# Parse Failure \[Failed to parse source...\] - while doing string search in elasticsearch

**URL:** <https://discuss.elastic.co/t/parse-failure-failed-to-parse-source-while-doing-string-search-in-elasticsearch/16183>\
**Category:** Elasticsearch\
**Created:** [March 6, 2014, 8:26am UTC](https://discuss.elastic.co/t/parse-failure-failed-to-parse-source-while-doing-string-search-in-elasticsearch/16183 "2014-03-06T08:26:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 6, 2014, 8:26am UTC](https://discuss.elastic.co/t/parse-failure-failed-to-parse-source-while-doing-string-search-in-elasticsearch/16183/1 "2014-03-06T08:26:26Z")

</div>

Hi,

I'm new in elasticsearch and need some help. I'm getting below exception  
while trying to search a string in elasticsearch using Kibana. Below are  
the components I'm using.

1. logstash 1.3.3
2. redis : 2.4.10
3. elasticsearch: 1.0  
4.kibana

## I'm running elasticsearch with default, single cluster and 1 node. Please help to resolve this issue.

elasticsearch conf:  
##########################  
bootstrap.mlockall: true  
indices.cache.filter.size: 20%  
index.cache.field.max\_size: 50000  
index.cache.field.expire: 10m  
indices.fielddata.cache.size: 30%  
indices.fielddata.cache.expire: -1  
indices.memory.index\_buffer\_size: 50%  
index.refresh\_interval: 30s  
index.translog.flush\_threshold\_ops: 50000  
index.store.compress.stored: true

threadpool.search.type: fixed  
threadpool.search.size: 20  
threadpool.search.queue\_size: 100

threadpool.index.type: fixed  
threadpool.index.size: 30  
threadpool.index.queue\_size: 200

threadpool.bulk.type: fixed  
threadpool.bulk.size: 60  
threadpool.bulk.queue\_size: 300  
##############################

* * *

[2014-03-06 13:27:08,235][DEBUG][action.search.type] [Katherine  
"Kitty" Pryde] [logstash-2014.03.06][1], node[QUrNRW5cSi6IS3P\_BCZkHw], [P],  
s[STARTED]: Failed to execute  
[org.elasticsearch.action.search.SearchRequest@1c03a4f] lastShard [true]  
org.elasticsearch.search.SearchParseException: [logstash-2014.03.06][1]:  
from[-1],size[-1]: Parse Failure [Failed to parse source  
[{"query":{"filtered":{"query":{"bool":{"should":[{"query\_string":{"query":"/ec2.ap-southeast-1.amazonaws.com"}}]}},"filter":{"bool":{"must":[{"match\_all":{}},{"range":{"@timestamp":{"from":1394006201505,"to":"now"}}},{"bool":{"must":[{"match\_all":{}}]}}]}}}},"highlight":{"fields":{},"fragment\_size":2147483647,"pre\_tags":["@start-highlight@"],"post\_tags":["@end-highlight@"]},"size":20000,"sort":[{"@timestamp":{"order":"desc"}}]}]]  
at  
org.elasticsearch.search.SearchService.parseSource(SearchService.java:586)  
at  
org.elasticsearch.search.SearchService.createContext(SearchService.java:489)  
at  
org.elasticsearch.search.SearchService.createContext(SearchService.java:474)  
at  
org.elasticsearch.search.SearchService.createAndPutContext(SearchService.java:467)  
at  
org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:239)  
at  
org.elasticsearch.search.action.SearchServiceTransportAction.sendExecuteQuery(SearchServiceTransportAction.java:202)  
at  
org.elasticsearch.action.search.type.TransportSearchQueryThenFetchAction$AsyncAction.sendExecuteFirstPhase(TransportSearchQueryThenFetchAction.java:80)  
at  
org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:216)  
at  
org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:203)  
at  
org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction$2.run(TransportSearchTypeAction.java:186)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:895)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:918)  
at java.lang.Thread.run(Thread.java:662)  
Caused by: org.elasticsearch.index.query.QueryParsingException:  
[logstash-2014.03.06] Failed to parse query  
[/ec2.ap-southeast-1.amazonaws.com]  
at  
org.elasticsearch.index.query.QueryStringQueryParser.parse(QueryStringQueryParser.java:235)  
at  
org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
at  
org.elasticsearch.index.query.BoolQueryParser.parse(BoolQueryParser.java:107)  
at  
org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
at  
org.elasticsearch.index.query.FilteredQueryParser.parse(FilteredQueryParser.java:71)  
at  
org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
at  
org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:321)  
at  
org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:260)  
at  
org.elasticsearch.search.query.QueryParseElement.parse(QueryParseElement.java:33)  
at  
org.elasticsearch.search.SearchService.parseSource(SearchService.java:574)  
... 12 more  
Caused by: org.apache.lucene.queryparser.classic.ParseException: Cannot  
parse '/ec2.ap-southeast-1.amazonaws.com': Lexical error at line 1, column  
34. Encountered: after : "/ec2.ap-southeast-1.amazonaws.com"  
at  
org.apache.lucene.queryparser.classic.QueryParserBase.parse(QueryParserBase.java:130)  
at  
org.apache.lucene.queryparser.classic.MapperQueryParser.parse(MapperQueryParser.java:882)  
at  
org.elasticsearch.index.query.QueryStringQueryParser.parse(QueryStringQueryParser.java:218)  
... 21 more

