# Querying Nested Structure Without Hardcoding Keys

**URL:** https://discuss.elastic.co/t/querying-nested-structure-without-hardcoding-keys/118857
**Category:** Elasticsearch
**Created:** [February 7, 2018, 2:15pm UTC](https://discuss.elastic.co/t/querying-nested-structure-without-hardcoding-keys/118857 "2018-02-07T14:15:56Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![jagt70](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jagt70/32/27469_2.png) [@jagt70](https://discuss.elastic.co/u/jagt70)
#### Post date: [February 7, 2018, 2:15pm UTC](https://discuss.elastic.co/t/querying-nested-structure-without-hardcoding-keys/118857/1 "2018-02-07T14:15:57Z")

</div>

Hi,

I am totally new to Elasticsearch 6.0 and need help in querying documents with a nested structure (below). I have kept the example below simple, but in total the payload is around 28 KB.

**My Query**  
What I am trying to ask is "Give me documents where **any** image.wl\_w = 909". It works if I know the image id (e.g. below overlay\_json.images. **600960**.wl\_w), but the image id could be anything, so hardcoding is **not** an option

```
GET cwl-2018.02.06/_search
{
    "query": {
        "bool" : {
            "must": [
            {"match" : { "overlay_json.images.600960.wl_w" : "909" }}]}
        }
}

```

**JSON Structure**

```
  "_source": {
    "overlay_id": 12223,
    "overlay_created_at": "2017-09-04 21:09:41.592475+00:00",
    "overlay_json": {
      "images": [
        {
          "600960": [
            {
              "wl_c": 11793,
              "wl_w": 2028,
              ...
            },
            {
              "wl_c": 999,
              "wl_w": 1000,
              ...
            }]
        },
        {
          "83343": [
            {
              "wl_c": 4351,
              "wl_w": 3442,
              ...
            },
            {
              "wl_c": 56642,
              "wl_w": 909,
              ...
            }]
        },
        ...
        ]}}

```

\*\* Snippet of Mapping Created by ES\*\*

```
{
  "cwl-2018.02.06": {
    "mappings": {
      "data_overlays": {
        "properties": {
          "overlay_created_at": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "overlay_id": {
            "type": "long"
          },
          "overlay_json": {
            "properties": {
              "images": {
                "properties": {
                  "154528": {
                    "properties": {
                      "wl_c": {
                        "type": "long"
                      },
                      "wl_w": {
                        "type": "long"
                      }
                    }
                  },
                  "154531": {
                    "properties": {
                      "wl_c": {
                        "type": "long"
                      },
                      "wl_w": {
                        "type": "long"
                      },
                    }
                  }
                },
              }
            }
          }
        }
      }
    }
  }
}

```

Any help is much appreciated  
Thanks  
Jag

---

<div class="post-metadata">

### Author: ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)
#### Post date: [February 7, 2018, 2:47pm UTC](https://discuss.elastic.co/t/querying-nested-structure-without-hardcoding-keys/118857/2 "2018-02-07T14:47:25Z")

</div>

Generally, the left hand side of `"foo" : "bar"` JSON documents doesn't want to be an endlessly growing list of values. The list of unique fieldnames is one area in which elasticsearch is not endlessly scalable.  
If you need huge numbers of fieldnames then you need to look at ways of shifting these values to the right hand side of the JSON e.g.  
**nested** objects:

```
{
    "my_key_val_props": [ 
         { "key" : "foo1021371", "value": "bar"},
         { "key" : "foo9090112", "value": "bar"}
   ]

```

}

Or concatenated strings:

```
{
  "keyAndValue" : "foo1021371_bar"
}  

```

There's pros and cons to these alternative models but endless new field names is generally a bad practice.

---

<div class="post-metadata">

### Author: ![jagt70](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jagt70/32/27469_2.png) [@jagt70](https://discuss.elastic.co/u/jagt70)
#### Post date: [February 7, 2018, 4:44pm UTC](https://discuss.elastic.co/t/querying-nested-structure-without-hardcoding-keys/118857/3 "2018-02-07T16:44:41Z")

</div>

Thank you for the quick reply! I have transformed the json according to your suggestion and it works!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 7, 2018, 4:44pm UTC](https://discuss.elastic.co/t/querying-nested-structure-without-hardcoding-keys/118857/4 "2018-03-07T16:44:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
