# Query\_string with wildcard fields sends "Can't parse boolean value"

**URL:** <https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245>\
**Category:** Elasticsearch\
**Created:** [April 26, 2021, 10:38am UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245 "2021-04-26T10:38:48Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![CLEMENT\_CAZEAUX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_cazeaux/32/78785_2.png) [@CLEMENT\_CAZEAUX](https://discuss.elastic.co/u/CLEMENT_CAZEAUX)\
**Post date:** [April 26, 2021, 10:38am UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245/1 "2021-04-26T10:38:48Z")

</div>

Hello,

Basic query such as the documentation here [Query string query | Elasticsearch Guide [7.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/query-dsl-query-string-query.html) results in error:

I've tested with version 7.9, I'll try next with the current 7.12

```auto

GET _search?error_trace=true
{
  "explain": true, 
  "version": true,
  "size": 50,
  "query": {
      "query_string": {
        "fields": ["identificationWorkSchema.*"],
        "query": "Welcome AND CLEOP"
      }
        
  }
}

```

This field contain nested fields as declared in the mapping

```auto

      "identificationWorkSchema.identifiers": {
        "type": "nested",
        "include_in_parent": true
      },
      "identificationWorkSchema.workTitle": {
        "type": "nested",
        "include_in_parent": true
      },

```

The response is:

```auto

{
  "took" : 556,
  "timed_out" : false,
  "_shards" : {
    "total" : 14,
    "successful" : 11,
    "skipped" : 0,
    "failed" : 3,
    "failures" : [
      {
        "shard" : 0,
        "index" : "tryphon-app",
        "node" : "phQNVeOPQJuM1K2HEjClYw",
        "reason" : {
          "type" : "query_shard_exception",
          "reason" : "failed to create query: Can't parse boolean value [Welcome], expected [true] or [false]",
          "index_uuid" : "KqoWux2RSCeyT2XOVvg2gQ",
          "index" : "tryphon-app",
          "caused_by" : {
            "type" : "illegal_argument_exception",
            "reason" : "Can't parse boolean value [Welcome], expected [true] or [false]"
          }
        }
      }
    ]
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  }
}

```

It looks like a bug ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 26, 2021, 2:43pm UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245/2 "2021-04-26T14:43:01Z")

</div>

Welcome Clément!

Please share the full mapping you have. That'd help to understand.  
I believe that one of the subfields that you have in `identificationWorkSchema` is a boolean.

You could also use the `lenient: true` option.

Could you provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

A full reproduction script is something anyone can copy and paste in Kibana dev console, click on the run button to reproduce your use case. It will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.

---

<div class="post-metadata">

**Author:** ![CLEMENT\_CAZEAUX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_cazeaux/32/78785_2.png) [@CLEMENT\_CAZEAUX](https://discuss.elastic.co/u/CLEMENT_CAZEAUX)\
**Post date:** [April 27, 2021, 1:01pm UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245/3 "2021-04-27T13:01:45Z")

</div>

Thank you David for your answer.  
I'm trying to make a script, it's going to take me time.

For now I've tried with version 7.12, with the same result.  
`lenient: true` work as a bypass solution!  
Indeed I have a boolean sub field in `identificationWorkSchema`.