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/75c89289-6448-475b-ac49-b9e133aec91e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/75c89289-6448-475b-ac49-b9e133aec91e%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 6, 2014, 9:18am UTC](https://discuss.elastic.co/t/parse-failure-failed-to-parse-source-while-doing-string-search-in-elasticsearch/16183/2 "2014-03-06T09:18:04Z")

</div>

Hey,

the exception tries to tell you, that there is a problem parsing the string  
''/ec2.ap-southeast-1.amazonaws.com'. The reason for this is, that the / is  
a reserved character. Just check out the reserved characters for the query  
and you can solve it

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

--Alex

On Thu, Mar 6, 2014 at 9:26 AM, Subhadip Bagui [i.bagui@gmail.com](mailto:i.bagui@gmail.com) wrote:

> Hi,
> 
> I'm new in elasticsearch and need some help. I'm getting below exception  
> while trying to search a string in elasticsearch using Kibana. Below are  
> the components I'm using.
> 
> 1. logstash 1.3.3
> 2. redis : 2.4.10
> 3. elasticsearch: 1.0  
> 4.kibana
> 
> ## I'm running elasticsearch with default, single cluster and 1 node. Please help to resolve this issue.
> 
> elasticsearch conf:  
> ##########################  
> bootstrap.mlockall: true  
> indices.cache.filter.size: 20%  
> index.cache.field.max\_size: 50000  
> index.cache.field.expire: 10m  
> indices.fielddata.cache.size: 30%  
> indices.fielddata.cache.expire: -1  
> indices.memory.index\_buffer\_size: 50%  
> index.refresh\_interval: 30s  
> index.translog.flush\_threshold\_ops: 50000  
> index.store.compress.stored: true
> 
> threadpool.search.type: fixed  
> threadpool.search.size: 20  
> threadpool.search.queue\_size: 100
> 
> threadpool.index.type: fixed  
> threadpool.index.size: 30  
> threadpool.index.queue\_size: 200
> 
> threadpool.bulk.type: fixed  
> threadpool.bulk.size: 60  
> threadpool.bulk.queue\_size: 300  
> ##############################
> 
> * * *
> 
> [2014-03-06 13:27:08,235][DEBUG][action.search.type] [Katherine  
> "Kitty" Pryde] [logstash-2014.03.06][1], node[QUrNRW5cSi6IS3P\_BCZkHw], [P],  
> s[STARTED]: Failed to execute  
> [org.elasticsearch.action.search.SearchRequest@1c03a4f] lastShard [true]  
> org.elasticsearch.search.SearchParseException: [logstash-2014.03.06][1]:  
> from[-1],size[-1]: Parse Failure [Failed to parse source  
> [{"query":{"filtered":{"query":{"bool":{"should":[{"query\_string":{"query":"/  
> [ec2.ap-southeast-1.amazonaws.com](http://ec2.ap-southeast-1.amazonaws.com)  
> "}}]}},"filter":{"bool":{"must":[{"match\_all":{}},{"range":{"@timestamp":{"from":1394006201505,"to":"now"}}},{"bool":{"must":[{"match\_all":{}}]}}]}}}},"highlight":{"fields":{},"fragment\_size":  
> 2147483647,"pre\_tags":["@start-highlight@"],"post\_tags":["@end-highlight@  
> "]},"size":20000,"sort":[{"@timestamp":{"order":"desc"}}]}]]  
> at  
> org.elasticsearch.search.SearchService.parseSource(SearchService.java:586)  
> at  
> org.elasticsearch.search.SearchService.createContext(SearchService.java:489)  
> at  
> org.elasticsearch.search.SearchService.createContext(SearchService.java:474)  
> at  
> org.elasticsearch.search.SearchService.createAndPutContext(SearchService.java:467)  
