# Painless scripting - Using match\_phrase along with must\_not.exists

**URL:** <https://discuss.elastic.co/t/painless-scripting-using-match-phrase-along-with-must-not-exists/133498>\
**Category:** Elasticsearch\
**Created:** [May 28, 2018, 9:06am UTC](https://discuss.elastic.co/t/painless-scripting-using-match-phrase-along-with-must-not-exists/133498 "2018-05-28T09:06:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Suhas\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suhas_k/32/31525_2.png) [@Suhas\_K](https://discuss.elastic.co/u/Suhas_K)\
**Post date:** [May 28, 2018, 9:06am UTC](https://discuss.elastic.co/t/painless-scripting-using-match-phrase-along-with-must-not-exists/133498/1 "2018-05-28T09:06:02Z")

</div>

Hi,  
I am currently using painless scripting to parse through a message field, extract the required information and create a new field consisting of only that information. The issue I'm facing is that if the query is hit multiple times, the field in each of the documents gets updated every time.  
I wish to first check whether the field exists, and only update the document if it doesn't exist.

```auto
POST /index_name-DATE/doc/_update_by_query
{
  "query": {
    "bool": {
      "must_not": {
        "exists": {
          "field": "loginID"
        }
      }
    },
    "match_phrase": {
      "m": "\"|1000|||1|1|0|\""
    }
  },
  "script": {
    "lang": "painless",
    "source": "ctx._source.loginID = /.*\\| LOGIN_ID=(\\w{0,50})\\|.*/.matcher(ctx._source.m).replaceAll('$1')"
  }
}

```

I am unable to use both the required conditions together (must\_not and match\_phrase) and it is giving the following error message:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "parsing_exception",
        "reason": "[match_phrase] malformed query, expected [END_OBJECT] but found [FIELD_NAME]",
        "line": 1,
        "col": 53
      }
    ],
    "type": "parsing_exception",
    "reason": "[match_phrase] malformed query, expected [END_OBJECT] but found [FIELD_NAME]",
    "line": 1,
    "col": 53
  },
  "status": 400
}

```

Is there a way to achieve this?

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [May 28, 2018, 9:44am UTC](https://discuss.elastic.co/t/painless-scripting-using-match-phrase-along-with-must-not-exists/133498/2 "2018-05-28T09:44:08Z")

</div>

You can't just stick multiple queries inside a `"query"` clause like that. You need to combine them using a [compound query](https://www.elastic.co/guide/en/elasticsearch/reference/current/compound-queries.html) like a `bool` query.

In this case, you could wrap your `match_phrase` in a filter clause of the `bool` query you already have. The following should work:

```auto
POST /index_name-DATE/doc/_update_by_query
{
  "query": {
    "bool": {
      "must_not": {
        "exists": {
          "field": "loginID"
        }
      },
      "filter": {
        "match_phrase": {
          "m": "\"|1000|||1|1|0|\""
        }
      }
    }
  },
  "script": {
    "lang": "painless",
    "source": """ctx._source.loginID = /.*\| LOGIN_ID=(\w{0,50})\|.*/.matcher(ctx._source.m).replaceAll('$1')"""
  }
}

```

---

<div class="post-metadata">

**Author:** ![Suhas\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suhas_k/32/31525_2.png) [@Suhas\_K](https://discuss.elastic.co/u/Suhas_K)\
**Post date:** [May 28, 2018, 10:05am UTC](https://discuss.elastic.co/t/painless-scripting-using-match-phrase-along-with-must-not-exists/133498/3 "2018-05-28T10:05:37Z")

</div>

Hey,

You saved my day ! @abdon Thanks for the help 🐅

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2018, 10:05am UTC](https://discuss.elastic.co/t/painless-scripting-using-match-phrase-along-with-must-not-exists/133498/4 "2018-06-25T10:05:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
