# Search for JSON array elements based on order

**URL:** <https://discuss.elastic.co/t/search-for-json-array-elements-based-on-order/129545>\
**Category:** Elasticsearch\
**Created:** [April 25, 2018, 6:19pm UTC](https://discuss.elastic.co/t/search-for-json-array-elements-based-on-order/129545 "2018-04-25T18:19:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![krishna\_chaitanya](https://avatars.discourse-cdn.com/v4/letter/k/b5a626/32.png) [@krishna\_chaitanya](https://discuss.elastic.co/u/krishna_chaitanya)\
**Post date:** [April 25, 2018, 6:19pm UTC](https://discuss.elastic.co/t/search-for-json-array-elements-based-on-order/129545/1 "2018-04-25T18:19:07Z")

</div>

Hi,

I have a usecase , where I have to search inside a JSON array based on field order.  
**Examples:**

Doc1:

```
{
"FIELD1":"VALUE1",
 ARR: [ 
         {"CUR":"ABC","NEXT":"PQR","ACTION":"CLICK"},
         {"CUR":"PQR","NEXT":"XYZ","ACTION":"SUBMIT"},
         {"CUR":"XYZ","NEXT":"LMN","ACTION":"HOVER"}
         ...
         ...
         ],
"FIELD2":"VALUE2"
}

```

Doc2:

```
{
    "FIELD1":"VALUE1",
    ARR: [ 
         {"CUR":"PQR","NEXT":"XYZ","ACTION":"HOVER"},
         {"CUR":"XYZ","NEXT":"ABC","ACTION":"RCLICK"},
         {"CUR":"ABC","NEXT":"LMN","ACTION":"SELECT"}
         ...
         ...
         ],
    "FIELD2":"VALUE2"
}

```

Inside Kibana, I want to get all documents where CUR=ABC occurs in one of the array element and is followed by ACTION=HOVER in some other array element. So, I should ideally get only `Doc1` as the resultset.

My query in Kibana  
`ARR.CUR:ABC AND ARR.ACTION:HOVER` is fetching me both documents `Doc1` and `Doc2`.

please advise how I can solve this problem

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [April 27, 2018, 9:56am UTC](https://discuss.elastic.co/t/search-for-json-array-elements-based-on-order/129545/2 "2018-04-27T09:56:31Z")

</div>

One "structured" approach is to use `nested` documents with a combination of a Boolean query to ensure cur:ABC and action:hover both appear in the object followed by some form of script logic to affirm the sequences in the array.

An alternative "unstructured" approach would be to (ab)use the phrase query capability by presenting your data in more of a string form e.g. terms that combine existing field names and values into single tokens e.g.

```
["CUR_ABC .... ACTION_HOVER "] etc

```

Then you can use regular "word1 near word2" type text queries to find matches.

---

<div class="post-metadata">

**Author:** ![krishna\_chaitanya](https://avatars.discourse-cdn.com/v4/letter/k/b5a626/32.png) [@krishna\_chaitanya](https://discuss.elastic.co/u/krishna_chaitanya)\
**Post date:** [April 27, 2018, 7:59pm UTC](https://discuss.elastic.co/t/search-for-json-array-elements-based-on-order/129545/3 "2018-04-27T19:59:58Z")

</div>

Thanks for the response.

I am currently using the 2nd solution (unstructured) inside my data.  
I am using logstash indexers to split out everything in array into text field.  
Then searching the text field (keyword) by regex queries. Its working as expected.

I want to have more overview on your 1st solution.  
If I get it correctly from this [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/nested.html):

> Internally, nested objects index each object in the array as a separate hidden document, meaning that each nested object can be queried independently of the others

So, as per my example in `Doc1`, using nested type, I should only be able to query `ARR.CUR:ABC AND ARR.ACTION:CLICK` (both inside 1st element) but not what I want to, which is `ARR.CUR:ABC AND ARR.ACTION:HOVER`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2018, 8:00pm UTC](https://discuss.elastic.co/t/search-for-json-array-elements-based-on-order/129545/4 "2018-05-25T20:00:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
