# Query\_string with "fields" option behaves unexpectedly

**URL:** <https://discuss.elastic.co/t/query-string-with-fields-option-behaves-unexpectedly/277529>\
**Category:** Elasticsearch\
**Created:** [July 1, 2021, 8:47am UTC](https://discuss.elastic.co/t/query-string-with-fields-option-behaves-unexpectedly/277529 "2021-07-01T08:47:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![andreas123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas123/32/78031_2.png) [@andreas123](https://discuss.elastic.co/u/andreas123)\
**Post date:** [July 1, 2021, 8:47am UTC](https://discuss.elastic.co/t/query-string-with-fields-option-behaves-unexpectedly/277529/1 "2021-07-01T08:47:08Z")

</div>

Hey,  
i would like to understand why my search query behaves that unexpectedly.  
I have an index with 3 docs:

```auto
{
        "_index" : "test_index",
        "_type" : "_doc",
        "_id" : "2",
        "_score" : 1.0,
        "_source" : {
          "domain" : "test22222.com"
        }
      },
      {
        "_index" : "test_index",
        "_type" : "_doc",
        "_id" : "3",
        "_score" : 1.0,
        "_source" : {
          "domain" : "test22222"
        }
      },
      {
        "_index" : "test_index",
        "_type" : "_doc",
        "_id" : "1",
        "_score" : 1.0,
        "_source" : {
          "domain" : "test.com"
        }
      }

```

the query i would like to use is:

```auto
GET test_index/_search
{
  "query": {
    "query_string": {
      "query": "*test22222.com*",
      "default_field": "domain"
    }
  }
}

```

but the result is 0 hits. ⁉

The following queries i have tried to understand the reason  
`"query": "*test*"` =\> doc ids 1, 2 and 3 are found ✔  
`"query": "*test22222*"` =\> doc ids 2 and 3 are found ✔  
`"query": "*test.com*"` =\> doc id 1 is found ✔  
`"query": "*test22222.com*"` =\> nothing found ⁉

As soon as i delete `"default_field": "domain"` from query\_string, `"query": "*test22222.com*"` founds doc id 2 as expected. But then the query needs \>25 times longer to retrieve the result in my real application.

Using `fields` instead of `default_field` results in exactly the save problem.

```auto
{
  "query": {
    "query_string": {
      "query": "*test22222.com*",
      "fields": ["domain"]
    }
  }
}

```

Any one an Idea how to handle that? The combination of letters, numbers and `.` seems to be a problem. As long as i have only two of them the results seem to be right.

Cluster: 7.13 (Nodes: 3 master, 9 hot, 6 warm)

Thanks  
Andreas

---

<div class="post-metadata">

**Author:** ![andreas123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreas123/32/78031_2.png) [@andreas123](https://discuss.elastic.co/u/andreas123)\
**Post date:** [July 1, 2021, 10:30am UTC](https://discuss.elastic.co/t/query-string-with-fields-option-behaves-unexpectedly/277529/2 "2021-07-01T10:30:26Z")

</div>

I guess i have found a solution. Playing around with the explain api showed me that the identified result was always found in domain.keyword.  
Refering to domain.keyword shows the correct and expected results, therefor solved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2021, 10:30am UTC](https://discuss.elastic.co/t/query-string-with-fields-option-behaves-unexpectedly/277529/3 "2021-07-29T10:30:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
