# Query ES -combine exists with term query

**URL:** <https://discuss.elastic.co/t/query-es-combine-exists-with-term-query/131945>\
**Category:** Elasticsearch\
**Created:** [May 15, 2018, 1:45pm UTC](https://discuss.elastic.co/t/query-es-combine-exists-with-term-query/131945 "2018-05-15T13:45:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yaara](https://avatars.discourse-cdn.com/v4/letter/y/c2a13f/32.png) [@yaara](https://discuss.elastic.co/u/yaara)\
**Post date:** [May 15, 2018, 1:45pm UTC](https://discuss.elastic.co/t/query-es-combine-exists-with-term-query/131945/1 "2018-05-15T13:45:43Z")

</div>

Hi all,  
I trying to get the latest row that has the field "inventory", but I also want to filter it with specific ip:  
something like that:

`
GET discovery/hosts/_search
{
  "_source": [
    "inventory"
  ],
  "query": {
    "query": {
      "term": {
        "ip_address": "192.168.200.14"
      },
      "exists": {
        "field": "inventory"
      }
    }
  },
  "sort": {
    "timestamp": "desc"
  },
  "size": 1
}
`

it doesnt work, however if I query with only the term ot the exists (without the other), it works. I get the data differently so I assume that's why it doesnt work together because there's something I'm missing.

an idea how can I get all rows with that IP which has the "inventory" field (not null)?

thanks

---

<div class="post-metadata">

**Author:** ![yaara](https://avatars.discourse-cdn.com/v4/letter/y/c2a13f/32.png) [@yaara](https://discuss.elastic.co/u/yaara)\
**Post date:** [May 15, 2018, 2:06pm UTC](https://discuss.elastic.co/t/query-es-combine-exists-with-term-query/131945/2 "2018-05-15T14:06:48Z")

</div>

Got it 🙂

`
GET discovery/hosts/_search
{
  "_source": [
    "inventory",
    "nmap.ostype",
    "nmap.product"
  ],
  "query": {
    "bool": {
      "must": [
        {
          "term": {
            "ip_address": "192.168.200.14"
          }
        },
        {
          "exists": {
            "field": "inventory"
          }
        }
      ]
    }
  },
  "sort": {
    "timestamp": "desc"
  },
  "size": 1
}
`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2018, 2:17pm UTC](https://discuss.elastic.co/t/query-es-combine-exists-with-term-query/131945/3 "2018-06-12T14:17:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
