# Problems with span\_not query

**URL:** <https://discuss.elastic.co/t/problems-with-span-not-query/17374>\
**Category:** Elasticsearch\
**Created:** [May 6, 2014, 2:44pm UTC](https://discuss.elastic.co/t/problems-with-span-not-query/17374 "2014-05-06T14:44:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matthew\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_brown/32/1588_2.png) [@Matthew\_Brown](https://discuss.elastic.co/u/Matthew_Brown)\
**Post date:** [May 6, 2014, 2:44pm UTC](https://discuss.elastic.co/t/problems-with-span-not-query/17374/1 "2014-05-06T14:44:24Z")

</div>

Having some problems with queries containing span\_not. I've simplified the  
query down to a test example however the query returns additional documents  
I don't think you be returned.

> <https://gist.github.com/m-brown/59b9b5ad6f68a5d12d0a>

In short I want to find the documents that contain 'foo' but not 'bar' from:  
foo  
foo bar  
bar foo  
foo foo bar  
foo bar foo  
bar foo foo

The below query returns two docs ('foo' and 'bar foo foo') rather than the  
one I was expecting:  
{  
"query": {  
"span\_not": {  
"include": {  
"span\_term": {  
"field1": "foo"  
}  
},  
"exclude": {  
"span\_near": {  
"in\_order": false,  
"clauses": [  
{  
"span\_term": {  
"field1": "bar"  
}  
},  
{  
"span\_term": {  
"field1": "foo"  
}  
}  
],  
"slop": 1000  
}  
}  
}  
}  
}

Why does 'bar foo foo' match the query, and given that it does, why don't  
any of the others given in\_order is false?

Tested on elasticsearch 1.0.1 and 1.1.1 on Ububtu 12.04.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/711fe54f-436c-453e-8a9d-59ff73c57c67%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/711fe54f-436c-453e-8a9d-59ff73c57c67%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [May 7, 2014, 9:12pm UTC](https://discuss.elastic.co/t/problems-with-span-not-query/17374/2 "2014-05-07T21:12:09Z")

</div>

My guess is that Lucene is matching on the second or third "foo" since  
"bar" does not appear in its span. That said, that means the 4th document  
should have match as well. Haven't actually run the query, but will try  
later.

Lucene now supports additional parameters for the span not query to extend  
the exclude portion "outside" of the matched span:  
[http://lucene.apache.org/core/4\_8\_0/core/org/apache/lucene/search/spans/SpanNotQuery.html](http://lucene.apache.org/core/4_8_0/core/org/apache/lucene/search/spans/SpanNotQuery.html)

I submitted a pull request to incorporate these new features a while ago,  
but the Elasticsearch team missed the change (they have a ton of open pull  
requests): [Expose `dist`/`pre`/`post` options for SpanNotQuery by brusic · Pull Request #4452 · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/pull/4452)

If you can convince them to merge my change, things should work for you. 🙂

Cheers,

Ivan

On Tue, May 6, 2014 at 7:44 AM, Matthew Brown [matthew@arachnys.com](mailto:matthew@arachnys.com) wrote:

> Having some problems with queries containing span\_not. I've simplified the  
> query down to a test example however the query returns additional documents  
> I don't think you be returned.
> 
> [gist:59b9b5ad6f68a5d12d0a · GitHub](https://gist.github.com/m-brown/59b9b5ad6f68a5d12d0a)
> 
> In short I want to find the documents that contain 'foo' but not 'bar'  
> from:  
> foo  
> foo bar  
> bar foo  
> foo foo bar  
> foo bar foo  
> bar foo foo
> 
> The below query returns two docs ('foo' and 'bar foo foo') rather than the  
> one I was expecting:  
> {  
> "query": {  
> "span\_not": {  
> "include": {  
> "span\_term": {  
> "field1": "foo"  
> }  
> },  
> "exclude": {  
> "span\_near": {  
> "in\_order": false,  
> "clauses": [  
> {  
> "span\_term": {  
> "field1": "bar"  
> }  
> },  
> {  
> "span\_term": {  
> "field1": "foo"  
> }  
> }  
> ],  
> "slop": 1000  
> }  
> }  
> }  
> }  
> }
> 
> Why does 'bar foo foo' match the query, and given that it does, why don't  
> any of the others given in\_order is false?
> 
> Tested on elasticsearch 1.0.1 and 1.1.1 on Ububtu 12.04.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/711fe54f-436c-453e-8a9d-59ff73c57c67%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/711fe54f-436c-453e-8a9d-59ff73c57c67%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/711fe54f-436c-453e-8a9d-59ff73c57c67%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/711fe54f-436c-453e-8a9d-59ff73c57c67%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQDfYf\_xgXWN\_L84HvzZWpUtF\_OTOEHAE19p88J8B9uJ5Q%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQDfYf_xgXWN_L84HvzZWpUtF_OTOEHAE19p88J8B9uJ5Q%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:30am UTC](https://discuss.elastic.co/t/problems-with-span-not-query/17374/3 "2017-07-06T01:30:57Z")

</div>