> at  
> org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:239)  
> at  
> org.elasticsearch.search.action.SearchServiceTransportAction.sendExecuteQuery(SearchServiceTransportAction.java:202)  
> at  
> org.elasticsearch.action.search.type.TransportSearchQueryThenFetchAction$AsyncAction.sendExecuteFirstPhase(TransportSearchQueryThenFetchAction.java:80)  
> at  
> org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:216)  
> at  
> org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:203)  
> at  
> org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction$2.run(TransportSearchTypeAction.java:186)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:895)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:918)  
> at java.lang.Thread.run(Thread.java:662)  
> Caused by: org.elasticsearch.index.query.QueryParsingException:  
> [logstash-2014.03.06] Failed to parse query [/  
> [ec2.ap-southeast-1.amazonaws.com](http://ec2.ap-southeast-1.amazonaws.com)]  
> at  
> org.elasticsearch.index.query.QueryStringQueryParser.parse(QueryStringQueryParser.java:235)  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
> at  
> org.elasticsearch.index.query.BoolQueryParser.parse(BoolQueryParser.java:107)  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
> at  
> org.elasticsearch.index.query.FilteredQueryParser.parse(FilteredQueryParser.java:71)  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:321)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:260)  
> at  
> org.elasticsearch.search.query.QueryParseElement.parse(QueryParseElement.java:33)  
> at  
> org.elasticsearch.search.SearchService.parseSource(SearchService.java:574)  
> ... 12 more  
> Caused by: org.apache.lucene.queryparser.classic.ParseException: Cannot  
> parse '/ec2.ap-southeast-1.amazonaws.com': Lexical error at line 1,  
> column 34. Encountered: after : "/ec2.ap-southeast-1.amazonaws.com"  
> at  
> org.apache.lucene.queryparser.classic.QueryParserBase.parse(QueryParserBase.java:130)  
> at  
> org.apache.lucene.queryparser.classic.MapperQueryParser.parse(MapperQueryParser.java:882)  
> at  
> org.elasticsearch.index.query.QueryStringQueryParser.parse(QueryStringQueryParser.java:218)  
> ... 21 more
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/75c89289-6448-475b-ac49-b9e133aec91e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/75c89289-6448-475b-ac49-b9e133aec91e%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/75c89289-6448-475b-ac49-b9e133aec91e%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/75c89289-6448-475b-ac49-b9e133aec91e%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGCwEM8ej2vfEJuLkG94Ozk\_PHfAeXAUOHTmf8yqDm28F1ED3A%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGCwEM8ej2vfEJuLkG94Ozk_PHfAeXAUOHTmf8yqDm28F1ED3A%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 7, 2014, 8:35am UTC](https://discuss.elastic.co/t/parse-failure-failed-to-parse-source-while-doing-string-search-in-elasticsearch/16183/3 "2014-03-07T08:35:11Z")

</div>

Hi,

I haven't used elasticsarch api for search results. I'm searchig the string  
using kibana gui. Please let me know how to enable special charter seach  
using kibana.

