# Query filter is not working

**URL:** <https://discuss.elastic.co/t/query-filter-is-not-working/16280>\
**Category:** Elasticsearch\
**Created:** [March 11, 2014, 8:18am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280 "2014-03-11T08:18:04Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 11, 2014, 8:18am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/1 "2014-03-11T08:18:04Z")

</div>

Hi,

I've a index in my elasticsearch like below

{

- "\_index":"logstash-2014.03.03",
- "\_type":"apache-access",
- "\_id":"snCPRnSHSvm\_aaeuHxB84w",
- "\_version":1,
- "found":true,
- "\_source":{
  - "message":"\tat  
org.apache.http.client.protocol.RequestProxyAuthentication.process(RequestProxyAuthentication.java:89)"  
,
  - "@version":"1",
  - "@timestamp":"2014-03-03T18:39:35.425+05:30",
  - "type":"apache-access",
  - "host":"[cloudclient.aricent.com](http://cloudclient.aricent.com)",
  - "path":"/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log"  
}

}

I’m trying to qrery the data using filter and below is the query

{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "message": "RequestProxyAuthentication" }  
}  
}  
}  
}

but the same is giving be null result from index search.  
{

- "took":275,
- "timed\_out":false,
- "\_shards":{
  - "total":5,
  - "successful":5,
  - "failed":0  
},

- "hits":{
  - "total":0,
  - "max\_score":null,
  - "hits":[  
]  
}

}

Kindly let mw know how to pass the query string

-Subhadip

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/586cb192-0abe-443b-9d4c-3d0669b89bcd%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/586cb192-0abe-443b-9d4c-3d0669b89bcd%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 11, 2014, 9:41am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/2 "2014-03-11T09:41:15Z")

</div>

lowercase your term filter.  
TermFilter is not analyzed.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 11 mars 2014 à 09:18, Subhadip Bagui [i.bagui@gmail.com](mailto:i.bagui@gmail.com) a écrit :

Hi,

I've a index in my elasticsearch like below

{  
"\_index":"logstash-2014.03.03",  
"\_type":"apache-access",  
"\_id":"snCPRnSHSvm\_aaeuHxB84w",  
"\_version":1,  
"found":true,  
"\_source":{  
"message":"\tat org.apache.http.client.protocol.RequestProxyAuthentication.process(RequestProxyAuthentication.java:89)",  
"@version":"1",  
"@timestamp":"2014-03-03T18:39:35.425+05:30",  
"type":"apache-access",  
"host":"[cloudclient.aricent.com](http://cloudclient.aricent.com)",  
"path":"/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log"  
}  
}

I’m trying to qrery the data using filter and below is the query

{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "message": "RequestProxyAuthentication" }  
}  
}  
}  
}

but the same is giving be null result from index search.  
{  
"took":275,  
"timed\_out":false,  
"\_shards":{  
"total":5,  
"successful":5,  
"failed":0  
},  
"hits":{  
"total":0,  
"max\_score":null,  
"hits":[  
]  
}  
}

Kindly let mw know how to pass the query string

## -Subhadip

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/586cb192-0abe-443b-9d4c-3d0669b89bcd%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/586cb192-0abe-443b-9d4c-3d0669b89bcd%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4CA390E6-0367-4821-A9B1-A3CA8E61E800%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/4CA390E6-0367-4821-A9B1-A3CA8E61E800%40pilato.fr).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 11, 2014, 10:02am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/3 "2014-03-11T10:02:56Z")

</div>

Hi David,

Trying to query as following, but still getting null result. Please suggest.

{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "message": "requestproxyauthentication" }  
}  
}  
}  
}

-Subhadip

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a9d10f48-d5fd-4578-b885-cfe0eb0fa3e1%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a9d10f48-d5fd-4578-b885-cfe0eb0fa3e1%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 11, 2014, 10:18am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/4 "2014-03-11T10:18:45Z")

</div>

what is your mapping?

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 11 mars 2014 à 11:03:00, Subhadip Bagui ([i.bagui@gmail.com](mailto:i.bagui@gmail.com)) a écrit:

Hi David,

Trying to query as following, but still getting null result. Please suggest.

