# Query string on an attachment field

**URL:** <https://discuss.elastic.co/t/query-string-on-an-attachment-field/7005>\
**Category:** Elasticsearch\
**Created:** [March 14, 2012, 5:50pm UTC](https://discuss.elastic.co/t/query-string-on-an-attachment-field/7005 "2012-03-14T17:50:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexandre\_Heimburger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexandre_heimburger/32/2941_2.png) [@Alexandre\_Heimburger](https://discuss.elastic.co/u/Alexandre_Heimburger)\
**Post date:** [March 14, 2012, 5:50pm UTC](https://discuss.elastic.co/t/query-string-on-an-attachment-field/7005/1 "2012-03-14T17:50:39Z")

</div>

Hi,

Is it possible to perform a query string on a specific attachment field :

{

```
"query_string" : {

    "fields" : ["files", "content"],

    "query" : "my text"

}

```

}

This query should search in the content AND the attachments.

But nothing is returned. If I keep the default field, it's ok.

Am I missing something in the mapping ("files":{"type":"attachment"}) ?

thx

--  
cheers,  
ahb

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 14, 2012, 9:45pm UTC](https://discuss.elastic.co/t/query-string-on-an-attachment-field/7005/2 "2012-03-14T21:45:04Z")

</div>

Based on the previous gist ( [https://gist.github.com/1075067](https://gist.github.com/1075067) [https://gist.github.com/1075067](https://gist.github.com/1075067) ), I tried to search on file field (aka the attachment field).

I searched for :

curl "${host}/\_search?pretty=true" -d '{

"fields" : ["file"],

"query" : {

```
"query_string" : {

  "query" : "amplifier"

}

```

},

"highlight" : {

```
"fields" : {

  "file" : {}

}

```

}

}'

And get the result.

{

"took" : 81,

"timed\_out" : false,

"\_shards" : {

```
"total" : 1,

"successful" : 1,

"failed" : 0

```

},

"hits" : {

```
"total" : 1,

"max_score" : 0.005872132,

"hits" : [ {

  "_index" : "test",

  "_type" : "attachment",

  "_id" : "s_C9wgsCQRKteC4i_WbjjQ",

  "_score" : 0.005872132,

  "fields" : {

    "file" : "[I REMOVED THE PDF CONTENT] "

  },

  "highlight" : {

    "file" : ["\nMono <em>Amplifier</em>\nThe ISL99201 is a fully integrate d high efficiency class-D \nmono <em>amplifier</em>. It is designed"]

  }

} ]

```

}

}

I really think that your mapping is incorrect. Don’t you see something strange in logs when you create your mapping ?

I already get the same issue but it was due to a wrong install of the attachment plugin.

HTH

David.

De : [elasticsearch@googlegroups.com](mailto:elasticsearch@googlegroups.com) [[mailto:elasticsearch@googlegroups.com](mailto:elasticsearch@googlegroups.com)] De la part de Alexandre Heimburger  
Envoyé : mercredi 14 mars 2012 18:51  
À : elasticsearch mailing list  
Objet : Query string on an attachment field

Hi,

Is it possible to perform a query string on a specific attachment field :

{

```
"query_string" : {

    "fields" : ["files", "content"],

    "query" : "my text"

}

```

}

This query should search in the content AND the attachments.

But nothing is returned. If I keep the default field, it's ok.

Am I missing something in the mapping ("files":{"type":"attachment"}) ?

thx

--  
cheers,

ahb

---

<div class="post-metadata">

**Author:** ![alheim](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@alheim](https://discuss.elastic.co/u/alheim)\
**Post date:** [March 14, 2012, 11:12pm UTC](https://discuss.elastic.co/t/query-string-on-an-attachment-field/7005/3 "2012-03-14T23:12:24Z")

</div>

You're absolutely right. There was an error with my default analyzer.

Thanks for your time and help David.

