# Not able to query using the elastic search filter

**URL:** <https://discuss.elastic.co/t/not-able-to-query-using-the-elastic-search-filter/120023>\
**Category:** Logstash\
**Created:** [February 15, 2018, 4:23pm UTC](https://discuss.elastic.co/t/not-able-to-query-using-the-elastic-search-filter/120023 "2018-02-15T16:23:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ranganath\_nangineni](https://avatars.discourse-cdn.com/v4/letter/r/3ec8ea/32.png) [@ranganath\_nangineni](https://discuss.elastic.co/u/ranganath_nangineni)\
**Post date:** [February 15, 2018, 4:23pm UTC](https://discuss.elastic.co/t/not-able-to-query-using-the-elastic-search-filter/120023/1 "2018-02-15T16:23:55Z")

</div>

Hi,

I have the below entries for the record "ddocname": "CNT1882742" and I have to extract the ddoctitle of the same using the elastic search filter.

{  
"\_index": "test-m-docs",  
"\_type": "data",  
"\_id": "AWF0dLEQ\_An67UGqACQn",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"@timestamp": "2018-02-08T08:07:38.554Z",  
"@version": "1",  
**"ddocname": "CNT1882742",**  
\*\* "ddoctitle": "VSNL\_R12Upgrade\_TECH\_UPG\_Resource\_Mix-DAA1\_V1.12.xls",\*\*  
"did": 4835074,  
"tags": [  
"M Stage",  
"data"  
]  
},  
"fields": {  
"@timestamp": [  
1518077258554  
]  
},  
"sort": [  
1518077258554  
]  
}

# Logstash file:

input {  
#Any other inputs  
}

filter{  
elasticsearch {  
hosts =\> ["[xyz.pyk.com:9200/test-m-docs/data](http://xyz.pyk.com:9200/test-m-docs/data)"]  
#query =\> "ddocname":"%{docname}"  
query =\> ddocname:"CNT1882742"  
fields =\> {"ddoctitle"}  
#We can any number of fields  
#sort =\> "ddoctitle:desc"  
}  
}

output {  
stdout { codec =\> json\_lines }  
stdout { codec =\> rubydebug }  
elasticsearch {  
"hosts" =\> "[xyz.pyk.com:9200](http://xyz.pyk.com:9200)"  
"index" =\> "test-m1-docs"  
"document\_type" =\> "data"  
}  
}

But I am facing an error as below:

# bin/logstash -f elasticquery.conf

WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path //usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console  
[ERROR] 2018-02-15 15:55:57.780 [LogStash::Runner] agent - Cannot create pipeline {:reason=\>"Expected one of #, {, } at line 9, column 42 (byte 249) after filter{\n elasticsearch {\n hosts =\> ["[xyz.pyk.com:9200/test-m-docs/data](http://xyz.pyk.com:9200/test-m-docs/data)"]\n #query =\> "ddocname":"%{docname}"\n query =\> ddocname"}

Could you please let me know where I am going wrong and the correct format?

---

<div class="post-metadata">

**Author:** ![ranganath\_nangineni](https://avatars.discourse-cdn.com/v4/letter/r/3ec8ea/32.png) [@ranganath\_nangineni](https://discuss.elastic.co/u/ranganath_nangineni)\
**Post date:** [February 16, 2018, 7:15am UTC](https://discuss.elastic.co/t/not-able-to-query-using-the-elastic-search-filter/120023/2 "2018-02-16T07:15:34Z")

</div>

I tried the query as below but there is no output observed.

input {  
#Any other inputs  
elasticsearch {  
hosts =\> "[xyz.com:9200/test-m-docs/data](http://xyz.com:9200/test-m-docs/data)"  
#query =\> {"ddocname" =\> "CNT1882742"}  
query =\> '{ "query": {"match": { "ddocname" :"CNT1882742"} }, "sort": ["ddoctitle"] }'  
#fieldy =\> {"ddoctitle"}  
#We can any number of fields  
#sort =\> "ddoctitle:desc"  
}  
}

output {  
stdout { codec =\> json\_lines }  
stdout { codec =\> rubydebug }  
elasticsearch {  
"hosts" =\> "[xyz.com:9200](http://xyz.com:9200)"  
"index" =\> "test-m1-docs"  
"document\_type" =\> "data"  
}  
}

# Output:

[root@xyz logstash]# bin/logstash -f elasticquery.conf  
WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path //usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console  
[root@xyz logstash]#

Is the format correct ? How can I check the output ,whether it is working or failing .

---

<div class="post-metadata">

**Author:** ![ranganath\_nangineni](https://avatars.discourse-cdn.com/v4/letter/r/3ec8ea/32.png) [@ranganath\_nangineni](https://discuss.elastic.co/u/ranganath_nangineni)\
**Post date:** [February 16, 2018, 9:28am UTC](https://discuss.elastic.co/t/not-able-to-query-using-the-elastic-search-filter/120023/3 "2018-02-16T09:28:23Z")

</div>

I am able to get the output with the below

elasticsearch {  
"hosts" =\> "[XYZ.com:9200](http://XYZ.com:9200)"  
"index" =\> "test-m-docs"  
query =\> '{ "query": {"match": { "ddocname" :"CNT1882742"} }, "sort": ["@timestamp"] }'  
#query =\> '{ "query": {"match": { "ddocname" :"CNT1882742"} }, "sort": ["ddoctitle.keyword"] }'  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2018, 9:28am UTC](https://discuss.elastic.co/t/not-able-to-query-using-the-elastic-search-filter/120023/4 "2018-03-16T09:28:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