{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "message": "requestproxyauthentication" }  
}  
}  
}  
}

## -Subhadip

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a9d10f48-d5fd-4578-b885-cfe0eb0fa3e1%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a9d10f48-d5fd-4578-b885-cfe0eb0fa3e1%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.531ee305.7fdcc233.b095%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.531ee305.7fdcc233.b095%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 11, 2014, 10:44am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/5 "2014-03-11T10:44:48Z")

</div>

mapping...

{

- "movies":{
  - "mappings":{
    - "movie":{
      - "properties":{
        - "director":{
          - "type":"string",
          - "fields":{
            - "original":{
              - "type":"string",
              - "index":"not\_analyzed"  
}  
}  
},

        - "genres":{
          - "type":"string"  
},

        - "query":{
          - "properties":{
            - "query\_string":{
              - "properties":{
                - "query":{
                  - "type":"string"  
}  
}  
}  
}  
},

        - "title":{
          - "type":"string"  
},

        - "year":{
          - "type":"long"  
}  
}  
}  
}  
}

}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5ea73df0-1ed6-4b4e-823f-ebc2bed6e46b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5ea73df0-1ed6-4b4e-823f-ebc2bed6e46b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 11, 2014, 10:48am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/6 "2014-03-11T10:48:56Z")

</div>

mapping...default

{

- "logstash-2014.03.03":{
  - "mappings":{
    - "apache-access":{
      - "dynamic\_templates":[
        - {
          - "string\_fields":{
            - "mapping":{
              - "type":"multi\_field",
              - "fields":{
                - "raw":{
                  - "index":"not\_analyzed",
                  - "ignore\_above":256,
                  - "type":"string"  
},

                - "{name}":{
                  - "index":"analyzed",
                  - "omit\_norms":true,
                  - "type":"string"  
}  
}  
},

            - "match":"\*",
            - "match\_mapping\_type":"string"  
}  
}  
],

      - "properties":{
        - "@timestamp":{
          - "type":"date",
          - "format":"dateOptionalTime"  
},

        - "@version":{
          - "type":"string",
          - "index":"not\_analyzed"  
},

        - "geoip":{
          - "dynamic":"true",
          - "properties":{
            - "location":{
              - "type":"geo\_point"  
}  
}  
},

        - "host":{
          - "type":"string",
          - "norms":{
            - "enabled":false  
},

          - "fields":{
            - "raw":{
              - "type":"string",
              - "index":"not\_analyzed",
              - "ignore\_above":256  
}  
}  
},

        - "message":{
          - "type":"string",
          - "norms":{
            - "enabled":false  
},

          - "fields":{
            - "raw":{
              - "type":"string",
              - "index":"not\_analyzed",
              - "ignore\_above":256  
}  
}  
},

        - "path":{
          - "type":"string",
          - "norms":{
            - "enabled":false  
},

          - "fields":{
            - "raw":{
              - "type":"string",
              - "index":"not\_analyzed",
              - "ignore\_above":256  
}  
}  
},

        - "query":{
          - "properties":{
            - "constant\_score":{
              - "properties":{
                - "filter":{
                  - "properties":{
                    - "term":{
                      - "properties":{
                        - "@timestamp":{
                          - "type":"date",
                          - "format":"dateOptionalTime"  
}  
}  
}  
}  
}  
}  
}  
}  
},

        - "type":{
          - "type":"string",
          - "norms":{
            - "enabled":false  
},

          - "fields":{
            - "raw":{
              - "type":"string",
              - "index":"not\_analyzed",
              - "ignore\_above":256  
}  
}  
}  
}  
}  
}  
}

}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/f3873f82-8000-4f35-8a3e-b2e29d7410f5%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f3873f82-8000-4f35-8a3e-b2e29d7410f5%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 11, 2014, 11:28am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/7 "2014-03-11T11:28:02Z")

</div>

So message seems to use a default analyzer…

May be you could try to reproduce your concern with a full curl recreation which:

delete test index,  
create index  
put template  
create a doc  
refresh  
query

It could help to understand what's wrong here. I'm probably missing something.

