# Odd behavior with AND condition

**URL:** <https://discuss.elastic.co/t/odd-behavior-with-and-condition/17440>\
**Category:** Elasticsearch\
**Created:** [May 9, 2014, 10:31pm UTC](https://discuss.elastic.co/t/odd-behavior-with-and-condition/17440 "2014-05-09T22:31:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdj2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mdj2/32/1586_2.png) [@mdj2](https://discuss.elastic.co/u/mdj2)\
**Post date:** [May 9, 2014, 10:31pm UTC](https://discuss.elastic.co/t/odd-behavior-with-and-condition/17440/1 "2014-05-09T22:31:08Z")

</div>

When I run the query (tags:("a")) in elasticsearch, I get 0 results. My  
query URL looks like:

[http://127.0.0.1:9200/haystack/\_search?q=(tags%3A("a")](http://127.0.0.1:9200/haystack/_search?q=(tags%3A(%22a%22)))

That is to be expected, since no objects have a tag set to "a".

Now when I change the condition, and add an AND, (org:("1") AND tags:("a"))  
, _I get 3 results back_! The query URL looks like:

[http://127.0.0.1:9200/haystack/\_search?q=(org%3A("1")%20AND%20tags%3A("a")](http://127.0.0.1:9200/haystack/_search?q=(org%3A(%221%22)%20AND%20tags%3A(%22a%22)))

Getting _more_ results back does not make any sense to me. I would expect  
that kind of behavior with the OR operator, but AND? What is going on?

(This is a cross post from stackoverflow[http://stackoverflow.com/questions/23568699/odd-behavior-with-and-condition-in-elasticsearch](http://stackoverflow.com/questions/23568699/odd-behavior-with-and-condition-in-elasticsearch)  
)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/2abd1b1b-edc0-4714-846f-8d8a82a39240%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/2abd1b1b-edc0-4714-846f-8d8a82a39240%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![mdj2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mdj2/32/1586_2.png) [@mdj2](https://discuss.elastic.co/u/mdj2)\
**Post date:** [May 12, 2014, 9:33pm UTC](https://discuss.elastic.co/t/odd-behavior-with-and-condition/17440/2 "2014-05-12T21:33:10Z")

</div>

This appears to be caused by the snowball analyzer which is used on the  
"tags" field. To reproduce the odd behavior:

curl -XDELETE "[http://localhost:9200/haystack](http://localhost:9200/haystack)"

curl -XPOST "[http://localhost:9200/haystack/](http://localhost:9200/haystack/)" -d '  
{  
"settings":{  
"index":{}  
}  
}'

curl -XPOST "[http://localhost:9200/haystack/modelresult/\_mapping](http://localhost:9200/haystack/modelresult/_mapping)" -d '  
{  
"modelresult" : {  
"\_boost" : {  
"name" : "boost",  
"null\_value" : 1.0  
},  
"properties" : {  
"assigned\_to" : {  
"type" : "string",  
"term\_vector" : "with\_positions\_offsets",  
"analyzer" : "snowball"  
},  
"clipped\_from" : {  
"type" : "long",  
"index" : "analyzed"  
},  
"created\_by" : {  
"type" : "long",  
"index" : "analyzed"  
},  
"django\_ct" : {  
"type" : "string"  
},  
"django\_id" : {  
"type" : "string"  
},  
"id" : {  
"type" : "string"  
},  
"org" : {  
"type" : "long",  
"index" : "analyzed"  
},  
"tags" : {  
"type" : "string",  
"store" : true,  
"term\_vector" : "with\_positions\_offsets",  
"analyzer" : "snowball"  
},  
"text" : {  
"type" : "string",  
"store" : true,  
"term\_vector" : "with\_positions\_offsets",  
"analyzer" : "snowball"  
},  
"type" : {  
"type" : "long",  
"index" : "analyzed"  
}  
}  
}  
}'

curl -XPOST "[http://localhost:9200/haystack/modelresult/](http://localhost:9200/haystack/modelresult/)" -d '{  
"assigned\_to": ,  
"created\_by": 1,  
"django\_ct": "preparations.preparation",  
"django\_id": "37",  
"id": "preparations.preparation.37",  
"org": 1,  
"tags": [  
"foo"  
],  
"text": "Wildlife.wmv\n:)\n",  
"type": 2

}'

echo "Shows no results (good)"  
curl "[http://127.0.0.1:9200/haystack/\_search?q=(tags%3A("a")](http://127.0.0.1:9200/haystack/_search?q=(tags%3A(%22a%22)))&pretty"

echo "Should show no results, but finds a match"

curl  
"[http://127.0.0.1:9200/haystack/\_search?q=(org%3A("1")%20AND%20tags%3A("a")](http://127.0.0.1:9200/haystack/_search?q=(org%3A(%221%22)%20AND%20tags%3A(%22a%22)))&pretty"

Switching the tags field to the "standard" analyzer fixes the problem.

On Friday, May 9, 2014 3:31:08 PM UTC-7, md...@pdx.edu wrote:

> When I run the query (tags:("a")) in elasticsearch, I get 0 results. My  
> query URL looks like:
> 
> [http://127.0.0.1:9200/haystack/\_search?q=(tags%3A("a")](http://127.0.0.1:9200/haystack/_search?q=(tags%3A(%22a%22)))
> 
> That is to be expected, since no objects have a tag set to "a".
> 
> Now when I change the condition, and add an AND, (org:("1") AND  
> tags:("a")), _I get 3 results back_! The query URL looks like:
> 
> [http://127.0.0.1:9200/haystack/\_search?q=(org%3A("1")%20AND%20tags%3A("a")](http://127.0.0.1:9200/haystack/_search?q=(org%3A(%221%22)%20AND%20tags%3A(%22a%22)))
> 
> Getting _more_ results back does not make any sense to me. I would expect  
> that kind of behavior with the OR operator, but AND? What is going on?
> 
> (This is a cross post from stackoverflow[http://stackoverflow.com/questions/23568699/odd-behavior-with-and-condition-in-elasticsearch](http://stackoverflow.com/questions/23568699/odd-behavior-with-and-condition-in-elasticsearch)  
> )

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/fcaddf25-7aa6-46e0-873d-d52d349ad5af%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/fcaddf25-7aa6-46e0-873d-d52d349ad5af%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:29am UTC](https://discuss.elastic.co/t/odd-behavior-with-and-condition/17440/3 "2017-07-06T01:29:57Z")

</div>


