# Query\_string filter fails on \_exists\_:fieldname query in Elasticsearch 5.5.0

**URL:** <https://discuss.elastic.co/t/query-string-filter-fails-on--exists--fieldname-query-in-elasticsearch-5-5-0/94680>\
**Category:** Elasticsearch\
**Created:** [July 26, 2017, 5:48pm UTC](https://discuss.elastic.co/t/query-string-filter-fails-on--exists--fieldname-query-in-elasticsearch-5-5-0/94680 "2017-07-26T17:48:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bwdezend](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bwdezend/32/8218_2.png) [@bwdezend](https://discuss.elastic.co/u/bwdezend)\
**Post date:** [July 26, 2017, 5:48pm UTC](https://discuss.elastic.co/t/query-string-filter-fails-on--exists--fieldname-query-in-elasticsearch-5-5-0/94680/1 "2017-07-26T17:48:44Z")

</div>

In years past (with ES 1.x and 2.x, and Kibana 3.x and 4.x), we would filter for records containing a field using the `_exists_:fieldname` query in the Kibana search bar. The format for these was something along the lines of:

```auto
{ "size": 0, "query": { "query_string":{ "query": "_exists_:req_size" } } }

```

In Elasticsearch 5.5.0 and Kibana 5.5.0, there's a button under the search bar for "Add a filter", which lets you add an exists query. It uses a different query, simplified to:

```auto
{ "size": 0, "query": { "exists": { "field": "req_size" } } }

```

They both work in Elasticsearch 5.5.0, as long as the index being queried has documents in it. If you issue the query against an empty index, you get a `NullPointerException` and a large count of "Courier Error: N of M shards failed" in Kibana.

The raw error returned is:

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "query_shard_exception",
        "reason" : "failed to create query: {\n \"query_string\" : {\n \"query\" : \"_exists_:req_size\",\n \"fields\" : [],\n \"use_dis_max\" : true,\n \"tie_breaker\" : 0.0,\n \"default_operator\" : \"or\",\n \"auto_generate_phrase_queries\" : false,\n \"max_determinized_states\" : 10000,\n \"enable_position_increments\" : true,\n \"fuzziness\" : \"AUTO\",\n \"fuzzy_prefix_length\" : 0,\n \"fuzzy_max_expansions\" : 50,\n \"phrase_slop\" : 0,\n \"escape\" : false,\n \"split_on_whitespace\" : true,\n \"boost\" : 1.0\n }\n}",
        "index_uuid" : "<index-uuid-redacted>",
        "index" : "<index-name-redacted>"
      }
    ],
    "type" : "search_phase_execution_exception",
    "reason" : "all shards failed",
    "phase" : "query",
    "grouped" : true,
    "failed_shards" : [
      {
        "shard" : 0,
        "index" : "<index-name-redacted>",
        "node" : "<node-id-redacted>",
        "reason" : {
          "type" : "query_shard_exception",
          "reason" : "failed to create query: {\n \"query_string\" : {\n \"query\" : \"_exists_:req_size\",\n \"fields\" : [],\n \"use_dis_max\" : true,\n \"tie_breaker\" : 0.0,\n \"default_operator\" : \"or\",\n \"auto_generate_phrase_queries\" : false,\n \"max_determinized_states\" : 10000,\n \"enable_position_increments\" : true,\n \"fuzziness\" : \"AUTO\",\n \"fuzzy_prefix_length\" : 0,\n \"fuzzy_max_expansions\" : 50,\n \"phrase_slop\" : 0,\n \"escape\" : false,\n \"split_on_whitespace\" : true,\n \"boost\" : 1.0\n }\n}",
          "index_uuid" : "<index-uuid-redacted>",
          "index" : "<index-name-redacted>",
          "caused_by" : {
            "type" : "null_pointer_exception",
            "reason" : null
          }
        }
      }
    ]
  },
  "status" : 400
}

```

I suspect I'm doing something wrong. Can someone help me understand? Our users have grown accustomed to typing `_exists_:foo` in the search bar, and they are noticing the Courier errors.

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [July 26, 2017, 10:34pm UTC](https://discuss.elastic.co/t/query-string-filter-fails-on--exists--fieldname-query-in-elasticsearch-5-5-0/94680/2 "2017-07-26T22:34:27Z")

</div>

Hi,

The only way I'm able to reproduce this is where the index is completely empty with no mapping. For example:

```auto
PUT xyz1

GET xyz1/_search
{
  "query": {
    "query_string": {
      "query": "_exists_:req_size"
    }
  }
}

```

Results in the same null\_pointer\_exception. However if you do:

```auto
PUT xyz2
{
  "mappings": {
    "type": {
      "properties": {
        "name": {
          "type": "text"
        }
      }
    }
  }
}

```

Then you'll get a response with an empty hits. I filed an issue here as I couldn't find an existing issue:

> <https://github.com/elastic/elasticsearch/issues/25920>

But as a workaround you may want to add a template that matches the index pattern, so that a mapping is automatically added.

---

<div class="post-metadata">

**Author:** ![bwdezend](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bwdezend/32/8218_2.png) [@bwdezend](https://discuss.elastic.co/u/bwdezend)\
**Post date:** [July 27, 2017, 2:24pm UTC](https://discuss.elastic.co/t/query-string-filter-fails-on--exists--fieldname-query-in-elasticsearch-5-5-0/94680/3 "2017-07-27T14:24:51Z")

</div>

Thanks for filing that! I wasn't sure if it was worthy of an issue or not. We're seeing this bug on indexes that are created with very large `_default_` mappings (I've trimmed out the ~700 field mappings after the `action` field, and most of the `dynamic_templates` section for brevity), but no actual mappings in place yet:

```auto
{
	"mappings": {
		"_default_": {
			"_all": {
				"enabled": true,
				"norms": false
			},
			"dynamic_templates": [{
				"string_fields": {
					"match": "*",
					"match_mapping_type": "string",
					"mapping": {
						"doc_values": true,
						"ignore_above": 1024,
						"index": "not_analyzed",
						"type": "string"
					}
				}
			}],
			"properties": {
				"@timestamp": {
					"type": "date",
					"format": "dateOptionalTime"
				},
				"@version": {
					"type": "keyword"
				},
				"actconn": {
					"type": "long"
				},
				"action": {
					"type": "keyword",
					"ignore_above": 1024
				}
			}
		}
	}
}

```

I've tested this in a VM, and I can confirm that having only set of `_default_` mappings has the same `NullPointerException`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2017, 2:25pm UTC](https://discuss.elastic.co/t/query-string-filter-fails-on--exists--fieldname-query-in-elasticsearch-5-5-0/94680/4 "2017-08-24T14:25:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