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 11 mars 2014 à 11:49:00, Subhadip Bagui ([i.bagui@gmail.com](mailto:i.bagui@gmail.com)) a écrit:

mapping...default

{

"logstash-2014.03.03":{

"mappings":{

"apache-access":{

"dynamic\_templates":[

{

"string\_fields":{

"mapping":{

"type":"multi\_field",

"fields":{

"raw":{

"index":"not\_analyzed",

"ignore\_above":256,

"type":"string"

},

"{name}":{

"index":"analyzed",

"omit\_norms":true,

"type":"string"

}

}

},

"match":"\*",

"match\_mapping\_type":"string"

}

}

],

"properties":{

"@timestamp":{

"type":"date",

"format":"dateOptionalTime"

},

"@version":{

"type":"string",

"index":"not\_analyzed"

},

"geoip":{

"dynamic":"true",

"properties":{

"location":{

"type":"geo\_point"

}

}

},

"host":{

"type":"string",

"norms":{

"enabled":false

},

"fields":{

"raw":{

"type":"string",

"index":"not\_analyzed",

"ignore\_above":256

}

}

},

"message":{

"type":"string",

"norms":{

"enabled":false

},

"fields":{

"raw":{

"type":"string",

"index":"not\_analyzed",

"ignore\_above":256

}

}

},

"path":{

"type":"string",

"norms":{

"enabled":false

},

"fields":{

"raw":{

"type":"string",

"index":"not\_analyzed",

"ignore\_above":256

}

}

},

"query":{

"properties":{

"constant\_score":{

"properties":{

"filter":{

"properties":{

"term":{

"properties":{

"@timestamp":{

"type":"date",

"format":"dateOptionalTime"

}

}

}

}

}

}

}

}

},

"type":{

"type":"string",

"norms":{

"enabled":false

},

"fields":{

"raw":{

"type":"string",

"index":"not\_analyzed",

"ignore\_above":256

}

}

}

}

}

}

}

## }

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/f3873f82-8000-4f35-8a3e-b2e29d7410f5%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f3873f82-8000-4f35-8a3e-b2e29d7410f5%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.531ef342.4e6afb66.b095%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.531ef342.4e6afb66.b095%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 11, 2014, 1:47pm UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/8 "2014-03-11T13:47:28Z")

</div>

Hi David,

I have done like below for a test sample.

1. deleted index.

2. create index by following  
curl -XPUT "[http://localhost:9200/movies/](http://localhost:9200/movies/)" -d  
'{ "index": {"\_index": "movies", "\_type": "movie", "\_id": "1"}}'

3. creating doc  
curl -XPUT "[http://localhost:9200/movies/movie/1](http://localhost:9200/movies/movie/1)" -d  
'{  
"title": "The Godfather",  
"director": "Francis Ford Coppola",  
"year": 1972,  
"genres": ["Crime", "Drama"]  
}'

4. creating mapping  
curl -XPUT "[http://localhost:9200/movies/movie/\_mapping](http://localhost:9200/movies/movie/_mapping)" -d  
'{  
"movie": {  
"properties": {  
"director": {  
"type": "multi\_field",  
"fields": {  
"director": {"type": "string"},  
"original": {"type" : "string", "index" : "not\_analyzed"}  
}  
}  
}  
}  
}'

5. query  
curl -XPOST "[http://localhost:9200/\_search](http://localhost:9200/_search)" -d'  
{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "director.original": "Francis Ford Coppola" }  
}  
}  
}  
}'

Please let me know what am I missing. I checked for template.

-Subhadip

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/7a736c32-34e7-4e7d-8a3d-c431c5c42175%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/7a736c32-34e7-4e7d-8a3d-c431c5c42175%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 11, 2014, 1:59pm UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/9 "2014-03-11T13:59:16Z")

</div>

This example has nothing in common with your data!

That said, you need to apply the mapping before indexing any document!

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 11 mars 2014 à 14:47:34, Subhadip Bagui ([i.bagui@gmail.com](mailto:i.bagui@gmail.com)) a écrit:

Hi David,

I have done like below for a test sample.

1. deleted index.

2. create index by following  
curl -XPUT "[http://localhost:9200/movies/](http://localhost:9200/movies/)" -d  
'{ "index": {"\_index": "movies", "\_type": "movie", "\_id": "1"}}'

3. creating doc  
curl -XPUT "[http://localhost:9200/movies/movie/1](http://localhost:9200/movies/movie/1)" -d  
'{  
"title": "The Godfather",  
"director": "Francis Ford Coppola",  
"year": 1972,  
"genres": ["Crime", "Drama"]  
}'

4. creating mapping  
curl -XPUT "[http://localhost:9200/movies/movie/\_mapping](http://localhost:9200/movies/movie/_mapping)" -d  
'{  
"movie": {  
"properties": {  
"director": {  
"type": "multi\_field",  
"fields": {  
"director": {"type": "string"},  
"original": {"type" : "string", "index" : "not\_analyzed"}  
}  
}  
}  
}  
}'

5. query  
curl -XPOST "[http://localhost:9200/\_search](http://localhost:9200/_search)" -d'  
{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "director.original": "Francis Ford Coppola" }  
}  
}  
}  
}'

Please let me know what am I missing. I checked for template.

