# Query on index-pattern gets more results than expected

**URL:** <https://discuss.elastic.co/t/query-on-index-pattern-gets-more-results-than-expected/161565>\
**Category:** Elasticsearch\
**Created:** [December 19, 2018, 5:02pm UTC](https://discuss.elastic.co/t/query-on-index-pattern-gets-more-results-than-expected/161565 "2018-12-19T17:02:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![apiras](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@apiras](https://discuss.elastic.co/u/apiras)\
**Post date:** [December 19, 2018, 5:02pm UTC](https://discuss.elastic.co/t/query-on-index-pattern-gets-more-results-than-expected/161565/1 "2018-12-19T17:02:22Z")

</div>

Hi all,  
I'm using Elasticsearch 6.5.0.  
I created 3 index patterns with Kibana. They are like bank, bank\* and bank2.  
I'd like to search by API if the index bank is available and query ES in this way:

`GET /.kibana/_search`

```
{
"_source": [
    "index-pattern.title",
    "namespace",
    "type",
    "title"
],
"query": {
    "bool": {
        "filter": [
            {
                "bool": {
                    "must": [
                        {
                            "term": {
                                "type": "index-pattern"
                            }
                        },
                        {
                            "term": {
                                "index-pattern.title": {
                                    "value": "bank"
                                }
                            }
                        }
                    ],
                    "must_not": [
                        {
                            "exists": {
                                "field": "namespace"
                            }
                        }
                    ]
                }
            }
        ]
    }
}
}

```

I supposed to get an "hits" array only 1 "index-pattern": the one with title "bank".  
But I got "hits" with 2 index-pattern: one with title "bank" and the second with "bank\*".  
Like it:

```
{
"took": 1,
"timed_out": false,
"_shards": {
    "total": 1,
    "successful": 1,
    "skipped": 0,
    "failed": 0
},
"hits": {
    "total": 2,
    "max_score": 0,
    "hits": [
        {
            "_index": ".kibana",
            "_type": "doc",
            "_id": "index-pattern:111111",
            "_version": 1,
            "_score": 0,
            "_source": {
                "index-pattern": {
                    "title": "bank*"
                },
                "type": "index-pattern"
            }
        },
        {
            "_index": ".kibana",
            "_type": "doc",
            "_id": "index-pattern:22222",
            "_version": 2,
            "_score": 0,
            "_source": {
                "index-pattern": {
                    "title": "bank"
                },
                "type": "index-pattern"
            }
        }
    ]
}

```

}

How could I define a query to get only "bank"?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2019, 5:02pm UTC](https://discuss.elastic.co/t/query-on-index-pattern-gets-more-results-than-expected/161565/2 "2019-01-16T17:02:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
