# Query or Index problem, please help

**URL:** <https://discuss.elastic.co/t/query-or-index-problem-please-help/19340>\
**Category:** Elasticsearch\
**Created:** [August 19, 2014, 1:10pm UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340 "2014-08-19T13:10:21Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vitaly\_bulgakov](https://avatars.discourse-cdn.com/v4/letter/v/76d3ee/32.png) [@vitaly\_bulgakov](https://discuss.elastic.co/u/vitaly_bulgakov)\
**Post date:** [August 19, 2014, 1:10pm UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340/1 "2014-08-19T13:10:21Z")

</div>

Using elasticsearch-head I do query  
{  
"query": {  
"term": {  
"NONSENSE":"NONSENSE"  
}  
}  
}  
The result shows the entire set no matter what I type in "term"  
{

- took: 2
- timed\_out: false
- \_shards: {
  - total: 5
  - successful: 5
  - failed: 0  
}

- hits: {
  - total: 10
  - max\_score: 1
  - hits: [
    - {
      - \_index: logstash-2014.08.18
      - \_type: logs
      - \_id: SMUgTGR9R-2SVaL1GTeX9A
      - \_score: 1
      - \_source: {
        - message: ......
        - @version: 1
        - @timestamp: 2014-08-18T16:16:48.797Z
        - host: .........
        - kw: area a realty
        - town: South Bend
        - state: IN
        - ip: 198.64.136.68
        - src: ve-whitepages-dt  
}  
}

    - {
      - \_index: logstash-2014.08.18
      - \_type: logs
      - \_id: yWR6DC9sQ2yAqxG9FJXauw
      - \_score: 1
      - \_source: {
        - message: ......
        - @version: 1
        - @timestamp: 2014-08-18T16:16:48.797Z
        - host: .......
        - kw: Doors
        - town: Chicago
        - state: IL
        - ip: 98.213.210.163
        - src: lsxppc21611  
}  
}

    - {
      - \_index: logstash-2014.08.18
      - \_type: logs
      - \_id: Z\_e-DQQkSv2ON1ar1WooSQ
      - \_score: 1
      - \_source: {
        - message: .......
        - @version: 1
        - @timestamp: 2014-08-18T16:16:48.797Z
        - host: .......
        - kw: home improvement
        - town: Clarkston
        - state: GA
        - ip: 172.56.1.181
        - src: lsxppc19735  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 19, 2014, 1:20pm UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340/2 "2014-08-19T13:20:26Z")

</div>

I don't really understand the question but I'd say that you should use Marvel / Sense.  
It has a better support for running queries.

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 19 août 2014 à 15:10:25, vitaly ([vitaly.bulgakov@gmail.com](mailto:vitaly.bulgakov@gmail.com)) a écrit:

## Using elasticsearch-head I do query { "query": { "term": { "NONSENSE":"NONSENSE" } } } The result shows the entire set no matter what I type in "term" { took: 2 timed\_out: false \_shards: { total: 5 successful: 5 failed: 0 } hits: { total: 10 max\_score: 1 hits: [ { \_index: logstash-2014.08.18 \_type: logs \_id: SMUgTGR9R-2SVaL1GTeX9A \_score: 1 \_source: { message: ...... @version: 1 @timestamp: 2014-08-18T16:16:48.797Z host: ......... kw: area a realty town: South Bend state: IN ip: 198.64.136.68 src: ve-whitepages-dt } } { \_index: logstash-2014.08.18 \_type: logs \_id: yWR6DC9sQ2yAqxG9FJXauw \_score: 1 \_source: { message: ...... @version: 1 @timestamp: 2014-08-18T16:16:48.797Z host: ....... kw: Doors town: Chicago state: IL ip: 98.213.210.163 src: lsxppc21611 } } { \_index: logstash-2014.08.18 \_type: logs \_id: Z\_e-DQQkSv2ON1ar1WooSQ \_score: 1 \_source: { message: ....... @version: 1 @timestamp: 2014-08-18T16:16:48.797Z host: ....... kw: home improvement town: Clarkston state: GA ip: 172.56.1.181 src: lsxppc19735 } }

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.53f34f1a.431bd7b7.132%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.53f34f1a.431bd7b7.132%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vitaly\_bulgakov](https://avatars.discourse-cdn.com/v4/letter/v/76d3ee/32.png) [@vitaly\_bulgakov](https://discuss.elastic.co/u/vitaly_bulgakov)\
**Post date:** [August 19, 2014, 1:40pm UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340/3 "2014-08-19T13:40:12Z")

</div>

David, my question is what I am doing wrong.

