# Newbie - records not being returned

**URL:** <https://discuss.elastic.co/t/newbie-records-not-being-returned/19348>\
**Category:** Elasticsearch\
**Created:** [August 19, 2014, 7:13pm UTC](https://discuss.elastic.co/t/newbie-records-not-being-returned/19348 "2014-08-19T19:13:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![eloris](https://avatars.discourse-cdn.com/v4/letter/e/2acd7d/32.png) [@eloris](https://discuss.elastic.co/u/eloris)\
**Post date:** [August 19, 2014, 7:13pm UTC](https://discuss.elastic.co/t/newbie-records-not-being-returned/19348/1 "2014-08-19T19:13:33Z")

</div>

I am brand new to this technology. Probably, this question is answered  
somewhere in the docs, but I can't see where.

I have inserted data as follows:

> curl localhost:9200/\_search?pretty

[...]

{  
"\_index" : "log",  
"\_type" : "external",  
"\_id" : "dggX5-r4SaW2DLnLwFJlkQ",  
"\_score" : 1.0,  
"\_source":{  
"ID":"b596330f-1898-4d9a-aa34-031fac480ead",  
"Type":3,  
"Message":".NET Hub is running.",  
"ParentID":null,  
"MetaData":{  
"Timestamp":"8/7/2014 2:50:11 PM",  
"Source":"FileProcessor",  
"EnterpriseID":"",  
"ServiceName":"MMM.HSA.Hub.HubService, Version=1.0.0.0,  
Culture=neutral, PublicKeyToken=null",  
"MessageID":"MON\_Heartbeat",  
"TimestampInTicks":"635430054119284674",  
"HeartbeatTime":"5000"  
},  
"CreateDate":"/Date(-62135578800000)/"}  
}

Then I run  
curl -XPOST [http://localhost:9200/log/\_search](http://localhost:9200/log/_search)  
{"size":1,"query":{"filtered":{"query":{"match\_all":{}},"filter":{"term":{"applicationID":"HSA\_NET\_Hub","Type":"3","MetaData.MessageID":"MON\_Heartbeat"}}}},"sort":[{"\_id":"desc"}]}

and get no results. It seems to me that the above record should be found.

Anybody know what I am doing wrong? I know it is because of the filtering  
on MetaData.MessageID, because without that records do get found. But I  
don't know what's wrong with my syntax and the documentation does not  
answer my question.

Thanks in advance!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 19, 2014, 7:34pm UTC](https://discuss.elastic.co/t/newbie-records-not-being-returned/19348/2 "2014-08-19T19:34:11Z")

</div>

Some thoughts:

I don't think you can define multiple fields/values for Term Filter: [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-term-filter.html#query-dsl-term-filter). I think that only the last one is applied here.  
You are using default analyzer. So MessageID content has probably been indexed as ["mon", "heartbeat"].  
A Term filter does not analyze the content. So you compare exactly your string with the inverted index. And MON\_Heartbeat is not "mon" or "heartbeat".  
You could change the mapping and set MessageID to not\_analyzed: [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping-core-types.html#string)

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 19 août 2014 à 21:13:37, eloris ([roykoczela@gmail.com](mailto:roykoczela@gmail.com)) a écrit:

I am brand new to this technology. Probably, this question is answered somewhere in the docs, but I can't see where.

I have inserted data as follows:

> curl localhost:9200/\_search?pretty

[...]