## -Subhadip

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/7a736c32-34e7-4e7d-8a3d-c431c5c42175%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/7a736c32-34e7-4e7d-8a3d-c431c5c42175%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.531f16b4.75a2a8d4.b095%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.531f16b4.75a2a8d4.b095%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Binh\_Ly\_2](https://avatars.discourse-cdn.com/v4/letter/b/d07c76/32.png) [@Binh\_Ly\_2](https://discuss.elastic.co/u/Binh_Ly_2)\
**Post date:** [March 11, 2014, 6:20pm UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/10 "2014-03-11T18:20:23Z")

</div>

The standard analyzer makes (RequestProxyAuthentication.java) into 1 term  
and lowercases it. So this one should match it:

{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "message": "requestproxyauthentication.java" }  
}  
}  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/9d79a394-cd69-4967-a3aa-74d3195ea1cd%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9d79a394-cd69-4967-a3aa-74d3195ea1cd%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 12, 2014, 10:08am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/11 "2014-03-12T10:08:20Z")

</div>

Hi Binh,

The query you given is working. Thanks for your help.  
But if I change the query and search for string "requestproxyauthentication"  
instead, It's not working. Below is the mapping for message field.

I'm trying to understand how elasticsearch analyze the field data. Pls  
comment.

"message":{

- "type":"string",
- "norms":{
  - "enabled":false  
},

- "fields":{
  - "raw":{
    - "type":"string",
    - "index":"not\_analyzed",
    - "ignore\_above":256  
}  
}

}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/fb30d7b5-11ab-4ee7-a3cb-647663b11623%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/fb30d7b5-11ab-4ee7-a3cb-647663b11623%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 12, 2014, 10:13am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/12 "2014-03-12T10:13:08Z")

</div>

Didn't you read my previous answer?

This example has nothing in common with your data!  
That said, you need to apply the mapping before indexing any document!

We can't help you without a full curl recreation which actually reproduce your issue.  
I think you are doing something wrong here but it's difficult to say without any clue.

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 12 mars 2014 à 11:08:24, Subhadip Bagui ([i.bagui@gmail.com](mailto:i.bagui@gmail.com)) a écrit:

Hi Binh,

The query you given is working. Thanks for your help.  
But if I change the query and search for string "requestproxyauthentication" instead, It's not working. Below is the mapping for message field.

I'm trying to understand how elasticsearch analyze the field data. Pls comment.

## "message":{ "type":"string", "norms":{ "enabled":false }, "fields":{ "raw":{ "type":"string", "index":"not\_analyzed", "ignore\_above":256 } } }

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/fb30d7b5-11ab-4ee7-a3cb-647663b11623%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/fb30d7b5-11ab-4ee7-a3cb-647663b11623%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.53203334.2ae8944a.bfa%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.53203334.2ae8944a.bfa%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 12, 2014, 10:25am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/13 "2014-03-12T10:25:47Z")

</div>

Hi David,

The data is coming through logstash and taking default mapping in  
elasticsearch. Can I do update mapping for that index id ?  
Pls let me know.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/dc119c29-264c-4e23-be8b-9a7ccd18ad47%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dc119c29-264c-4e23-be8b-9a7ccd18ad47%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 12, 2014, 10:29am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/14 "2014-03-12T10:29:56Z")

</div>

May be this could help?  
[http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/indices-templates.html#indices-templates](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/indices-templates.html#indices-templates)

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 12 mars 2014 à 11:25:53, Subhadip Bagui ([i.bagui@gmail.com](mailto:i.bagui@gmail.com)) a écrit:

Hi David,

The data is coming through logstash and taking default mapping in elasticsearch. Can I do update mapping for that index id ?  
Pls let me know.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/dc119c29-264c-4e23-be8b-9a7ccd18ad47%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dc119c29-264c-4e23-be8b-9a7ccd18ad47%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.53203724.79e2a9e3.bfa%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.53203724.79e2a9e3.bfa%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 13, 2014, 11:07am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/15 "2014-03-13T11:07:02Z")

</div>

Hi David,

I have done following steps u suggested. The exact string search is working  
now.  
But when I'm trying the below query for string matching it's giving null  
result.

