# Search for records with both 'match' or does not 'exists'?

**URL:** <https://discuss.elastic.co/t/search-for-records-with-both-match-or-does-not-exists/94159>\
**Category:** Elasticsearch\
**Created:** [July 21, 2017, 8:03pm UTC](https://discuss.elastic.co/t/search-for-records-with-both-match-or-does-not-exists/94159 "2017-07-21T20:03:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![l0gic01](https://avatars.discourse-cdn.com/v4/letter/l/ebca7d/32.png) [@l0gic01](https://discuss.elastic.co/u/l0gic01)\
**Post date:** [July 21, 2017, 8:03pm UTC](https://discuss.elastic.co/t/search-for-records-with-both-match-or-does-not-exists/94159/1 "2017-07-21T20:03:38Z")

</div>

I have a use case where I need to find records where a field is both missing or contains a specific value. Anyone have any idea how to do this? I can use the must\_not with exists to find the fields that are missing and I can use the should with match to find the records with the value I am looking for. I cannot figure out how to combine these into a single query.

In the sample below, I want to find records with a 'lastname' of 'Smith' or where the last name is missing.  
In other words, I want to return both records 1 and 3.

Sample records:  
PUT /my\_index/my\_name/1  
{  
"firstname": "John",  
"lastname": "Smith"  
}

PUT /my\_index/my\_name/2  
{  
"firstname": "Jane",  
"lastname": "Brown"  
}

PUT /my\_index/my\_name/3  
{  
"firstname": "Joe"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2017, 8:03pm UTC](https://discuss.elastic.co/t/search-for-records-with-both-match-or-does-not-exists/94159/2 "2017-08-18T20:03:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
