# Query from ES 2.3 to 5.5

**URL:** <https://discuss.elastic.co/t/query-from-es-2-3-to-5-5/94695>\
**Category:** Elasticsearch\
**Created:** [July 26, 2017, 7:18pm UTC](https://discuss.elastic.co/t/query-from-es-2-3-to-5-5/94695 "2017-07-26T19:18:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmbtenorio](https://avatars.discourse-cdn.com/v4/letter/m/ebca7d/32.png) [@mmbtenorio](https://discuss.elastic.co/u/mmbtenorio)\
**Post date:** [July 26, 2017, 7:18pm UTC](https://discuss.elastic.co/t/query-from-es-2-3-to-5-5/94695/1 "2017-07-26T19:18:55Z")

</div>

We're upgrading from ELK 2.3 to ELK 5.5, I'm trying to make this query work, tried to follow the query changes from ES 2.3 to 5.5 but every time I tweak something in it, different errors came up. Maybe someone can help me edit/translate these queries?

This is the original query and the error I got when I ran it in ES 5.5

 ![](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c95df40930a3db9d36d4d97a84034f7f582666f9.png)

So I changed "filtered" to "bool" based on this changes ---\>  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e56ab1a299819ee7c3b69a4c60f8372ed5e5fa95.png)

But I still get error...

 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/5/351c2890616e9c6784ef9f7ea8935130fdaa9926.png)

Then I tried to remove "bool" and "query" under "query" clause:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/2/a25c05f7ebd5a96a6edb6ecc782e36e35039dbb4.png)

I don't know where to go from here.  
Thanks in advance!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 26, 2017, 7:56pm UTC](https://discuss.elastic.co/t/query-from-es-2-3-to-5-5/94695/2 "2017-07-26T19:56:00Z")

</div>

Please don't post pictures of text, they are difficult to read and some people may not be even able to see them 🙂  
Are you able to repost the text, making sure it's code formatted?

---

<div class="post-metadata">

**Author:** ![mmbtenorio](https://avatars.discourse-cdn.com/v4/letter/m/ebca7d/32.png) [@mmbtenorio](https://discuss.elastic.co/u/mmbtenorio)\
**Post date:** [July 26, 2017, 8:28pm UTC](https://discuss.elastic.co/t/query-from-es-2-3-to-5-5/94695/3 "2017-07-26T20:28:22Z")

</div>

Sorry for that. Here are the codes:

Original Query:

```
    GET <index_name>/_search
    {
      "from": 0,
      "size": 5,
      "query": {
        "filtered": {
          "query": {
            "regexp": {
              "message": ".*reprocess costing data count = [1-9][0-9]*.*"
            }
          },
          "filter": {
            "bool": {
              "must": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-15m"
                    }
                  }
                }
              ],
              "must_not": []
            }
          }
        }
      }
    }

```

Error:

```
{
  "error": {
    "root_cause": [
      {
        "type": "parsing_exception",
        "reason": "no [query] registered for [filtered]",
        "line": 5,
        "col": 17
      }
    ],
    "type": "parsing_exception",
    "reason": "no [query] registered for [filtered]",
    "line": 5,
    "col": 17
  },
  "status": 400
}

```

Then changed "filtered" with "bool"(query clause):

```
GET <index_name>/_search
{
  "from": 0,
  "size": 5,
  "query": {
    "bool": {
      "query": {
        "regexp": {
          "message": ".*reprocess costing data count = [1-9][0-9]*.*"
        }
      },
      "filter": {
        "bool": {
          "must": [
            {
              "range": {
                "@timestamp": {
                  "gte": "now-15m"
                }
              }
            }
          ],
          "must_not": []
        }
      }
    }
  }
}

```

Error 2:

```
{
  "error": {
    "root_cause": [
      {
        "type": "parsing_exception",
        "reason": "[bool] query does not support [query]",
        "line": 6,
        "col": 16
      }
    ],
    "type": "parsing_exception",
    "reason": "[bool] query does not support [query]",
    "line": 6,
    "col": 16
  },
  "status": 400
}

```

Removed "bool" & "query" under "query" clause:

```
GET <index_name>/_search
{
  "from": 0,
  "size": 5,
  "query": {
    "regexp": {
      "message": ".*reprocess costing data count = [1-9][0-9]*.*"
    }
  },
  "filter": {
    "bool": {
      "must": [
        {
          "range": {
            "@timestamp": {
              "gte": "now-15m"
            }
          }
        }
      ],
      "must_not": []
    }
  }
}

```

Error 3:

```
{
  "error": {
    "root_cause": [
      {
        "type": "parsing_exception",
        "reason": "Unknown key for a START_OBJECT in [filter].",
        "line": 7,
        "col": 13
      }
    ],
    "type": "parsing_exception",
    "reason": "Unknown key for a START_OBJECT in [filter].",
    "line": 7,
    "col": 13
  },
  "status": 400
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2017, 8:28pm UTC](https://discuss.elastic.co/t/query-from-es-2-3-to-5-5/94695/4 "2017-08-23T20:28:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
