C-C22EA85894E8%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/5BB9A2A3-2364-461B-8E5C-C22EA85894E8%40pilato.fr).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:04am UTC](https://discuss.elastic.co/t/newbie-question-on-searching/14589/5 "2017-07-06T02:04:43Z")

</div>