* * *

On Thursday, March 6, 2014 1:56:26 PM UTC+5:30, Subhadip Bagui wrote:

> Hi,
> 
> I'm new in elasticsearch and need some help. I'm getting below exception  
> while trying to search a string in elasticsearch using Kibana. Below are  
> the components I'm using.
> 
> 1. logstash 1.3.3
> 2. redis : 2.4.10
> 3. elasticsearch: 1.0  
> 4.kibana
> 
> ## I'm running elasticsearch with default, single cluster and 1 node. Please help to resolve this issue.
> 
> elasticsearch conf:  
> ##########################  
> bootstrap.mlockall: true  
> indices.cache.filter.size: 20%  
> index.cache.field.max\_size: 50000  
> index.cache.field.expire: 10m  
> indices.fielddata.cache.size: 30%  
> indices.fielddata.cache.expire: -1  
> indices.memory.index\_buffer\_size: 50%  
> index.refresh\_interval: 30s  
> index.translog.flush\_threshold\_ops: 50000  
> index.store.compress.stored: true
> 
> threadpool.search.type: fixed  
> threadpool.search.size: 20  
> threadpool.search.queue\_size: 100
> 
> threadpool.index.type: fixed  
> threadpool.index.size: 30  
> threadpool.index.queue\_size: 200
> 
> threadpool.bulk.type: fixed  
> threadpool.bulk.size: 60  
> threadpool.bulk.queue\_size: 300  
> ##############################
> 
> * * *
> 
> [2014-03-06 13:27:08,235][DEBUG][action.search.type] [Katherine  
> "Kitty" Pryde] [logstash-2014.03.06][1], node[QUrNRW5cSi6IS3P\_BCZkHw], [P],  
> s[STARTED]: Failed to execute  
> [org.elasticsearch.action.search.SearchRequest@1c03a4f] lastShard [true]  
> org.elasticsearch.search.SearchParseException: [logstash-2014.03.06][1]:  
> from[-1],size[-1]: Parse Failure [Failed to parse source  
> [{"query":{"filtered":{"query":{"bool":{"should":[{"query\_string":{"query":"/  
> [ec2.ap-southeast-1.amazonaws.com](http://ec2.ap-southeast-1.amazonaws.com)  
> "}}]}},"filter":{"bool":{"must":[{"match\_all":{}},{"range":{"@timestamp":{"from":1394006201505,"to":"now"}}},{"bool":{"must":[{"match\_all":{}}]}}]}}}},"highlight":{"fields":{},"fragment\_size":2147483647,"pre\_tags":["@start-highlight@"],"post\_tags":["@end-highlight@"]},"size":20000,"sort":[{"@timestamp":{"order":"desc"}}]}]]  
> at  
> org.elasticsearch.search.SearchService.parseSource(SearchService.java:586)  
> at  
> org.elasticsearch.search.SearchService.createContext(SearchService.java:489)  
> at  
> org.elasticsearch.search.SearchService.createContext(SearchService.java:474)  
> at  
> org.elasticsearch.search.SearchService.createAndPutContext(SearchService.java:467)  
> at  
> org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:239)  
> at  
> org.elasticsearch.search.action.SearchServiceTransportAction.sendExecuteQuery(SearchServiceTransportAction.java:202)  
> at  
> org.elasticsearch.action.search.type.TransportSearchQueryThenFetchAction$AsyncAction.sendExecuteFirstPhase(TransportSearchQueryThenFetchAction.java:80)  
> at  
> org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:216)  
> at  
> org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:203)  
> at  
> org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction$2.run(TransportSearchTypeAction.java:186)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:895)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:918)  
> at java.lang.Thread.run(Thread.java:662)  
> Caused by: org.elasticsearch.index.query.QueryParsingException:  
> [logstash-2014.03.06] Failed to parse query [/  
> [ec2.ap-southeast-1.amazonaws.com](http://ec2.ap-southeast-1.amazonaws.com)]  
> at  
> org.elasticsearch.index.query.QueryStringQueryParser.parse(QueryStringQueryParser.java:235)  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
> at  
> org.elasticsearch.index.query.BoolQueryParser.parse(BoolQueryParser.java:107)  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
> at  
> org.elasticsearch.index.query.FilteredQueryParser.parse(FilteredQueryParser.java:71)  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:321)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:260)  
> at  
> org.elasticsearch.search.query.QueryParseElement.parse(QueryParseElement.java:33)  
> at  
> org.elasticsearch.search.SearchService.parseSource(SearchService.java:574)  
> ... 12 more  
> Caused by: org.apache.lucene.queryparser.classic.ParseException: Cannot  
> parse '/ec2.ap-southeast-1.amazonaws.com': Lexical error at line 1,  
> column 34. Encountered: after : "/ec2.ap-southeast-1.amazonaws.com"  
> at  
> org.apache.lucene.queryparser.classic.QueryParserBase.parse(QueryParserBase.java:130)  
> at  
> org.apache.lucene.queryparser.classic.MapperQueryParser.parse(MapperQueryParser.java:882)  
> at  
> org.elasticsearch.index.query.QueryStringQueryParser.parse(QueryStringQueryParser.java:218)  
> ... 21 more