Also when I do URI search  
http://:9200/\_search?q="state:IN"  
I am getting 0 results

{"took":2,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":}}

What I could do wrong?

On Tuesday, August 19, 2014 9:20:43 AM UTC-4, David Pilato wrote:

> I don't really understand the question but I'd say that you should use  
> Marvel / Sense.  
> It has a better support for running queries.
> 
> --  
> _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr  
> [https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)
> 
> Le 19 août 2014 à 15:10:25, vitaly ([vitaly....@gmail.com](mailto:vitaly....@gmail.com) \<javascript:\>) a  
> écrit:
> 
> Using elasticsearch-head I do query  
> {  
> "query": {  
> "term": {  
> "NONSENSE":"NONSENSE"  
> }  
> }  
> }  
> The result shows the entire set no matter what I type in "term"  
> {
> 
> - took: 2
> - timed\_out: false
> - \_shards: {
> - total: 5
> - successful: 5
> - failed: 0  
> }
> 
> - hits: {
> - total: 10
> - max\_score: 1
> - hits: [
> - {
> - \_index: logstash-2014.08.18
> - \_type: logs
> - \_id: SMUgTGR9R-2SVaL1GTeX9A
> - \_score: 1
> - \_source: {
> - message: ......
> - @version: 1
> - @timestamp: 2014-08-18T16:16:48.797Z
> - host: .........
> - kw: area a realty
> - town: South Bend
> - state: IN
> - ip: 198.64.136.68
> - src: ve-whitepages-dt  
> }  
> }
> 
> - {
> - \_index: logstash-2014.08.18
> - \_type: logs
> - \_id: yWR6DC9sQ2yAqxG9FJXauw
> - \_score: 1
> - \_source: {
> - message: ......
> - @version: 1
> - @timestamp: 2014-08-18T16:16:48.797Z
> - host: .......
> - kw: Doors
> - town: Chicago
> - state: IL
> - ip: 98.213.210.163
> - src: lsxppc21611  
> }  
> }
> 
> - {
> - \_index: logstash-2014.08.18
> - \_type: logs
> - \_id: Z\_e-DQQkSv2ON1ar1WooSQ
> - \_score: 1
> - \_source: {
> - message: .......
> - @version: 1
> - @timestamp: 2014-08-18T16:16:48.797Z
> - host: .......
> - kw: home improvement
> - town: Clarkston
> - state: GA
> - ip: 172.56.1.181
> - src: lsxppc19735  
> }  
> }
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 19, 2014, 1:43pm UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340/4 "2014-08-19T13:43:12Z")

</div>

Have a look at [http://www.elasticsearch.org/help/](http://www.elasticsearch.org/help/)

We can probably help you if we understand what exactly you are doing.

IN could be an english stop word BTW (which is filtered by standard analyzer on some elasticsearch versions).

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 19 août 2014 à 15:40:20, vitaly ([vitaly.bulgakov@gmail.com](mailto:vitaly.bulgakov@gmail.com)) a écrit:

David, my question is what I am doing wrong.

Also when I do URI search  
http://:9200/\_search?q="state:IN"  
I am getting 0 results  
{"took":2,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":[]}}

What I could do wrong?

On Tuesday, August 19, 2014 9:20:43 AM UTC-4, David Pilato wrote:  
I don't really understand the question but I'd say that you should use Marvel / Sense.  
It has a better support for running queries.

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 19 août 2014 à 15:10:25, vitaly ([vitaly....@gmail.com](mailto:vitaly....@gmail.com)) a écrit:

