# Not able to search through attachment contents

**URL:** <https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473>\
**Category:** Elasticsearch\
**Created:** [October 19, 2015, 10:19am UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473 "2015-10-19T10:19:55Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 19, 2015, 10:19am UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/1 "2015-10-19T10:19:55Z")

</div>

I am new to ElasticSearch and evaluating PDF files indexing.

I have used NEST .net plugin, to index pdf files. I have used steps as described in one of stackoverflow post [http://stackoverflow.com/questions/25917386/client-net-nest-with-attachment-highlight-feature](http://stackoverflow.com/questions/25917386/client-net-nest-with-attachment-highlight-feature)

I am able index pdf contents with Convert.ToBase64String method. and document is getting indexed.

**I am able to search plain from Title field but not able to search text contents from PDF file, it returns me zero hits.**

Can someone please help on this.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 19, 2015, 12:50pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/3 "2015-10-19T12:50:43Z")

</div>

Did you install mapper attachments plugin? What can you see in logs?

---

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 19, 2015, 12:55pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/4 "2015-10-19T12:55:12Z")

</div>

Yes I have installed mapper attachments plugin and restarted cluster, it is displayed in clusters plugin list.Please refer screenshot for same:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/d48d21586af547d80d35cf944a47872d6ae8e8a5.png)

Below is screenshot for uploaded sample index:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/6/602ee790e40d478045cc6917c73ec277694a58c8.png)

---

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 19, 2015, 1:01pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/5 "2015-10-19T13:01:23Z")

</div>

Here is sample C# code I have used:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/e782ed7b4f320f0e048c4b8d6ac66f5b860c38e6.png)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 19, 2015, 1:07pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/6 "2015-10-19T13:07:51Z")

</div>

Anything in elasticsearch logs?

---

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 19, 2015, 1:09pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/7 "2015-10-19T13:09:50Z")

</div>

Where I can find log files? Is there any option in ES-Head?

---

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 19, 2015, 1:14pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/8 "2015-10-19T13:14:17Z")

</div>

I dont see any error in ES logs:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/c2024b095f0d3e824fe1b7e7d9fdc75ac72520c2.png)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 19, 2015, 1:15pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/9 "2015-10-19T13:15:37Z")

</div>

Can you show the mapping for your type and what a typical JSON document looks like?

---

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 19, 2015, 1:17pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/11 "2015-10-19T13:17:49Z")

</div>

Please refer below C# code for mapping and i am uploading pdf as file:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a906e1d67bee92716799f0db615fe95de63dc58d.png)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 19, 2015, 1:53pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/12 "2015-10-19T13:53:13Z")

</div>

Can you please run the following queries on your cluster?

- GET /data/doc/1
- GET /data/doc/\_mapping

---

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 19, 2015, 2:29pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/13 "2015-10-19T14:29:50Z")

</div>

Yes, Here are results:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/8ce84dd10d1207bf2397f451abff01429fec58a4.png)

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/40b61ebd1a2c52b346a8afd28c35a13d9ef46298.png)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 19, 2015, 2:52pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/14 "2015-10-19T14:52:20Z")

</div>

As you can see, your mapping is incorrect.  
There is no `attachment` type in it.

So the file content is not analyzed with the mapper attachments plugin.

Remove your index, create it again, PUT the mapping, check that it has been applied, then index your docs.

---

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 19, 2015, 2:55pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/15 "2015-10-19T14:55:04Z")

</div>

how should I define field type as an attachment? any reference link for c#?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 19, 2015, 3:07pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/16 "2015-10-19T15:07:09Z")

</div>

You can read the doc: [https://github.com/elastic/elasticsearch-mapper-attachments#using-mapper-attachments](https://github.com/elastic/elasticsearch-mapper-attachments#using-mapper-attachments)

I don't know about `C#` so I can't tell how to translate that in that language. Might not be hard though.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 19, 2015, 11:04pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/17 "2015-10-19T23:04:30Z")

</div>

@Suyog_Kale FYI in all of your pictures we can see your Found cluster ID, which means someone can potentially get access to your data.

I'd strongly suggest that you remove/edit the pictures.

---

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 21, 2015, 9:10am UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/18 "2015-10-21T09:10:23Z")

</div>

Thank you David,

Now I am able to configure mapping and able to index pdf contents.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/3/32228812f0c49a5af80a425ffbeefddd252a4dda.png)

Now problem is when I execute search it returns records but not able to highlight actual file contents, it displays file binary data:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/3/33b9a3cb94361c2ad6e9cf589f290b7ebac7a1a0.png)

Any suggestion?

