# Search All fields in an Index

**URL:** <https://discuss.elastic.co/t/search-all-fields-in-an-index/204965>\
**Category:** Elasticsearch\
**Created:** [October 23, 2019, 9:22pm UTC](https://discuss.elastic.co/t/search-all-fields-in-an-index/204965 "2019-10-23T21:22:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![keerthn](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@keerthn](https://discuss.elastic.co/u/keerthn)\
**Post date:** [October 23, 2019, 9:22pm UTC](https://discuss.elastic.co/t/search-all-fields-in-an-index/204965/1 "2019-10-23T21:22:48Z")

</div>

Hey There !

I want to do a search where i can access all the documents within the given index to find the word i'm looking for. I see that "\_all" has been taken off which brings it down to use only the wildcard search with match\_all option or another option is to use wildcard with query\_string - is there a good way you can suggest how i can search ?

I'm developing a small project for myself in typescript.  
Here's a sample to visualize my question :  
**Index Name :**  
Cars

**The CARS index has the following columns :**  
Car Name, Car Brand, Car Type, Car make year, Car manufacture country

Sample :  
Civic EX, Honda, Sedan, 2015, USA  
Tundra, Toyota, Truck, 2012, USA  
Focus, Ford, Sedan, 2018, USA  
Mustang, Ford, Sedan, 2019, USA

Now, if i search for the word "or" i need to get any entry having "or" in any of the fields. So, in this search i should get the last 2 entries as they have the texts "or" in one of the field ("or" is available in FORD)

I have used the below but i feel it's a bad way to do it as i'm mentioning every field header here. The reason i use an asterisk (\*) is to do a "like" search and not an exact search. So, basically any text having the text "or" anywhere in the word.

**I have a feeling even the below is not correct, please help !**

```
body: {
            query: {
query_string: {
                    query : '*' + searchTxt,
                    fields : [car_name, car_brand, car_type, car_year, car_country]
                   }
         }
},
```

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [October 25, 2019, 3:56pm UTC](https://discuss.elastic.co/t/search-all-fields-in-an-index/204965/2 "2019-10-25T15:56:22Z")

</div>

There are a few things you could do here. First of all you could create your own `_all`-like field by using [`copy_to`](https://www.elastic.co/guide/en/elasticsearch/reference/current/copy-to.html). In your [mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html) you could copy the values of `car_name`, `car_brand`, etc to a new field called something like `car_combined` for example. Then, you would only have to query that `car_combined` field.

On that combined field `car_combined` you could define a custom [analyzer](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis.html) that uses [ngrams](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-ngram-tokenizer.html). Using NGrams, you will break up your strings into substrings when indexing. That will allow you to search for `or` for example, and find `Ford`, without having to use wildcards.

---

<div class="post-metadata">

**Author:** ![keerthn](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@keerthn](https://discuss.elastic.co/u/keerthn)\
**Post date:** [November 7, 2019, 9:52pm UTC](https://discuss.elastic.co/t/search-all-fields-in-an-index/204965/3 "2019-11-07T21:52:24Z")

</div>

Thank you so much @abdon !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2019, 9:54pm UTC](https://discuss.elastic.co/t/search-all-fields-in-an-index/204965/4 "2019-12-05T21:54:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