## Using elasticsearch-head I do query { "query": { "term": { "NONSENSE":"NONSENSE" } } } The result shows the entire set no matter what I type in "term" { took: 2 timed\_out: false \_shards: { total: 5 successful: 5 failed: 0 } hits: { total: 10 max\_score: 1 hits: [ { \_index: logstash-2014.08.18 \_type: logs \_id: SMUgTGR9R-2SVaL1GTeX9A \_score: 1 \_source: { message: ...... @version: 1 @timestamp: 2014-08-18T16:16:48.797Z host: ......... kw: area a realty town: South Bend state: IN ip: 198.64.136.68 src: ve-whitepages-dt } } { \_index: logstash-2014.08.18 \_type: logs \_id: yWR6DC9sQ2yAqxG9FJXauw \_score: 1 \_source: { message: ...... @version: 1 @timestamp: 2014-08-18T16:16:48.797Z host: ....... kw: Doors town: Chicago state: IL ip: 98.213.210.163 src: lsxppc21611 } } { \_index: logstash-2014.08.18 \_type: logs \_id: Z\_e-DQQkSv2ON1ar1WooSQ \_score: 1 \_source: { message: ....... @version: 1 @timestamp: 2014-08-18T16:16:48.797Z host: ....... kw: home improvement town: Clarkston state: GA ip: 172.56.1.181 src: lsxppc19735 } }

## You received this message because you are subscribed to the Google Groups "elasticsearch" group. To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com). To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com). For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.53f35470.721da317.132%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.53f35470.721da317.132%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vitaly\_bulgakov](https://avatars.discourse-cdn.com/v4/letter/v/76d3ee/32.png) [@vitaly\_bulgakov](https://discuss.elastic.co/u/vitaly_bulgakov)\
**Post date:** [August 19, 2014, 2:34pm UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340/5 "2014-08-19T14:34:56Z")

</div>

David,  
my index was created using logstash with Grok filter (see below) using our  
logs as a stream in stdin.  
I showed the index in my first message. When I am trying to search on  
fields (no matter which field) it results in

{"took":2,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":}}

Please let me know what info is missing to provide you with.

Filter I use when creating the index:

filter{  
grok{  
match=\>[  
"message",

"(?:?|&)C=%{DATA:kw}&%{DATA}\sT\s%{DATA:town}\sS\s%{WORD:state}\s%{DATA}%{IP:ip}"  
]  
}  
grok{  
match=\>[  
"message",  
"(?:?|&)SRC=%{DATA:src}(?:&|$)"  
]  
}  
}  
output {  
elasticsearch {  
host =\> localhost  
}  
stdout { codec =\> rubydebug }  
}

On Tuesday, August 19, 2014 9:43:23 AM UTC-4, David Pilato wrote:

> Have a look at [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/help/)
> 
> We can probably help you if we understand what exactly you are doing.
> 
> IN could be an english stop word BTW (which is filtered by standard  
> analyzer on some elasticsearch versions).
> 
> --  
> _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr  
> [https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)
> 
> Le 19 août 2014 à 15:40:20, vitaly ([vitaly....@gmail.com](mailto:vitaly....@gmail.com) \<javascript:\>) a  
> écrit:
> 
> David, my question is what I am doing wrong.
> 
> Also when I do URI search  
> http://:9200/\_search?q="state:IN"  
> I am getting 0 results
> 
> {"took":2,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":}}
> 
> What I could do wrong?
> 
> On Tuesday, August 19, 2014 9:20:43 AM UTC-4, David Pilato wrote:
> 
> > I don't really understand the question but I'd say that you should use  
> > Marvel / Sense.  
> > It has a better support for running queries.
> > 
> > ```
> > -- 
> > 
> > ```
> > 
> > _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> > @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr  
> > [https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)
> > 
> > Le 19 août 2014 à 15:10:25, vitaly ([vitaly....@gmail.com](mailto:vitaly....@gmail.com)) a écrit:
> > 
> > Using elasticsearch-head I do query  
> > {  
> > "query": {  
> > "term": {  
> > "NONSENSE":"NONSENSE"  
> > }  
> > }  
> > }  
> > The result shows the entire set no matter what I type in "term"  
> > {
> > 
> > - took: 2
> > - timed\_out: false
> > - \_shards: {
> > - total: 5
> > - successful: 5
> > - failed: 0  
> > }
> > 
> > - hits: {
> > - total: 10
> > - max\_score: 1
> > - hits: [
> > - {
> > - \_index: logstash-2014.08.18
> > - \_type: logs
> > - \_id: SMUgTGR9R-2SVaL1GTeX9A
> > - \_score: 1
> > - \_source: {
> > - message: ......
> > - @version: 1
> > - @timestamp: 2014-08-18T16:16:48.797Z
> > - host: .........
> > - kw: area a realty
> > - town: South Bend
> > - state: IN
> > - ip: 198.64.136.68
> > - src: ve-whitepages-dt  
> > }  
> > }
> > 
> > - {
> > - \_index: logstash-2014.08.18
> > - \_type: logs
> > - \_id: yWR6DC9sQ2yAqxG9FJXauw
> > - \_score: 1
> > - \_source: {
> > - message: ......
> > - @version: 1
> > - @timestamp: 2014-08-18T16:16:48.797Z
> > - host: .......
> > - kw: Doors
> > - town: Chicago
> > - state: IL
> > - ip: 98.213.210.163
> > - src: lsxppc21611  
> > }  
> > }
> > 
> > - {
> > - \_index: logstash-2014.08.18
> > - \_type: logs
> > - \_id: Z\_e-DQQkSv2ON1ar1WooSQ
> > - \_score: 1
> > - \_source: {
> > - message: .......
> > - @version: 1
> > - @timestamp: 2014-08-18T16:16:48.797Z
> > - host: .......
> > - kw: home improvement
> > - town: Clarkston
> > - state: GA
> > - ip: 172.56.1.181
> > - src: lsxppc19735  
> > }  
> > }
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/03b35e5b-cbf3-4211-adb4-b9de5625f6c3%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/03b35e5b-cbf3-4211-adb4-b9de5625f6c3%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Aleks](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@Aleks](https://discuss.elastic.co/u/Aleks)\
**Post date:** [August 19, 2014, 3:12pm UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340/6 "2014-08-19T15:12:03Z")