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/1bc92849-105e-4289-8c0a-446a3ea68995%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1bc92849-105e-4289-8c0a-446a3ea68995%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Binh\_Ly\_2](https://avatars.discourse-cdn.com/v4/letter/b/d07c76/32.png) [@Binh\_Ly\_2](https://discuss.elastic.co/u/Binh_Ly_2)\
**Post date:** [March 7, 2014, 1:21pm UTC](https://discuss.elastic.co/t/parse-failure-failed-to-parse-source-while-doing-string-search-in-elasticsearch/16183/4 "2014-03-07T13:21:31Z")

</div>

Try enclosing your search text in double quotes in Kibana:

"/blahblah"

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/812b0ecd-f773-4001-bc52-12b9e3a306ea%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/812b0ecd-f773-4001-bc52-12b9e3a306ea%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 10, 2014, 8:27am UTC](https://discuss.elastic.co/t/parse-failure-failed-to-parse-source-while-doing-string-search-in-elasticsearch/16183/5 "2014-03-10T08:27:41Z")

</div>

Thanks Binh. It's working now...

On Thursday, March 6, 2014 1:56:26 PM UTC+5:30, Subhadip Bagui wrote:

> Hi,
> 
> I'm new in elasticsearch and need some help. I'm getting below exception  
> while trying to search a string in elasticsearch using Kibana. Below are  
> the components I'm using.
> 
> 1. logstash 1.3.3
> 2. redis : 2.4.10
> 3. elasticsearch: 1.0  
> 4.kibana
> 
> ## I'm running elasticsearch with default, single cluster and 1 node. Please help to resolve this issue.
> 
> elasticsearch conf:  
> ##########################  
> bootstrap.mlockall: true  
> indices.cache.filter.size: 20%  
> index.cache.field.max\_size: 50000  
> index.cache.field.expire: 10m  
> indices.fielddata.cache.size: 30%  
> indices.fielddata.cache.expire: -1  
> indices.memory.index\_buffer\_size: 50%  
> index.refresh\_interval: 30s  
> index.translog.flush\_threshold\_ops: 50000  
> index.store.compress.stored: true
> 
> threadpool.search.type: fixed  
> threadpool.search.size: 20  
> threadpool.search.queue\_size: 100
> 
> threadpool.index.type: fixed  
> threadpool.index.size: 30  
> threadpool.index.queue\_size: 200
> 
> threadpool.bulk.type: fixed  
> threadpool.bulk.size: 60  
> threadpool.bulk.queue\_size: 300  
> ##############################
> 
> * * *
> 
> [2014-03-06 13:27:08,235][DEBUG][action.search.type] [Katherine  
> "Kitty" Pryde] [logstash-2014.03.06][1], node[QUrNRW5cSi6IS3P\_BCZkHw], [P],  
> s[STARTED]: Failed to execute  
> [org.elasticsearch.action.search.SearchRequest@1c03a4f] lastShard [true]  
> org.elasticsearch.search.SearchParseException: [logstash-2014.03.06][1]:  
> from[-1],size[-1]: Parse Failure [Failed to parse source  
> [{"query":{"filtered":{"query":{"bool":{"should":[{"query\_string":{"query":"/  
> [ec2.ap-southeast-1.amazonaws.com](http://ec2.ap-southeast-1.amazonaws.com)  
> "}}]}},"filter":{"bool":{"must":[{"match\_all":{}},{"range":{"@timestamp":{"from":1394006201505,"to":"now"}}},{"bool":{"must":[{"match\_all":{}}]}}]}}}},"highlight":{"fields":{},"fragment\_size":2147483647,"pre\_tags":["@start-highlight@"],"post\_tags":["@end-highlight@"]},"size":20000,"sort":[{"@timestamp":{"order":"desc"}}]}]]  