May this is very basic and I'm doing something wrong. I'm a week old on  
elasticsearch and trying to understand the query-sql and text search. Pls  
help to clear the conception.

## create index create mapping create a doc refresh query

query==\>  
{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "message.original":  
"org.apache.http.protocol.immutablehttpprocessor.process" }  
}  
}  
}  
}

mapping ==\>  
{

- "log-2014.03.03":{
  - "mappings":{
    - "apache-log":{
      - "properties":{
        - "@timestamp":{
          - "type":"date",
          - "format":"yyyy-MM-dd HH:mm:ss"  
},

        - "@version":{
          - "type":"long"  
},

        - "host":{
          - "type":"string",
          - "index":"not\_analyzed"  
},

        - "message":{
          - "type":"string",
          - "fields":{
            - "actual":{
              - "type":"string",
              - "index":"not\_analyzed"  
}  
}  
},

        - "path":{
          - "type":"string",
          - "index":"not\_analyzed"  
},

        - "type":{
          - "type":"string",
          - "index":"not\_analyzed"  
}  
}  
}  
}  
}

}

doc ==\>  
{

- "\_index":"log-2014.03.03",
- "\_type":"apache-log",
- "\_id":"5",
- "\_version":1,
- "found":true,
- "\_source":{
  - "message":"org.apache.http.protocol.ImmutableHttpProcessor.process",
  - "@version":"3",
  - "@timestamp":"2014-03-03 18:45:35",
  - "type":"apache-access",
  - "host":"[cloudclient.aricent.com](http://cloudclient.aricent.com)",
  - "path":"/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log"  
}

}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/74e0cc0e-25db-47cf-8524-cc1c151a7a76%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/74e0cc0e-25db-47cf-8524-cc1c151a7a76%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![bagui](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bagui/32/960_2.png) [@bagui](https://discuss.elastic.co/u/bagui)\
**Post date:** [March 13, 2014, 1:24pm UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/16 "2014-03-13T13:24:34Z")

</div>

Hi David,

I have done following steps u suggested. The string search is working now.

But for filter I have to always pass strings in lowercase; where as for  
query text search I can give the proper string sequence inserted in doc.  
query shown below.

May be this is very basic and I'm doing something wrong. I'm a week old on  
elasticsearch and trying to understand the query-sql and text search. Pls  
help to clear the conception.

1. curl -XDELETE [http://10.203.251.142:9200/log-2014.03.03](http://10.203.251.142:9200/log-2014.03.03)

2. 

curl -XPUT [http://10.203.251.142:9200/log-2014.03.03/](http://10.203.251.142:9200/log-2014.03.03/) -d  
'{  
"settings": {  
"index": {  
"number\_of\_shards": 3,  
"number\_of\_replicas": 0,  
"index.cache.field.type": "soft",  
"index.refresh\_interval": "30s",  
"index.store.compress.stored": true  
}  
},  
"mappings": {  
"apache-log": {  
"properties": {  
"message": {  
"type": "string",  
"fields": {  
"actual": {  
"type": "string",  
"index": "not\_analyzed"  
}  
}  
},  
"@version": {  
"type": "long",  
"index": "not\_analyzed"  
},  
"@timestamp": {  
"type": "date",  
"format": "yyyy-MM-dd HH:mm:ss",  
"index": "not\_analyzed"  
},  
"type": {  
"type": "string",  
"index": "not\_analyzed"  
},  
"host": {  
"type": "string",  
"index": "not\_analyzed"  
},  
"path": {  
"type": "string",  
"norms": {  
"enabled": false  
},  
"index": "not\_analyzed"  
}  
}  
}  
}  
}'