</div>

Hi Vitaly,

Try making the request with lower case "in" :  
http://:9200/\_search?q="state:in"

Aleks

On Tuesday, August 19, 2014 3:40:13 PM UTC+2, vitaly wrote:

> David, my question is what I am doing wrong.
> 
> Also when I do URI search  
> http://:9200/\_search?q="state:IN"  
> I am getting 0 results
> 
> {"took":2,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":}}
> 
> What I could do wrong?
> 
> On Tuesday, August 19, 2014 9:20:43 AM UTC-4, David Pilato wrote:
> 
> > I don't really understand the question but I'd say that you should use  
> > Marvel / Sense.  
> > It has a better support for running queries.
> > 
> > --  
> > _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> > @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr  
> > [https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)
> > 
> > Le 19 août 2014 à 15:10:25, vitaly ([vitaly....@gmail.com](mailto:vitaly....@gmail.com)) a écrit:
> > 
> > Using elasticsearch-head I do query  
> > {  
> > "query": {  
> > "term": {  
> > "NONSENSE":"NONSENSE"  
> > }  
> > }  
> > }  
> > The result shows the entire set no matter what I type in "term"  
> > {
> > 
> > - took: 2
> > - timed\_out: false
> > - \_shards: {
> > - total: 5
> > - successful: 5
> > - failed: 0  
> > }
> > 
> > - hits: {
> > - total: 10
> > - max\_score: 1
> > - hits: [
> > - {
> > - \_index: logstash-2014.08.18
> > - \_type: logs
> > - \_id: SMUgTGR9R-2SVaL1GTeX9A
> > - \_score: 1
> > - \_source: {
> > - message: ......
> > - @version: 1
> > - @timestamp: 2014-08-18T16:16:48.797Z
> > - host: .........
> > - kw: area a realty
> > - town: South Bend
> > - state: IN
> > - ip: 198.64.136.68
> > - src: ve-whitepages-dt  
> > }  
> > }
> > 
> > - {
> > - \_index: logstash-2014.08.18
> > - \_type: logs
> > - \_id: yWR6DC9sQ2yAqxG9FJXauw
> > - \_score: 1
> > - \_source: {
> > - message: ......
> > - @version: 1
> > - @timestamp: 2014-08-18T16:16:48.797Z
> > - host: .......
> > - kw: Doors
> > - town: Chicago
> > - state: IL
> > - ip: 98.213.210.163
> > - src: lsxppc21611  
> > }  
> > }
> > 
> > - {
> > - \_index: logstash-2014.08.18
> > - \_type: logs
> > - \_id: Z\_e-DQQkSv2ON1ar1WooSQ
> > - \_score: 1
> > - \_source: {
> > - message: .......
> > - @version: 1
> > - @timestamp: 2014-08-18T16:16:48.797Z
> > - host: .......
> > - kw: home improvement
> > - town: Clarkston
> > - state: GA
> > - ip: 172.56.1.181
> > - src: lsxppc19735  
> > }  
> > }
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/87cc4b5e-eb5b-4c22-b680-e9090419af53%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/87cc4b5e-eb5b-4c22-b680-e9090419af53%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vitaly\_bulgakov](https://avatars.discourse-cdn.com/v4/letter/v/76d3ee/32.png) [@vitaly\_bulgakov](https://discuss.elastic.co/u/vitaly_bulgakov)\
**Post date:** [August 19, 2014, 3:16pm UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340/7 "2014-08-19T15:16:46Z")

</div>

Aleks,  
none of the queries work.

