# Query with multiple AND and OR clauses in a filter context?

**URL:** <https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678>\
**Category:** Elasticsearch\
**Created:** [October 8, 2019, 1:12pm UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678 "2019-10-08T13:12:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jyridevelopingsw](https://avatars.discourse-cdn.com/v4/letter/j/71e660/32.png) [@jyridevelopingsw](https://discuss.elastic.co/u/jyridevelopingsw)\
**Post date:** [October 8, 2019, 1:12pm UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678/1 "2019-10-08T13:12:13Z")

</div>

Is it possible to perform a complex query in just filter context? In my case scoring does not matter at all. The documentation states that in a bool query `filter` and `must_not` are performed in a filter context.

So can I wrap a query in `filter` parameter and have it include `bool` elements that have a `should` property? Seems to work, but is this a recommended way?

A simplified case would be: `All users that are over the age of 20 AND have glasses AND (are software developers OR data analysts) AND (have a degree in analytics OR engineering)`

Here is an example query (completely unrelated to the sentence ^):

```auto
GET index/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "terms": {
            "someField": [
              "0",
              "1"
            ]
          }
        },
        {
          "terms": {
            "someField2": [
              "3",
              "4",
              "0"
            ]
          }
        },
        {
          "match_phrase_prefix": {
            "someField3": "Mich"
          }
        },
        {
          "bool": {
            "should": [
              {
                "prefix": {
                  "someField4": "Test"
                }
              },
              {
                "prefix": {
                  "someField5": "Test"
                }
              }
            ]
          }
        },
        {
          "range": {
            "CreationTime": {
              "gte": "2019-08-08",
              "lte": "2019-10-08"
            }
          }
        }
      ]
    }
  }
}

```

Before I used a bool query with a `must` parameter.

Thanks in advance for any help.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 9, 2019, 7:04am UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678/2 "2019-10-09T07:04:14Z")

</div>

Hey,

that is possible in general. Just be aware of how the behaviour of the bool query changes, when you have a `must` clause, as then a `should` clause becomes optional and thus is not needed to decide if a document should be filtered or not. In your example it looks, as if you simply use the `should` clause as an OR combination between two queries, which makes sense to me.

hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![jyridevelopingsw](https://avatars.discourse-cdn.com/v4/letter/j/71e660/32.png) [@jyridevelopingsw](https://discuss.elastic.co/u/jyridevelopingsw)\
**Post date:** [October 22, 2019, 7:27am UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678/3 "2019-10-22T07:27:25Z")

</div>

Thanks, is this the most efficient way to do this? I am having some performance issues when performing parallel requests to an index

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 22, 2019, 8:02am UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678/4 "2019-10-22T08:02:47Z")

</div>

Try using the [profile API](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/search-profile.html) to find out what is causing the performance issues. You may want to try with kibana as a start to have a nice UI around this, see [https://www.elastic.co/guide/en/kibana/7.4/xpack-profiler.html](https://www.elastic.co/guide/en/kibana/7.4/xpack-profiler.html)

---

<div class="post-metadata">

**Author:** ![jyridevelopingsw](https://avatars.discourse-cdn.com/v4/letter/j/71e660/32.png) [@jyridevelopingsw](https://discuss.elastic.co/u/jyridevelopingsw)\
**Post date:** [October 22, 2019, 12:02pm UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678/5 "2019-10-22T12:02:20Z")

</div>

Thanks for the quick reply, nothing seems out of the ordinary when I run the queries from Kibana or navigate through the application manually, all queries are very fast in these cases. Slowness only happens when ~10 users run searches in parallel.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 23, 2019, 1:25pm UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678/6 "2019-10-23T13:25:30Z")

</div>

are you hitting a lot of shards with each query, so that the thread pools and queues become saturated quickly?

---

<div class="post-metadata">

**Author:** ![jyridevelopingsw](https://avatars.discourse-cdn.com/v4/letter/j/71e660/32.png) [@jyridevelopingsw](https://discuss.elastic.co/u/jyridevelopingsw)\
**Post date:** [October 28, 2019, 10:12am UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678/7 "2019-10-28T10:12:07Z")

</div>

> [@spinscale](#):
>
> are you hitting a lot of shards with each query, so that the thread pools and queues become saturated quickly?

How can I investigate that? I've tested with 5 shards and 1 shard, that does not seem to matter as it's slow with both configurations.

Thanks for the help again 😄

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 31, 2019, 12:28pm UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678/8 "2019-10-31T12:28:37Z")

</div>

The node stats API shows information about searches being rejected or delayed because they are queued, that might be a first target for checking. See [https://www.elastic.co/guide/en/elasticsearch/reference/7.4/cluster-nodes-stats.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/cluster-nodes-stats.html)

Also, are there any messages in the elasticsearch log file, that may help here?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2019, 12:31pm UTC](https://discuss.elastic.co/t/query-with-multiple-and-and-or-clauses-in-a-filter-context/202678/9 "2019-11-28T12:31:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
