# Question about query

**URL:** <https://discuss.elastic.co/t/question-about-query/105355>\
**Category:** Elasticsearch\
**Created:** [October 26, 2017, 7:29am UTC](https://discuss.elastic.co/t/question-about-query/105355 "2017-10-26T07:29:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Javier](https://avatars.discourse-cdn.com/v4/letter/j/9dc877/32.png) [@Javier](https://discuss.elastic.co/u/Javier)\
**Post date:** [October 26, 2017, 7:29am UTC](https://discuss.elastic.co/t/question-about-query/105355/1 "2017-10-26T07:29:11Z")

</div>

Hello.

I have a problem with a query. I´m trying to add several fields and only one of them is permit.  
QUERY='{"query":{"bool":{"must":[{"range":{"@timestamp":{"gte":"now-'$RELATIVE\_START\_TIME\_TO\_SEARCH'/d","lt":"now/d"}}},{"match\_phrase\_prefix":{"level":{"query"  
:"Error"}}},{"bool":{"should":[{"match\_phrase\_prefix":{"log\_name":{"query":"System"}}},{"match\_phrase\_prefix":{"level":{"query":"Security"}}}],"must\_not":[{"match":{"message":"The default transaction resource mana  
ger"}}],"minimum\_number\_should\_match":1}}]}}}'

This is the query and mi question is: I want to add another "must\_not" to don´t receive messages with these fields but only one must\_not is permit. Could you Help me?.

Thanks.

Javier.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 27, 2017, 3:00pm UTC](https://discuss.elastic.co/t/question-about-query/105355/2 "2017-10-27T15:00:36Z")

</div>

you can specifiy only one `must_not` clause, but as this field is an array, you can specifiy several queries inside of that like this (pseudocode)

```auto
"must_not" : [
  { first_query },
  { second_query }
]

```

---

<div class="post-metadata">

**Author:** ![Javier](https://avatars.discourse-cdn.com/v4/letter/j/9dc877/32.png) [@Javier](https://discuss.elastic.co/u/Javier)\
**Post date:** [October 30, 2017, 2:09pm UTC](https://discuss.elastic.co/t/question-about-query/105355/3 "2017-10-30T14:09:19Z")

</div>

Hi.  
My problema is that with a must\_not is working, but I add another more with a correct text it´s not running, ie:QUERY='{"query":{"bool":{"must":[{"range":{"@timestamp":{"gte":"now-'$RELATIVE\_START\_TIME\_TO\_SEARCH'/d","lt":"now/d"}}}, {"match\_phrase\_prefix":{"level":{"query":"Error"}}}, {"bool":{"should":[{"match\_phrase\_prefix":{"log\_name":{"query":"System"}}},{"match\_phrase\_prefix":{"level":{"query":"Security"}}}],"must\_not":[{"bool":{"should":[{"match":{"message":"Microsoft Antimalware has encountered"}},{"match":{"message":"Installation Failure"}}]}}],"minimum\_number\_should\_match":1}}]}}}'  
In addition.  
Some idea?

---

<div class="post-metadata">

**Author:** ![Javier](https://avatars.discourse-cdn.com/v4/letter/j/9dc877/32.png) [@Javier](https://discuss.elastic.co/u/Javier)\
**Post date:** [October 31, 2017, 11:43am UTC](https://discuss.elastic.co/t/question-about-query/105355/4 "2017-10-31T11:43:48Z")

</div>

I have these messages: "message":TEXT-A: " The default transaction resource manager on volume encountered anon-retryable error and could not start""message":TEXT-B: " Microsoft Antimalware has encountered an error trying to updatesignatures""message":TEXT-C: " Microsoft Antimalware has encountered an error trying to updatesignatures.\n \tNew Signature Version: \n \tPrevious Signature Version:1.253.923.0\n \tUpdate Source: Microsoft Update Server\n \tUpdate Stage" Run thequery:QUERY='{"query":{"bool":{"must":[{"range":{"@timestamp":{"gte":"now-'$RELATIVE\_START\_TIME\_TO\_SEARCH'/d","lt":"now/d"}}},{"match\_phrase\_prefix":{"level":{"query":"Error"}}},{"bool":{"should":[{"match\_phrase\_prefix":{"log\_name":{"query":"System"}}},{"match\_phrase\_prefix":{"level":{"query":"Security"}}}],"must\_not":[{"match":{"message":"TEXTA"}}],"minimum\_number\_should\_match":1}}]}}}' Results of query:"message":"TEXT B""message":"TEXTC" Run the query QUERY='{"query":{"bool":{"must":[{"range":{"@timestamp":{"gte":"now-'$RELATIVE\_START\_TIME\_TO\_SEARCH'/d","lt":"now/d"}}},{"match\_phrase\_prefix":{"level":{"query":"Error"}}},{"bool":{"should":[{"match\_phrase\_prefix":{"log\_name":{"query":"System"}}},{"match\_phrase\_prefix":{"level":{"query":"Security"}}}],"must\_not":[{"match":{"message":"TEXTA"}},{"match":{"message":"TEXT B"}}],"minimum\_number\_should\_match":1}}]}}}' Results of the query:No entries. What I haveto do to filter "TEXT A" and "TEXT B" and only get "TEXT C"?

---

<div class="post-metadata">

**Author:** ![Javier](https://avatars.discourse-cdn.com/v4/letter/j/9dc877/32.png) [@Javier](https://discuss.elastic.co/u/Javier)\
**Post date:** [October 31, 2017, 11:46am UTC](https://discuss.elastic.co/t/question-about-query/105355/5 "2017-10-31T11:46:41Z")

</div>

I have these messages:

"message": TEXT-A: " The default transaction resource manager on volume encountered a non-retryable error and could not start"  
"message": TEXT-B: " Microsoft Antimalware has encountered an error trying to update signatures"  
"message": TEXT-C: " Microsoft Antimalware has encountered an error trying to update signatures.\n \tNew Signature Version: \n \tPrevious Signature Version: 1.253.923.0\n \tUpdate Source: Microsoft Update Server\n \tUpdate Stage"

Run the query:  
QUERY='{"query":{"bool":{"must":[{"range":{"@timestamp":{"gte":"now-'$RELATIVE\_START\_TIME\_TO\_SEARCH'/d","lt":"now/d"}}},{"match\_phrase\_prefix":{"level":{"query":"Error"}}},{"bool":{"should":[{"match\_phrase\_prefix":{"log\_name":{"query":"System"}}},{"match\_phrase\_prefix":{"level":{"query":"Security"}}}],"must\_not":[{"match":{"message":"TEXT A"}}],"minimum\_number\_should\_match":1}}]}}}'

Results of query:  
"message":"TEXT B"  
"message":"TEXT C"

Run the query  
QUERY='{"query":{"bool":{"must":[{"range":{"@timestamp":{"gte":"now-'$RELATIVE\_START\_TIME\_TO\_SEARCH'/d","lt":"now/d"}}},{"match\_phrase\_prefix":{"level":{"query":"Error"}}},{"bool":{"should":[{"match\_phrase\_prefix":{"log\_name":{"query":"System"}}},{"match\_phrase\_prefix":{"level":{"query":"Security"}}}],"must\_not":[{"match":{"message":"TEXT A"}},{"match":{"message":"TEXT B"}}],"minimum\_number\_should\_match":1}}]}}}'

Results of the query:  
No entries.

What I have to do to filter "TEXT A" and "TEXT B" and only get "TEXT C"?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2017, 11:47am UTC](https://discuss.elastic.co/t/question-about-query/105355/6 "2017-11-28T11:47:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