On Tuesday, August 19, 2014 11:12:03 AM UTC-4, Aleks wrote:

> Hi Vitaly,
> 
> Try making the request with lower case "in" :  
> http://:9200/\_search?q="state:in"
> 
> Aleks
> 
> On Tuesday, August 19, 2014 3:40:13 PM UTC+2, vitaly wrote:
> 
> > David, my question is what I am doing wrong.
> > 
> > Also when I do URI search  
> > http://:9200/\_search?q="state:IN"  
> > I am getting 0 results
> > 
> > {"took":2,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":}}
> > 
> > What I could do wrong?
> > 
> > On Tuesday, August 19, 2014 9:20:43 AM UTC-4, David Pilato wrote:
> > 
> > > I don't really understand the question but I'd say that you should use  
> > > Marvel / Sense.  
> > > It has a better support for running queries.
> > > 
> > > --  
> > > _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> > > @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr  
> > > [https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)
> > > 
> > > Le 19 août 2014 à 15:10:25, vitaly ([vitaly....@gmail.com](mailto:vitaly....@gmail.com)) a écrit:
> > > 
> > > Using elasticsearch-head I do query  
> > > {  
> > > "query": {  
> > > "term": {  
> > > "NONSENSE":"NONSENSE"  
> > > }  
> > > }  
> > > }  
> > > The result shows the entire set no matter what I type in "term"  
> > > {
> > > 
> > > - took: 2
> > > - timed\_out: false
> > > - \_shards: {
> > > - total: 5
> > > - successful: 5
> > > - failed: 0  
> > > }
> > > 
> > > - hits: {
> > > - total: 10
> > > - max\_score: 1
> > > - hits: [
> > > - {
> > > - \_index: logstash-2014.08.18
> > > - \_type: logs
> > > - \_id: SMUgTGR9R-2SVaL1GTeX9A
> > > - \_score: 1
> > > - \_source: {
> > > - message: ......
> > > - @version: 1
> > > - @timestamp: 2014-08-18T16:16:48.797Z
> > > - host: .........
> > > - kw: area a realty
> > > - town: South Bend
> > > - state: IN
> > > - ip: 198.64.136.68
> > > - src: ve-whitepages-dt  
> > > }  
> > > }
> > > 
> > > - {
> > > - \_index: logstash-2014.08.18
> > > - \_type: logs
> > > - \_id: yWR6DC9sQ2yAqxG9FJXauw
> > > - \_score: 1
> > > - \_source: {
> > > - message: ......
> > > - @version: 1
> > > - @timestamp: 2014-08-18T16:16:48.797Z
> > > - host: .......
> > > - kw: Doors
> > > - town: Chicago
> > > - state: IL
> > > - ip: 98.213.210.163
> > > - src: lsxppc21611  
> > > }  
> > > }
> > > 
> > > - {
> > > - \_index: logstash-2014.08.18
> > > - \_type: logs
> > > - \_id: Z\_e-DQQkSv2ON1ar1WooSQ
> > > - \_score: 1
> > > - \_source: {
> > > - message: .......
> > > - @version: 1
> > > - @timestamp: 2014-08-18T16:16:48.797Z
> > > - host: .......
> > > - kw: home improvement
> > > - town: Clarkston
> > > - state: GA
> > > - ip: 172.56.1.181
> > > - src: lsxppc19735  
> > > }  
> > > }
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit  
> > > [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5e7c7362-d9dd-44c7-95f8-f48dcdcb2161%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5e7c7362-d9dd-44c7-95f8-f48dcdcb2161%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 19, 2014, 4:01pm UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340/8 "2014-08-19T16:01:12Z")

</div>

With what you sent, I can not reproduce easily your problem: launch elasticsearch, launch a script and that is.  
So, basically, try to provide a script which can be played as explained in the help page.