{  
"\_index" : "log",  
"\_type" : "external",  
"\_id" : "dggX5-r4SaW2DLnLwFJlkQ",  
"\_score" : 1.0,  
"\_source":{  
"ID":"b596330f-1898-4d9a-aa34-031fac480ead",  
"Type":3,  
"Message":".NET Hub is running.",  
"ParentID":null,  
"MetaData":{  
"Timestamp":"8/7/2014 2:50:11 PM",  
"Source":"FileProcessor",  
"EnterpriseID":"",  
"ServiceName":"MMM.HSA.Hub.HubService, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null",  
"MessageID":"MON\_Heartbeat",  
"TimestampInTicks":"635430054119284674",  
"HeartbeatTime":"5000"  
},  
"CreateDate":"/Date(-62135578800000)/"}  
}

Then I run  
curl -XPOST [http://localhost:9200/log/\_search](http://localhost:9200/log/_search)  
{"size":1,"query":{"filtered":{"query":{"match\_all":{}},"filter":{"term":{"applicationID":"HSA\_NET\_Hub","Type":"3","MetaData.MessageID":"MON\_Heartbeat"}}}},"sort":[{"\_id":"desc"}]}

and get no results. It seems to me that the above record should be found.

Anybody know what I am doing wrong? I know it is because of the filtering on MetaData.MessageID, because without that records do get found. But I don't know what's wrong with my syntax and the documentation does not answer my question.

Thanks in advance!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.53f3a6b3.57e4ccaf.132%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.53f3a6b3.57e4ccaf.132%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![eloris](https://avatars.discourse-cdn.com/v4/letter/e/2acd7d/32.png) [@eloris](https://discuss.elastic.co/u/eloris)\
**Post date:** [August 20, 2014, 1:33pm UTC](https://discuss.elastic.co/t/newbie-records-not-being-returned/19348/3 "2014-08-20T13:33:59Z")

</div>

Thanks! Would have taken me forever to figure out the underscore was the  
problem. Not the kind of thing you can find out from the "Getting Started"  
docs.

On Tuesday, August 19, 2014 3:34:23 PM UTC-4, David Pilato wrote:

> Some thoughts:
> 
> I don't think you can define multiple fields/values for Term Filter:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-term-filter.html#query-dsl-term-filter).  
> I think that only the last one is applied here.  
> You are using default analyzer. So MessageID content has probably been  
> indexed as ["mon", "heartbeat"].  
> A Term filter does not analyze the content. So you compare exactly your  
> string with the inverted index. And MON\_Heartbeat is not "mon" or  
> "heartbeat".  
> You could change the mapping and set MessageID to not\_analyzed:  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping-core-types.html#string)
> 
> --  
> _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr  
> [https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)
> 
> Le 19 août 2014 à 21:13:37, eloris ([royko...@gmail.com](mailto:royko...@gmail.com) \<javascript:\>) a  
> écrit:
> 
> I am brand new to this technology. Probably, this question is answered  
> somewhere in the docs, but I can't see where.
> 
> I have inserted data as follows:
> 
> > curl localhost:9200/\_search?pretty
> 
> [...]
> 
> {  
> "\_index" : "log",  
> "\_type" : "external",  
> "\_id" : "dggX5-r4SaW2DLnLwFJlkQ",  
> "\_score" : 1.0,  
> "\_source":{  
> "ID":"b596330f-1898-4d9a-aa34-031fac480ead",  
> "Type":3,  
> "Message":".NET Hub is running.",  
> "ParentID":null,  
> "MetaData":{  
> "Timestamp":"8/7/2014 2:50:11 PM",  
> "Source":"FileProcessor",  
> "EnterpriseID":"",  
> "ServiceName":"MMM.HSA.Hub.HubService, Version=1.0.0.0,  
> Culture=neutral, PublicKeyToken=null",  
> "MessageID":"MON\_Heartbeat",  
> "TimestampInTicks":"635430054119284674",  
> "HeartbeatTime":"5000"  
> },  
> "CreateDate":"/Date(-62135578800000)/"}  
> }
> 
> Then I run  
> curl -XPOST [http://localhost:9200/log/\_search](http://localhost:9200/log/_search)
> 
> {"size":1,"query":{"filtered":{"query":{"match\_all":{}},"filter":{"term":{"applicationID":"HSA\_NET\_Hub","Type":"3","MetaData.MessageID":"MON\_Heartbeat"}}}},"sort":[{"\_id":"desc"}]}
> 
> and get no results. It seems to me that the above record should be found.
> 
> Anybody know what I am doing wrong? I know it is because of the filtering  
> on MetaData.MessageID, because without that records do get found. But I  
> don't know what's wrong with my syntax and the documentation does not  
> answer my question.
> 
> Thanks in advance!
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/27c1626d-946c-4da6-af21-3b547395c7ec%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/27c1626d-946c-4da6-af21-3b547395c7ec%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 20, 2014, 4:53pm UTC](https://discuss.elastic.co/t/newbie-records-not-being-returned/19348/4 "2014-08-20T16:53:54Z")