> at  
> org.elasticsearch.search.SearchService.parseSource(SearchService.java:586)  
> at  
> org.elasticsearch.search.SearchService.createContext(SearchService.java:489)  
> at  
> org.elasticsearch.search.SearchService.createContext(SearchService.java:474)  
> at  
> org.elasticsearch.search.SearchService.createAndPutContext(SearchService.java:467)  
> at  
> org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:239)  
> at  
> org.elasticsearch.search.action.SearchServiceTransportAction.sendExecuteQuery(SearchServiceTransportAction.java:202)  
> at  
> org.elasticsearch.action.search.type.TransportSearchQueryThenFetchAction$AsyncAction.sendExecuteFirstPhase(TransportSearchQueryThenFetchAction.java:80)  
> at  
> org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:216)  
> at  
> org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:203)  
> at  
> org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction$2.run(TransportSearchTypeAction.java:186)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:895)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:918)  
> at java.lang.Thread.run(Thread.java:662)  
> Caused by: org.elasticsearch.index.query.QueryParsingException:  
> [logstash-2014.03.06] Failed to parse query [/  
> [ec2.ap-southeast-1.amazonaws.com](http://ec2.ap-southeast-1.amazonaws.com)]  
> at  
> org.elasticsearch.index.query.QueryStringQueryParser.parse(QueryStringQueryParser.java:235)  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
> at  
> org.elasticsearch.index.query.BoolQueryParser.parse(BoolQueryParser.java:107)  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
> at  
> org.elasticsearch.index.query.FilteredQueryParser.parse(FilteredQueryParser.java:71)  
> at  
> org.elasticsearch.index.query.QueryParseContext.parseInnerQuery(QueryParseContext.java:223)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:321)  
> at  
> org.elasticsearch.index.query.IndexQueryParserService.parse(IndexQueryParserService.java:260)  
> at  
> org.elasticsearch.search.query.QueryParseElement.parse(QueryParseElement.java:33)  
> at  
> org.elasticsearch.search.SearchService.parseSource(SearchService.java:574)  
> ... 12 more  
> Caused by: org.apache.lucene.queryparser.classic.ParseException: Cannot  
> parse '/ec2.ap-southeast-1.amazonaws.com': Lexical error at line 1,  
> column 34. Encountered: after : "/ec2.ap-southeast-1.amazonaws.com"  
> at  
> org.apache.lucene.queryparser.classic.QueryParserBase.parse(QueryParserBase.java:130)  
> at  
> org.apache.lucene.queryparser.classic.MapperQueryParser.parse(MapperQueryParser.java:882)  
> at  
> org.elasticsearch.index.query.QueryStringQueryParser.parse(QueryStringQueryParser.java:218)  
> ... 21 more

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/03d8b104-f4f5-49d7-b74f-46fe2c4ab444%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/03d8b104-f4f5-49d7-b74f-46fe2c4ab444%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44am UTC](https://discuss.elastic.co/t/parse-failure-failed-to-parse-source-while-doing-string-search-in-elasticsearch/16183/6 "2017-07-06T01:44:33Z")

</div>