Cheers

On Wed, Mar 14, 2012 at 10:45 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> Based on the previous gist ([Test of attachments plugin · GitHub](https://gist.github.com/1075067) ), I tried to  
> search on file field (aka the attachment field).\*\*\*\*
> 
> * * *
> 
> I searched for :\*\*\*\*
> 
> curl "${host}/\_search?pretty=true" -d '{\*\*\*\*
> 
> "fields" : ["file"],\*\*\*\*
> 
> "query" : {\*\*\*\*
> 
> ```
> "query_string" : { ****
> 
> "query" : "amplifier" ****
> 
> } ****
> 
> ```
> 
> },\*\*\*\*
> 
> "highlight" : {\*\*\*\*
> 
> ```
> "fields" : { ****
> 
> "file" : {} ****
> 
> } ****
> 
> ```
> 
> }\*\*\*\*
> 
> }'\*\*\*\*
> 
> * * *
> 
> And get the result.\*\*\*\*
> 
> * * *
> 
> {\*\*\*\*
> 
> "took" : 81,\*\*\*\*
> 
> "timed\_out" : false,\*\*\*\*
> 
> "\_shards" : {\*\*\*\*
> 
> ```
> "total" : 1, ****
> 
> "successful" : 1, ****
> 
> "failed" : 0 ****
> 
> ```
> 
> },\*\*\*\*
> 
> "hits" : {\*\*\*\*
> 
> ```
> "total" : 1, ****
> 
> "max_score" : 0.005872132, ****
> 
> "hits" : [ { ****
> 
> "_index" : "test", ****
> 
> "_type" : "attachment", ****
> 
> "_id" : "s_C9wgsCQRKteC4i_WbjjQ", ****
> 
> "_score" : 0.005872132, ****
> 
> "fields" : { ****
> 
> "file" : "[I REMOVED THE PDF CONTENT] " ****
> 
> }, ****
> 
> "highlight" : { ****
> 
> "file" : [ "\nMono <em>Amplifier</em>\nThe ISL99201 is a fully
> 
> ```
> 
> integrate d high efficiency class-D  
> \nmono _amplifier_. It is designed" ]\*\*\*\*
> 
> ```
> } ****
> 
> } ] ****
> 
> ```
> 
> }\*\*\*\*
> 
> }\*\*\*\*
> 
> * * *
> 
> I really think that your mapping is incorrect. Don’t you see something  
> strange in logs when you create your mapping ?\*\*\*\*
> 
> * * *
> 
> I already get the same issue but it was due to a wrong install of the  
> attachment plugin.\*\*\*\*
> 
> * * *
> 
> HTH\*\*\*\*
> 
> David.\*\*\*\*
> 
> * * *
> 
> _De :_ [elasticsearch@googlegroups.com](mailto:elasticsearch@googlegroups.com) [mailto:  
> [elasticsearch@googlegroups.com](mailto:elasticsearch@googlegroups.com)] _De la part de_ Alexandre Heimburger  
> _Envoyé :_ mercredi 14 mars 2012 18:51  
> _À :_ elasticsearch mailing list  
> _Objet :_ Query string on an attachment field\*\*\*\*
> 
> * * *
> 
> Hi,\*\*\*\*
> 
> * * *
> 
> Is it possible to perform a query string on a specific attachment field :\*
> 
> * * *
> 
> * * *
> 
> * * *
> 
> * * *
> 
> {
> 
> * * *
> 
> * * *
> 
> ```
> "query_string" : {
> 
> ```
> 
> * * *
> 
> * * *
> 
> ```
> "fields" : ["files", "content"],
> 
> ```
> 
> * * *
> 
> * * *
> 
> ```
> "query" : "my text"
> 
> ```
> 
> * * *
> 
> * * *
> 
> ```
> }
> 
> ```
> 
> * * *
> 
> * * *
> 
> }\*\*\*\*
> 
> * * *
> 
> This query should search in the content AND the attachments.\*\*\*\*
> 
> * * *
> 
> But nothing is returned. If I keep the default field, it's ok.\*\*\*\*
> 
> * * *
> 
> Am I missing something in the mapping ("files":{"type":"attachment"}) ?\*\*\*  
> \*
> 
> * * *
> 
> thx\*\*\*\*
> 
> * * *
> 
> --  
> cheers,\*\*\*\*
> 
> ahb\*\*\*\*

## -- Alexandre Heimburger VP Engineering blueKiwi Software tel : +33687880997 email : [ahb@bluekiwi-software.com](mailto:ahb@bluekiwi-software.com) adress : 93 rue Vieille du Temple, 75003 Paris

blueKiwi is the innovation leader in Enterprise Social Software. Our  
solutions enable enterprises worldwide to engage and interact with their  
internal and external social networks in multiple business domains.  
blueKiwi has been consistently recognized by Gartner Inc. as a visionary  
provider since 2007.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:36am UTC](https://discuss.elastic.co/t/query-string-on-an-attachment-field/7005/4 "2017-07-06T03:36:04Z")

</div>


