# Quotation marks search stopped working in v6.6

**URL:** <https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772>\
**Category:** Elasticsearch\
**Created:** [March 18, 2019, 12:43pm UTC](https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772 "2019-03-18T12:43:09Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bigdatapower](https://avatars.discourse-cdn.com/v4/letter/b/da6949/32.png) [@bigdatapower](https://discuss.elastic.co/u/bigdatapower)\
**Post date:** [March 18, 2019, 12:43pm UTC](https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772/1 "2019-03-18T12:43:10Z")

</div>

Hello  
I have an indexed field in my elastic:  
"HTTP\_Error\_Body" : {  
"type" : "text",  
"norms" : false,  
"index\_options" : "docs"  
}  
At version 5.5 when I searched kibana by guid enclosed in quotation marks (in order to find error messages, which contained it), I succesfully got the results, for example:

"ec22e9d2-98b2-11e0-b8c2-0017085b945f"

the value of HTTP\_Error\_Body in result:  
ec22e9d2-98b2-11e0-b8c2-0017085b945f; blah blah /\>

But in v. 6.6 such search returns nothing, although mapping and queries are the same.

Does anyone has a clue how this could be fixed?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 20, 2019, 8:22am UTC](https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772/2 "2019-03-20T08:22:48Z")

</div>

can you please probive a fully reproducible example for 6.6 and 5.6. Without the mapping, the index creation and the full query it will be nearly impossible to properly reproduce.

Thank you!

--Alex

---

<div class="post-metadata">

**Author:** ![bigdatapower](https://avatars.discourse-cdn.com/v4/letter/b/da6949/32.png) [@bigdatapower](https://discuss.elastic.co/u/bigdatapower)\
**Post date:** [April 3, 2019, 1:13pm UTC](https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772/3 "2019-04-03T13:13:03Z")

</div>

Hello, Alex. Thank you for response.

Here are scripts for issue reproduction:

> **Kibana Scripts**
>
> ```
> PUT issue_test
> {
> "mappings": {
> "iibevent": {
> "properties": {
> "HTTP_Error_Body": {
> "type": "text",
> "norms": false,
> "index_options": "docs"
> },
> "creationTime": {
> "type": "date",
> "format": "strict_date_optional_time || epoch_millis"
> }
> 
> }
> }
> }
> }
> 
> POST issue_test/iibevent
> {
> "HTTP_Error_Body":"error in transaction ec22e9d2-98b2-11e0-b8c2-0017085b945f: bad request",
> "creationTime":"2019-04-03T12:55:41.908108Z"
> }
> 
> POST issue_test/iibevent/_search
> {
> "size": 1000,
> "sort": [
> {
> "creationTime": {
> "order": "desc",
> "unmapped_type": "boolean"
> }
> }
> ],
> "query": {
> "bool": {
> "must": [
> {
> "query_string": {
> "query": "\"ec22e9d2-98b2-11e0-b8c2-0017085b945f\"",
> "analyze_wildcard": true
> }
> },
> {
> "range": {
> "creationTime": {
> "gte": 1554293216941,
> "lte": 1554296816941,
> "format": "epoch_millis"
> }
> }
> }
> ],
> "must_not": []
> }
> },
> "aggs": {
> "2": {
> "date_histogram": {
> "field": "creationTime",
> "interval": "1m",
> "time_zone": "Europe/Minsk",
> "min_doc_count": 1
> }
> }
> }
> }
> 
> ```

If I run them for both 5 and 6 version, I get differrent search result: 1 result at v.5 (as intended) and no results at v.6  
All other settings between the instances are the same/

I've also noticed that if I remove the line  
`"index_options": "docs"`  
from mapping, the search at v6 works fine, but this is not a solution, as I don't want to change indexing type. Could not find any clues in changelogs as well

* * *

Dmitry

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 3, 2019, 2:17pm UTC](https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772/4 "2019-04-03T14:17:01Z")

</div>

it seems you are trying to search the `_all` field by not specifying a field in your search. This does not work in 6.0 anymore. See [https://www.elastic.co/guide/en/elasticsearch/reference/6.6/mapping-all-field.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/mapping-all-field.html)

try using a match query and specify the field you want to search in

---

<div class="post-metadata">

**Author:** ![bigdatapower](https://avatars.discourse-cdn.com/v4/letter/b/da6949/32.png) [@bigdatapower](https://discuss.elastic.co/u/bigdatapower)\
**Post date:** [April 3, 2019, 2:36pm UTC](https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772/5 "2019-04-03T14:36:26Z")

</div>

Thanks, Alexander. But that's the way kibana searches, I took queries from there.  
Does that mean that it is no longer possible to get results I need by typing "ec22e9d2-98b2-11e0-b8c2-0017085b945f" in kibana search field?

It's also not quite clear for me why does index\_options affect the searchablity of my guid if \_all field is switch off anyway

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 4, 2019, 9:40am UTC](https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772/6 "2019-04-04T09:40:55Z")

</div>

On top of my head I **think** that kibana used the `default_field` of the query string query to specify a field or select all.

---

<div class="post-metadata">

**Author:** ![bigdatapower](https://avatars.discourse-cdn.com/v4/letter/b/da6949/32.png) [@bigdatapower](https://discuss.elastic.co/u/bigdatapower)\
**Post date:** [April 4, 2019, 12:23pm UTC](https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772/7 "2019-04-04T12:23:30Z")

</div>

Thank you, Alexander.  
As far as i understand first solution is to create a custom field "all" with default index\_options value and make a rule to copy all other indexable fields to it. It will also be required to switch default\_field to "all" for kibana.  
On the other hand, I can just switch index\_options for all fields to default value. I did not want to do that, but apparently on my data it takes ~30% less disk space.

So, the question is: What would be a right choice here?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2019, 12:38pm UTC](https://discuss.elastic.co/t/quotation-marks-search-stopped-working-in-v6-6/172772/8 "2019-05-02T12:38:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