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 19 août 2014 à 16:35:01, vitaly ([vitaly.bulgakov@gmail.com](mailto:vitaly.bulgakov@gmail.com)) a écrit:

David,  
my index was created using logstash with Grok filter (see below) using our logs as a stream in stdin.  
I showed the index in my first message. When I am trying to search on fields (no matter which field) it results in  
{"took":2,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":[]}}

Please let me know what info is missing to provide you with.

Filter I use when creating the index:

filter{  
grok{  
match=\>[  
"message",  
"(?:?|&)C=%{DATA:kw}&%{DATA}\sT\s%{DATA:town}\sS\s%{WORD:state}\s%{DATA}%{IP:ip}"  
]  
}  
grok{  
match=\>[  
"message",  
"(?:?|&)SRC=%{DATA:src}(?:&|$)"  
]  
}  
}  
output {  
elasticsearch {  
host =\> localhost  
}  
stdout { codec =\> rubydebug }  
}

On Tuesday, August 19, 2014 9:43:23 AM UTC-4, David Pilato wrote:  
Have a look at [http://www.elasticsearch.org/help/](http://www.elasticsearch.org/help/)

We can probably help you if we understand what exactly you are doing.

IN could be an english stop word BTW (which is filtered by standard analyzer on some elasticsearch versions).

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 19 août 2014 à 15:40:20, vitaly ([vitaly....@gmail.com](mailto:vitaly....@gmail.com)) a écrit:

David, my question is what I am doing wrong.

Also when I do URI search  
http://:9200/\_search?q="state:IN"  
I am getting 0 results  
{"took":2,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":[]}}

What I could do wrong?

On Tuesday, August 19, 2014 9:20:43 AM UTC-4, David Pilato wrote:  
I don't really understand the question but I'd say that you should use Marvel / Sense.  
It has a better support for running queries.

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr

Le 19 août 2014 à 15:10:25, vitaly ([vitaly....@gmail.com](mailto:vitaly....@gmail.com)) a écrit:

## Using elasticsearch-head I do query { "query": { "term": { "NONSENSE":"NONSENSE" } } } The result shows the entire set no matter what I type in "term" { took: 2 timed\_out: false \_shards: { total: 5 successful: 5 failed: 0 } hits: { total: 10 max\_score: 1 hits: [ { \_index: logstash-2014.08.18 \_type: logs \_id: SMUgTGR9R-2SVaL1GTeX9A \_score: 1 \_source: { message: ...... @version: 1 @timestamp: 2014-08-18T16:16:48.797Z host: ......... kw: area a realty town: South Bend state: IN ip: 198.64.136.68 src: ve-whitepages-dt } } { \_index: logstash-2014.08.18 \_type: logs \_id: yWR6DC9sQ2yAqxG9FJXauw \_score: 1 \_source: { message: ...... @version: 1 @timestamp: 2014-08-18T16:16:48.797Z host: ....... kw: Doors town: Chicago state: IL ip: 98.213.210.163 src: lsxppc21611 } } { \_index: logstash-2014.08.18 \_type: logs \_id: Z\_e-DQQkSv2ON1ar1WooSQ \_score: 1 \_source: { message: ....... @version: 1 @timestamp: 2014-08-18T16:16:48.797Z host: ....... kw: home improvement town: Clarkston state: GA ip: 172.56.1.181 src: lsxppc19735 } }

## You received this message because you are subscribed to the Google Groups "elasticsearch" group. To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com). To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ee5fa39-804b-4b48-9b76-21225daa9c35%40googlegroups.com). For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

## You received this message because you are subscribed to the Google Groups "elasticsearch" group. To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com). To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4ff89a22-7d5b-4843-a12c-eaeafc5df8ed%40googlegroups.com). For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/03b35e5b-cbf3-4211-adb4-b9de5625f6c3%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/03b35e5b-cbf3-4211-adb4-b9de5625f6c3%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/etPan.53f374c8.440badfc.132%40MacBook-Air-de-David.local](https://groups.google.com/d/msgid/elasticsearch/etPan.53f374c8.440badfc.132%40MacBook-Air-de-David.local).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:07am UTC](https://discuss.elastic.co/t/query-or-index-problem-please-help/19340/9 "2017-07-06T01:07:41Z")

</div>


