# Query with more than one field

**URL:** <https://discuss.elastic.co/t/query-with-more-than-one-field/241509>\
**Category:** Elasticsearch\
**Created:** [July 16, 2020, 4:37pm UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509 "2020-07-16T16:37:05Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![schneider](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@schneider](https://discuss.elastic.co/u/schneider)\
**Post date:** [July 16, 2020, 4:37pm UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509/1 "2020-07-16T16:37:05Z")

</div>

Hello, i want the data witch : field "transacao" = " QuarantineTransac" and the field  
"assunto" = "qualquerassunto", but is retrieving data witch one OR another no the 2 at the same time

> ```
> {
> "query": {
> "bool": {
> "must": [
> {"match": {"transacao": " QuarantineTransac"}},
> {"match": {"assunto": "qualquerassunto"}}
> ],
> "filter": [
> {"range": {"data1": {"from": "now-1h", "to": "now"}}}       
> ]
> }
> }
> }
> 
> ```

Thx.

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [July 16, 2020, 7:03pm UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509/2 "2020-07-16T19:03:42Z")

</div>

Can you post mappings for the two fields?

---

<div class="post-metadata">

**Author:** ![schneider](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@schneider](https://discuss.elastic.co/u/schneider)\
**Post date:** [July 17, 2020, 4:24pm UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509/3 "2020-07-17T16:24:14Z")

</div>

Is this:

```
filter
{
	if "imsva" in [tags]
	{
		csv 
		{
			source => "message"
            columns => 
			[ 
				"transacao","data1","data2","data3","campo5","id","id2","campo8","remetente",
				"destinatario","assunto","host_origen","host_destino","resposta_server",
				"status","campo16","campo17","campo18","data4","data5","campo21","campo22","anexo"
            ]
			separator => "teste"
        }
		date
		{
			match => ["data1", "yyyy MMM dd HH:mm:ss ZZ"]
			target =>"data1"
		}
		mutate 
		{
			remove_field => ["message"]
		}
    }
}
```

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [July 17, 2020, 6:44pm UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509/4 "2020-07-17T18:44:02Z")

</div>

@schneider  
I meant how these are defined in the index. Text vs. keyword. Analyzer etc.

GET \<index\_name\>/\_mappings?pretty

---

<div class="post-metadata">

**Author:** ![schneider](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@schneider](https://discuss.elastic.co/u/schneider)\
**Post date:** [July 17, 2020, 6:52pm UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509/5 "2020-07-17T18:52:12Z")

</div>

Thank you, this is the response:

> {  
> "imsva\_message" : {  
> "mappings" : {  
> "doc" : {  
> "properties" : {  
> "@timestamp" : {  
> "type" : "date"  
> },  
> "@version" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },"transacao" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "assunto" : {  
> "type" : "text",  
> "fields" : {  
> "keyword" : {  
> "type" : "keyword",  
> "ignore\_above" : 256  
> }  
> }  
> },  
> "data1" : {  
> "type" : "date"  
> }  
> }  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![schneider](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@schneider](https://discuss.elastic.co/u/schneider)\
**Post date:** [July 22, 2020, 3:49pm UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509/6 "2020-07-22T15:49:41Z")

</div>

i font this:

> {"size":0,  
> "aggs":{  
> "aggdata":{  
> "filter":{  
> "bool": {  
> "filter":[  
> {"range":{"data1":{"from": \_from, "to": "now"}}},  
> {"match\_phrase": {"assunto": {"query": assunto}}}  
> ]  
> }  
> },  
> "aggs":{  
> "aggassunto":{  
> "terms":{  
> "field":"transacao.keyword",  
> "min\_doc\_count":min\_doc\_count,  
> "size":size  
> }  
> }  
> }  
> }  
> }  
> }  
> and is working for me. thx for the help @Vinayak_Sapre

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [July 23, 2020, 3:30am UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509/7 "2020-07-23T03:30:44Z")

</div>

@schneider  
Your two queries are completely different. The original non-working query will return documents matching 3 criteria and second matches 2 criteria and get top transacao. Rough equivalent SQLs are

```auto
SELECT * 
FROM <INDEX> 
WHERE transacao = " QuarantineTransac" and assunto = "qualquerassunto" and data1 between (now-1h, now)

```

```auto
SELECT transacao, count as cnt
FROM <INDEX> 
WHERE assunto = "qualquerassunto" and data1 BETWEEN (now-1h, now) 
GROUP BY transacao 
ORDER BY cnt DESC

```

Can you post example documents that match but not expected to match and documents that do not match but expected to match?

Only transacao, assunto and data1 values are important. You can omit other attributes if you prefer.

---

<div class="post-metadata">

**Author:** ![schneider](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@schneider](https://discuss.elastic.co/u/schneider)\
**Post date:** [July 23, 2020, 12:50pm UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509/8 "2020-07-23T12:50:34Z")

</div>

I am using 2 searches:

1)=

> {"size":0,  
> "aggs":{  
> "aggdata":{  
> "filter":{  
> "bool": {  
> "filter":[  
> {"range":{"data1":{"from":\_from,"to":"now"}}},  
> {"term": {"message\_direction": "incoming"}}  
> ]  
> }  
> },  
> "aggs":{  
> "aggassunto":{  
> "terms":{  
> "field":"assunto.keyword",  
> "min\_doc\_count":min\_doc\_count,  
> "size":size  
> }  
> }  
> }  
> }  
> }  
> }

This search return the "assunto" witch more score, after this, i search again witch each of the those "assunto" using this:

1. 

> {"size":0,  
> "aggs":{  
> "aggdata":{  
> "filter":{  
> "bool": {  
> "filter":[  
> {"range":{"data1":{"from": \_from, "to": "now"}}},  
> {"match\_phrase":  
> {"assunto":  
> {"query": assunto}}}  
> ]  
> }  
> },  
> "aggs":{  
> "aggassunto":{  
> "terms":{  
> "field":"transacao.keyword",  
> "min\_doc\_count":min\_doc\_count,  
> "size":size  
> }  
> }  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2020, 12:50pm UTC](https://discuss.elastic.co/t/query-with-more-than-one-field/241509/9 "2020-08-20T12:50:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