---

<div class="post-metadata">

**Author:** ![Suyog\_Kale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyog_kale/32/5328_2.png) [@Suyog\_Kale](https://discuss.elastic.co/u/Suyog_Kale)\
**Post date:** [October 21, 2015, 9:25am UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/19 "2015-10-21T09:25:47Z")

</div>

What I also observed is that even there is no match in contents it returns all records in search result:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a13d06623a628cd929d8961fce32fb1b3d29ce89.png)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 21, 2015, 12:06pm UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/20 "2015-10-21T12:06:24Z")

</div>

Head plugin is buggy. Use POST instead of GET

---

<div class="post-metadata">

**Author:** ![ajoealex](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@ajoealex](https://discuss.elastic.co/u/ajoealex)\
**Post date:** [July 3, 2016, 4:51am UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/21 "2016-07-03T04:51:35Z")

</div>

Hi, I have the same issue that I cannot search from the attached document using NEST client  
My mapping is

```
 {
 "mydocs": {
  "mappings": {
     "indexdocument": {
        "properties": {
           "docLocation": {
              "type": "string",
              "index": "not_analyzed",
              "store": true
           },
           "documentType": {
              "type": "string",
              "store": true
           },
           "file": {
              "type": "attachment",
              "fields": {
                 "content": {
                    "type": "string",
                    "analyzer": "full"
                 },
                 "author": {
                    "type": "string"
                 },
                 "title": {
                    "type": "string",
                    "term_vector": "with_positions_offsets",
                    "analyzer": "full"
                 },
                 "name": {
                    "type": "string"
                 },
                 "date": {
                    "type": "date",
                    "format": "strict_date_optional_time||epoch_millis"
                 },
                 "keywords": {
                    "type": "string"
                 },
                 "content_type": {
                    "type": "string"
                 },
                 "content_length": {
                    "type": "integer"
                 },
                 "language": {
                    "type": "string"
                 }
              }
           },
           "filePermissionInfo": {
              "properties": {
                 "accessControlType": {
                    "type": "string",
                    "store": true
                 },
                 "accountValue": {
                    "type": "string",
                    "store": true
                 },
                 "fileSystemRights": {
                    "type": "string",
                    "store": true
                 },
                 "isInherited": {
                    "type": "string",
                    "store": true
                 }
              }
           },
           "id": {
              "type": "double",
              "store": true
           },
           "lastModifiedDate": {
              "type": "date",
              "store": true,
              "format": "strict_date_optional_time||epoch_millis"
           },
           "otherDetails": {
              "type": "string"
           },
           "title": {
              "type": "string",
              "store": true,
              "term_vector": "with_positions_offsets"
           }
        }
     }
  }
 }
}

```

My Post query is working fine

```
POST /mydocs/_search
{
"query" : {
    "bool" : {
        "must" : [
           
            { "match" : { "filePermissionInfo.accountValue" : "S-1-5-18"}} ,
           { "match":{"otherDetails":"xyz"}},
            { "match":{"file.content":"abc"}}              
           
        ]
    }
}
}

```

But when I convert it to C#, Its not working. If I remove the File.Content field from the match query , it returns resultset. So I think the problem is with the attachment field. It is base64 encoded

```
var queryResult = client.Search<IndexDocument>(s => s
                            .Index("mydocs")
                            .Query(q => q
                            .Bool(b => b
                            .Must(m =>
                                 m.Match(mt1 => mt1.Field(f1 => f1.DocumentType).Query(queryTerm)) &&
                                 m.Match(mt2 => mt2.Field(f2 => f2.FilePermissionInfo.First().AccountValue).Query(accountName)) &&
                                 m.Match(mt3 => mt3.Field(f3 => f3.OtherDetails).Query(other))
                             ))) );

```

Can you please help?

---

<div class="post-metadata">

**Author:** ![ajoealex](https://avatars.discourse-cdn.com/v4/letter/a/45deac/32.png) [@ajoealex](https://discuss.elastic.co/u/ajoealex)\
**Post date:** [July 4, 2016, 11:54am UTC](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473/22 "2016-07-04T11:54:24Z")

</div>

@dadoonet Can you please look into my issue?

[Next page](https://discuss.elastic.co/t/not-able-to-search-through-attachment-contents/32473.md?page=2)
