# Query for empty field, add new field later possible?

**URL:** <https://discuss.elastic.co/t/query-for-empty-field-add-new-field-later-possible/6617>\
**Category:** Elasticsearch\
**Created:** [February 7, 2012, 10:30am UTC](https://discuss.elastic.co/t/query-for-empty-field-add-new-field-later-possible/6617 "2012-02-07T10:30:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeangld](https://avatars.discourse-cdn.com/v4/letter/j/4af34b/32.png) [@jeangld](https://discuss.elastic.co/u/jeangld)\
**Post date:** [February 7, 2012, 10:30am UTC](https://discuss.elastic.co/t/query-for-empty-field-add-new-field-later-possible/6617/1 "2012-02-07T10:30:02Z")

</div>

Hi,

I'm having troubles to find the correct query to get all documents  
where a specific field is not set at all.

My test index has 3 text fields: field1, field2, field3. Some  
documents, have all fields filled, some only one or two of the fields.  
What would be the query to get all documents with an empty field2?

Let's say time goes by, the index grew, and I like to add another  
field "field4". Do I have to reindex all documents in the index again  
for such a schema change?

Thank you,

Jean

---

<div class="post-metadata">

**Author:** ![jeangld](https://avatars.discourse-cdn.com/v4/letter/j/4af34b/32.png) [@jeangld](https://discuss.elastic.co/u/jeangld)\
**Post date:** [February 18, 2012, 1:04am UTC](https://discuss.elastic.co/t/query-for-empty-field-add-new-field-later-possible/6617/2 "2012-02-18T01:04:46Z")

</div>

Hi,

I found a way to filter for a non set field, but I don't know if it's  
the most elegant way to do it. I guess the wildcard query has some  
computing overhead.

query: {  
bool: {  
must\_not:  
{  
wildcard: {  
source.county: \*  
}  
}  
}  
}

Regarding adding a new field, it's no problem at all, but ES still  
does some of its magic and sets the type by itself. If a field looks  
like 2012-02-02 it becomes automatically a date/timestamp field. I  
tried to set dynamic to false, with no luck. As I don't know

---

<div class="post-metadata">

**Author:** ![jeangld](https://avatars.discourse-cdn.com/v4/letter/j/4af34b/32.png) [@jeangld](https://discuss.elastic.co/u/jeangld)\
**Post date:** [February 18, 2012, 1:41am UTC](https://discuss.elastic.co/t/query-for-empty-field-add-new-field-later-possible/6617/3 "2012-02-18T01:41:07Z")

</div>

Hi,

I found a way to filter for a non set field, but I don't know if it's  
the most elegant way to do it. I guess the wildcard query has some  
computing overhead.

query: {  
bool: {  
must\_not:  
{  
wildcard: {  
field2: \*  
}  
}  
}  
}

Regarding adding a new field, it's no problem at all, but ES still  
does some of its magic and sets the type by itself. If a field looks  
like 2012-02-02 it becomes automatically a date/timestamp field. I  
tried to set dynamic to false, with no luck.

Since I don't know the field names and contents in advance,  
I want to just save everything as a string for now.

---

<div class="post-metadata">

**Author:** ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)\
**Post date:** [February 18, 2012, 10:45am UTC](https://discuss.elastic.co/t/query-for-empty-field-add-new-field-later-possible/6617/4 "2012-02-18T10:45:08Z")

</div>

On Tue, 2012-02-07 at 02:30 -0800, [jeangld@yahoo.com](mailto:jeangld@yahoo.com) wrote:

> Hi,
> 
> I'm having troubles to find the correct query to get all documents  
> where a specific field is not set at all.
> 
> My test index has 3 text fields: field1, field2, field3. Some  
> documents, have all fields filled, some only one or two of the fields.  
> What would be the query to get all documents with an empty field2?

curl -XGET '[http://127.0.0.1:9200/\_all/\_search?pretty=1](http://127.0.0.1:9200/_all/_search?pretty=1)' -d '  
{  
"query" : {  
"constant\_score" : {  
"filter" : {  
"missing" : {  
"field" : "field2"  
}  
}  
}  
}  
}  
'

> Let's say time goes by, the index grew, and I like to add another  
> field "field4". Do I have to reindex all documents in the index again  
> for such a schema change?

No - adding a new field is not a problem. Changing an existing field  
(eg field type or analyzer) would require reindexing.

clint

---

<div class="post-metadata">

**Author:** ![jeangld](https://avatars.discourse-cdn.com/v4/letter/j/4af34b/32.png) [@jeangld](https://discuss.elastic.co/u/jeangld)\
**Post date:** [February 21, 2012, 3:01pm UTC](https://discuss.elastic.co/t/query-for-empty-field-add-new-field-later-possible/6617/5 "2012-02-21T15:01:01Z")

</div>

Hi clint,

> curl -XGET '[http://127.0.0.1:9200/\_all/\_search?pretty=1](http://127.0.0.1:9200/_all/_search?pretty=1)' -d '  
> {  
> "query" : {  
> "constant\_score" : {  
> "filter" : {  
> "missing" : {  
> "field" : "field2"  
> }  
> }  
> }  
> }}

Your code works like a charm 🙂 I measued also the speed and it is  
significantly faster than my wildcard nonsense.

> No - adding a new field is not a problem. Changing an existing field  
> (eg field type or analyzer) would require reindexing.

Right. The only thing with new fields I'm trying now is to bypass the  
dynamic allocation at all. For the beginning I just want everything to  
be a string field, even if it starts like a date (2012-02-21...).  
Later on, I can decide what the correct field type is, change it and  
reindex the related stuff.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:38am UTC](https://discuss.elastic.co/t/query-for-empty-field-add-new-field-later-possible/6617/6 "2017-07-06T03:38:43Z")

</div>