1. curl -XPUT [http://10.203.251.142:9200/\_bulk](http://10.203.251.142:9200/_bulk) -d '  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "1"}}  
{ "message": "03-03-2014 18:39:35,025 DEBUG  
[org.springframework.scheduling.quartz.SchedulerFactoryBean#0\_Worker-8]  
com.aricent.aricloud.monitoring.CloudController 121 -  
com.sun.jersey.core.spi.factory.ResponseImpl@1139f1b","@version":  
"1","@timestamp": "2014-03-03 18:39:35","type": "apache-access", "host":  
"[cloudclient.aricent.com](http://cloudclient.aricent.com)", "path":  
"/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "2"}}  
{ "message": "\tat org.quartz.core.JobRunShell.run(JobRunShell.java:223)",  
"@version": "1", "@timestamp": "2014-03-03 18:39:36","type":  
"apache-access", "host": "[cloudclient.aricent.com](http://cloudclient.aricent.com)", "path":  
"/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "3"}}  
{ "message": "03-03-2014 18:39:35,030 INFO  
[org.springframework.scheduling.quartz.SchedulerFactoryBean#0\_Worker-8]  
com.amazonaws.http.HttpClientFactory 128 - Configuring Proxy. Proxy Host:  
10.203.193.227 Proxy Port: 80", "@version": "2", "@timestamp": "2014-03-03  
18:40:35", "type": "apache-access", "host": "[cloudclient.aricent.com](http://cloudclient.aricent.com)",  
"path": "/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "4"}}  
{ "message": "\tat  
org.apache.http.protocol.ImmutableHttpProcessor.process(ImmutableHttpProcessor.java:109)",  
"@version": "3", "@timestamp": "2014-03-03 18:43:35", "type":  
"apache-access", "host": "[cloudclient.aricent.com](http://cloudclient.aricent.com)", "path":  
"/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "5"}}  
{ "message": "03-03-2014 18:45:30,002 DEBUG  
[org.springframework.scheduling.quartz.SchedulerFactoryBean#0\_Worker-9]  
com.aricent.aricloud.monitoring.scheduler.SchedulerJob 22 - Entering  
SchedulerJob", "@version": "3", "@timestamp": "2014-03-03 18:45:35",  
"type": "apache-access", "host": "[cloudclient.aricent.com](http://cloudclient.aricent.com)", "path":  
"/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
\n'

2. curl -XGET '[http://10.203.251.142:9200/log-2014.03.03/\_refresh](http://10.203.251.142:9200/log-2014.03.03/_refresh)'

3. query ==\>  
curl -XPOST [http://10.203.251.142:9200/log-2014.03.03/\_search](http://10.203.251.142:9200/log-2014.03.03/_search) -d  
'{  
"query": {  
"match": {  
"message" : {  
"query": "Proxy Port",  
"type" : "phrase"  
}  
}  
}  
}'

null value -  
curl -XPOST [http://10.203.251.142:9200/log-2014.03.03/\_search](http://10.203.251.142:9200/log-2014.03.03/_search) -d  
'{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "message": "DEBUG" }  
}  
}  
}  
}  
'

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/9daed515-6990-45a3-af47-b87d10bc44ae%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9daed515-6990-45a3-af47-b87d10bc44ae%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 13, 2014, 1:56pm UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/17 "2014-03-13T13:56:36Z")

</div>

message field has been analyzed using standard analyzer. It means that you message content has been indexed using lowercase.  
a Term Filter does not analyze your query.

"DEBUG" is \<\> than "debug".

If you want to find your term in the inverted index, you have either to analyze your query (matchQuery for example) or lowercase in that case your searched term.

curl -XPOST [http://10.203.251.142:9200/log-2014.03.03/\_search](http://10.203.251.142:9200/log-2014.03.03/_search) -d  
'{  
"query": {  
"constant\_score": {  
"filter": {  
"term": { "message": "debug" }  
}  
}  
}  
}  
'

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 13 mars 2014 à 14:24:39, Subhadip Bagui ([i.bagui@gmail.com](mailto:i.bagui@gmail.com)) a écrit:

Hi David,

I have done following steps u suggested. The string search is working now.

But for filter I have to always pass strings in lowercase; where as for query text search I can give the proper string sequence inserted in doc. query shown below.

May be this is very basic and I'm doing something wrong. I'm a week old on elasticsearch and trying to understand the query-sql and text search. Pls help to clear the conception.