I cannot paste all mapping because it's mainly 2000 lines of declaring other nested fields.  
But here's a more detail file:

```auto
{
  "settings": {
    "index.mapping.total_fields.limit": 50000,
    "index.mapping.nested_fields.limit": 1000,
    "index.query.default_field": 5000,
    "index.mapping.nested_objects.limit": 50000,
    "number_of_shards": 3,
    "number_of_replicas": 0,
    "analysis": {
      "analyzer": {
        "case_insensitive_analyzer": {
          "tokenizer": "whitespace",
          "filter": [
            "lowercase",
            "word_delim",
            "asciifolding"
          ]
        },
        "folding_standard": {
          "tokenizer": "whitespace",
          "filter": [
            "lowercase",
            "asciifolding"
          ]
        }
      },
      "filter": {
        "word_delim": {
          "type": "word_delimiter",
          "type_table": [
            ". => ALPHA"
          ],
          "catenate_words": true,
          "generate_word_parts": false,
          "generate_number_parts": false,
          "preserve_original": true,
          "split_on_case_change": false,
          "split_on_numerics": false,
          "stem_english_possessive": true
        }
      },
      "normalizer": {
        "case_insensitive_sorting": {
          "type": "custom",
          "char_filter": [
            "custom_char_filter"
          ],
          "filter": [
            "lowercase",
            "asciifolding"
          ]
        }
      },
      "char_filter": {
        "custom_char_filter": {
          "type": "pattern_replace",
          "pattern": "(.{0,50}).*",
          "replacement": "$1"
        }
      }
    }
  },
  "mappings": {
    "dynamic_templates": [
      {
        "text_analyze": {
          "match": "*",
          "match_mapping_type": "string",
          "mapping": {
            "type": "text",
            "analyzer": "folding_standard",
            "search_analyzer": "case_insensitive_analyzer",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              },
              "lower": {
                "type": "keyword",
                "ignore_above": 256,
                "normalizer": "case_insensitive_sorting"
              }
            }
          }
        }
      }
    ],
    "date_detection": false,
    "properties": {
      "entityType": {
        "type": "keyword"
      },
      "identificationWorkSchema.identifiers": {
        "type": "nested",
        "include_in_parent": true
      },
      "identificationWorkSchema.workTitle": {
        "type": "nested",
        "include_in_parent": true
      }
  }
}

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 27, 2021, 1:33pm UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245/4 "2021-04-27T13:33:29Z")

</div>

So if you can just reproduce with a simpler script, that'd be great.

---

<div class="post-metadata">

**Author:** ![CLEMENT\_CAZEAUX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_cazeaux/32/78785_2.png) [@CLEMENT\_CAZEAUX](https://discuss.elastic.co/u/CLEMENT_CAZEAUX)\
**Post date:** [April 27, 2021, 2:37pm UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245/5 "2021-04-27T14:37:18Z")

</div>

@dadoonet Ok, I managed to reproduce it with a simple script in kibana:

```auto
DELETE index
PUT index/_doc/1
{
  "toto": {
    "tata": "Big blue",
    "isBig": true
  }
}
GET _search?error_trace=true
{
  "version": true,
  "size": 50,
  "query": {
      "query_string": {
        "fields": ["toto.*"],
        "query": "Big"
      }
  }
}

```

Producing error:

```auto
{
  "took" : 4,
  "timed_out" : false,
  "_shards" : {
    "total" : 11,
    "successful" : 10,
    "skipped" : 0,
    "failed" : 1,
    "failures" : [
      {
        "shard" : 0,
        "index" : "index",
        "node" : "f9dy58r6ToqLOcGacxdkug",
        "reason" : {
          "type" : "query_shard_exception",
          "reason" : "failed to create query: Can't parse boolean value [Big], expected [true] or [false]",
          "index_uuid" : "JTVQu-mDSKyQob5R1Zleig",
          "index" : "index",
          "caused_by" : {
            "type" : "illegal_argument_exception",
            "reason" : "Can't parse boolean value [Big], expected [true] or [false]"
          }
        }
      }
    ]
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  }
}

```

There's no error if I try with all fields:

```auto
fields: ["*"]

```

So something in elastic code may avoid conflict with boolean for this particular case.

No error either without the `isBig` boolean in the document.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 4, 2021, 10:29am UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245/6 "2021-05-04T10:29:24Z")

</div>

Just to make sure I understand. I tried with:

```auto
DELETE index
PUT index/_doc/1
{
  "toto": {
    "tata": "Big blue",
    "isBig": true
  }
}
GET index/_search?error_trace=true
{
  "size": 50,
  "query": {
      "query_string": {
        "fields": ["toto.*"],
        "query": "Big",
        "lenient": true
      }
  }
}

```

This works well. So is there anything else that needs to be fixed?

BTW in you example you are running the search on the whole cluster, including "system" indices. I recommend running that only on indices that have the data you want to search for.

---

<div class="post-metadata">

**Author:** ![CLEMENT\_CAZEAUX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement_cazeaux/32/78785_2.png) [@CLEMENT\_CAZEAUX](https://discuss.elastic.co/u/CLEMENT_CAZEAUX)\
**Post date:** [May 4, 2021, 5:08pm UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245/7 "2021-05-04T17:08:01Z")

</div>

With "lenient": true, it works well. It's just that the documentation nor the error message gives a clear explaination of the necessity of lenient. And the behavior is not consistent between just "_" and "xxx._" in fields.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 4, 2021, 5:40pm UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245/8 "2021-05-04T17:40:41Z")

</div>

I got a much more detailed stacktrace when I searched only in the right index.

Try:

```auto
GET index/_search?error_trace=true
{
  "size": 50,
  "query": {
      "query_string": {
        "fields": ["toto.*"],
        "query": "Big"
      }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2021, 5:41pm UTC](https://discuss.elastic.co/t/query-string-with-wildcard-fields-sends-cant-parse-boolean-value/271245/9 "2021-06-01T17:41:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