</div>

I think you should read this chapter: [Elastic — The Search AI Company | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/guide/current/mapping-analysis.html)  
It could help you understanding what is happening behind the scene.

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 20 août 2014 à 15:34:03, eloris ([roykoczela@gmail.com](mailto:roykoczela@gmail.com)) a écrit:

Thanks! Would have taken me forever to figure out the underscore was the problem. Not the kind of thing you can find out from the "Getting Started" docs.

On Tuesday, August 19, 2014 3:34:23 PM UTC-4, David Pilato wrote:  
Some thoughts:

I don't think you can define multiple fields/values for Term Filter: [Elastic — The Search AI Company | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-term-filter.html#query-dsl-term-filter). I think that only the last one is applied here.  
You are using default analyzer. So MessageID content has probably been indexed as ["mon", "heartbeat"].  
A Term filter does not analyze the content. So you compare exactly your string with the inverted index. And MON\_Heartbeat is not "mon" or "heartbeat".  
You could change the mapping and set MessageID to not\_analyzed: [Elastic — The Search AI Company | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping-core-types.html#string)

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 19 août 2014 à 21:13:37, eloris ([royko...@gmail.com](mailto:royko...@gmail.com)) a écrit:

I am brand new to this technology. Probably, this question is answered somewhere in the docs, but I can't see where.

I have inserted data as follows:

> curl localhost:9200/\_search?pretty

[...]

{  
"\_index" : "log",  
"\_type" : "external",  
"\_id" : "dggX5-r4SaW2DLnLwFJlkQ",  
"\_score" : 1.0,  
"\_source":{  
"ID":"b596330f-1898-4d9a-aa34-031fac480ead",  
"Type":3,  
"Message":".NET Hub is running.",  
"ParentID":null,  
"MetaData":{  
"Timestamp":"8/7/2014 2:50:11 PM",  
"Source":"FileProcessor",  
"EnterpriseID":"",  
"ServiceName":"MMM.HSA.Hub.HubService, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null",  
"MessageID":"MON\_Heartbeat",  
"TimestampInTicks":"635430054119284674",  
"HeartbeatTime":"5000"  
},  
"CreateDate":"/Date(-62135578800000)/"}  
}

Then I run  
curl -XPOST [http://localhost:9200/log/\_search](http://localhost:9200/log/_search)  
{"size":1,"query":{"filtered":{"query":{"match\_all":{}},"filter":{"term":{"applicationID":"HSA\_NET\_Hub","Type":"3","MetaData.MessageID":"MON\_Heartbeat"}}}},"sort":[{"\_id":"desc"}]}

and get no results. It seems to me that the above record should be found.

Anybody know what I am doing wrong? I know it is because of the filtering on MetaData.MessageID, because without that records do get found. But I don't know what's wrong with my syntax and the documentation does not answer my question.

Thanks in advance!

## -- You received this message because you are subscribed to the Google Groups "elasticsearch" group. To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com). To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e2c82f7a-9903-4dee-a44f-2e0c4a8d0e2c%40googlegroups.com). For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/27c1626d-946c-4da6-af21-3b547395c7ec%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/27c1626d-946c-4da6-af21-3b547395c7ec%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.53f4d2a2.2ae8944a.6ef9%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.53f4d2a2.2ae8944a.6ef9%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:07am UTC](https://discuss.elastic.co/t/newbie-records-not-being-returned/19348/5 "2017-07-06T01:07:23Z")

</div>