1. curl -XDELETE [http://10.203.251.142:9200/log-2014.03.03](http://10.203.251.142:9200/log-2014.03.03)

2. 

curl -XPUT [http://10.203.251.142:9200/log-2014.03.03/](http://10.203.251.142:9200/log-2014.03.03/) -d  
'{  
"settings": {  
"index": {  
"number\_of\_shards": 3,  
"number\_of\_replicas": 0,  
"index.cache.field.type": "soft",  
"index.refresh\_interval": "30s",  
"index.store.compress.stored": true  
}  
},  
"mappings": {  
"apache-log": {  
"properties": {  
"message": {  
"type": "string",  
"fields": {  
"actual": {  
"type": "string",  
"index": "not\_analyzed"  
}  
}  
},  
"@version": {  
"type": "long",  
"index": "not\_analyzed"  
},  
"@timestamp": {  
"type": "date",  
"format": "yyyy-MM-dd HH:mm:ss",  
"index": "not\_analyzed"  
},  
"type": {  
"type": "string",  
"index": "not\_analyzed"  
},  
"host": {  
"type": "string",  
"index": "not\_analyzed"  
},  
"path": {  
"type": "string",  
"norms": {  
"enabled": false  
},  
"index": "not\_analyzed"  
}  
}  
}  
}  
}'

1. curl -XPUT [http://10.203.251.142:9200/\_bulk](http://10.203.251.142:9200/_bulk) -d '  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "1"}}  
{ "message": "03-03-2014 18:39:35,025 DEBUG [org.springframework.scheduling.quartz.SchedulerFactoryBean#0\_Worker-8] com.aricent.aricloud.monitoring.CloudController 121 - com.sun.jersey.core.spi.factory.ResponseImpl@1139f1b","@version": "1","@timestamp": "2014-03-03 18:39:35","type": "apache-access", "host": "[cloudclient.aricent.com](http://cloudclient.aricent.com)", "path": "/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "2"}}  
{ "message": "\tat org.quartz.core.JobRunShell.run(JobRunShell.java:223)", "@version": "1", "@timestamp": "2014-03-03 18:39:36","type": "apache-access", "host": "[cloudclient.aricent.com](http://cloudclient.aricent.com)", "path": "/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "3"}}  
{ "message": "03-03-2014 18:39:35,030 INFO [org.springframework.scheduling.quartz.SchedulerFactoryBean#0\_Worker-8] com.amazonaws.http.HttpClientFactory 128 - Configuring Proxy. Proxy Host: 10.203.193.227 Proxy Port: 80", "@version": "2", "@timestamp": "2014-03-03 18:40:35", "type": "apache-access", "host": "[cloudclient.aricent.com](http://cloudclient.aricent.com)", "path": "/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "4"}}  
{ "message": "\tat org.apache.http.protocol.ImmutableHttpProcessor.process(ImmutableHttpProcessor.java:109)", "@version": "3", "@timestamp": "2014-03-03 18:43:35", "type": "apache-access", "host": "[cloudclient.aricent.com](http://cloudclient.aricent.com)", "path": "/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
{ "index": {"\_index": "log-2014.03.03", "\_type": "apache-log", "\_id": "5"}}  
{ "message": "03-03-2014 18:45:30,002 DEBUG [org.springframework.scheduling.quartz.SchedulerFactoryBean#0\_Worker-9] com.aricent.aricloud.monitoring.scheduler.SchedulerJob 22 - Entering SchedulerJob", "@version": "3", "@timestamp": "2014-03-03 18:45:35", "type": "apache-access", "host": "[cloudclient.aricent.com](http://cloudclient.aricent.com)", "path": "/opt/apache-tomcat-7.0.40/logs/aricloud/monitoring.log" }  
\n'

2. curl -XGET '[http://10.203.251.142:9200/log-2014.03.03/\_refresh](http://10.203.251.142:9200/log-2014.03.03/_refresh)'

3. query ==\>  
curl -XPOST [http://10.203.251.142:9200/log-2014.03.03/\_search](http://10.203.251.142:9200/log-2014.03.03/_search) -d  
'{  
"query": {  
"match": {  
"message" : {  
"query": "Proxy Port",  
"type" : "phrase"  
}  
}  
}  
}'

## null value - curl -XPOST [http://10.203.251.142:9200/log-2014.03.03/\_search](http://10.203.251.142:9200/log-2014.03.03/_search) -d '{ "query": { "constant\_score": { "filter": { "term": { "message": "DEBUG" } } } } } '

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/9daed515-6990-45a3-af47-b87d10bc44ae%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/9daed515-6990-45a3-af47-b87d10bc44ae%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.5321b914.216231b.158d%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.5321b914.216231b.158d%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43am UTC](https://discuss.elastic.co/t/query-filter-is-not-working/16280/18 "2017-07-06T01:43:28Z")

</div>


