# Search query format

**URL:** <https://discuss.elastic.co/t/search-query-format/51385>\
**Category:** Elasticsearch\
**Created:** [May 31, 2016, 6:56am UTC](https://discuss.elastic.co/t/search-query-format/51385 "2016-05-31T06:56:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![srinathkm](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@srinathkm](https://discuss.elastic.co/u/srinathkm)\
**Post date:** [May 31, 2016, 6:56am UTC](https://discuss.elastic.co/t/search-query-format/51385/1 "2016-05-31T06:56:36Z")

</div>

Hi ,

I am trying to run search from elastic based on output from another application which dumps data in JSON format. Here is the format :

{"currentRow":100,"fields":[{"name":"dDocName"},{"name":"dDocTitle"},{"name":"dDocType"},{"name":"dSecurityGroup"},{"name":"dInDate"},{"name":"xColor"},{"name":"xPersonType"},{"name":"xRegionDefinition"},{"name":"xLibraryGUID"},{"name":"dDocLastModifiedDate"},{"name":"xIdentityNum"},{"name":"xLonTriggeyu"},{"name":"xIntField"},{"name":"dRevClassID"},{"name":"xFFTest"},{"name":"xWCWorkflowAssignment"},{"name":"dDocClass"},{"name":"xWebsiteObjectType"},{"name":"xCustomerCode"},{"name":"xInvoiceNum"},{"name":"AlternateFormat"},{"name":"dDocAuthor"},{"name":"xfruit"},{"name":"xSupplierNum"},{"name":"xEBSParam"},{"name":"xTestTree"},{"name":"xVideoRenditions"},{"name":"xStorageRule"},{"name":"xstatecitymemo"},{"name":"xPOHeaderId"},{"name":"xTREELOCATION"},{"name":"xDamConversionType"},{"name":"xInvoiceAmount"},{"name":"xDiscussionType"},{"name":"dDocFunction"},{"name":"xModifiedBy"},{"name":"xCustomerTaxPayerId"},{"name":"dOutDate"},{"name":"xIPMSYS\_BATCH\_SEQ"},{"name":"dDocLastModifier"},{"name":"dFormat"},{"name":"dRendition2"},{"name":"dRendition1"},{"name":"xCustomerName"},{"name":"xHideThread"},{"name":"xGender"},{"name":"xWCTags"},{"name":"xExtURL"},{"name":"xTestFolder1"},{"name":"xPackagedConversions"},{"name":"xClbraRoleList"},{"name":"xFFTest1"},{"name":"xInvoiceCurrency"},{"name":"dDocCreatedDate"},{"name":"xWebsites"},{"name":"xTestFiddler"},{"name":"xDontShowInListsForWebsites"},{"name":"dDocAccount"},{"name":"URL"},{"name":"xClbraUserList"},{"name":"xAvaya\_Region"},{"name":"dCreateDate"},{"name":"dID"},{"name":"xSri2"},{"name":"dExtension"},{"name":"xSri1"},{"name":"xfwm\_cat\_Mercados"},{"name":"dWebExtension"},{"name":"xcateg1"},{"name":"xChecksum"},{"name":"xPONum"},{"name":"dDocCreator"},{"name":"VaultFileSize"},{"name":"dRevLabel"},{"name":"xFirstName"},{"name":"xCMUTest"},{"name":"xDiscussionCount"},{"name":"xClbraAliasList"},{"name":"xPartitionId"},{"name":"dGif"},{"name":"xIPMSYS\_APP\_ID"},{"name":"dFullTextFormat"},{"name":"xTest1"},{"name":"xFamilyName"},{"name":"xInvoice"},{"name":"xInvoiceDate"},{"name":"dRevisionID"},{"name":"xWebsiteSection"},{"name":"xWCWorkflowApproverUserList"},{"name":"WebFileSize"},{"name":"xComments"},{"name":"xWebFlag"},{"name":"xNewtest"},{"name":"xOptionListIssue"},{"name":"xtest"},{"name":"xIPMSYS\_BATCH\_ID1"},{"name":"xIdcProfile"},{"name":"dOriginalName"},{"name":"dDocOwner"},{"name":"dPublishType"},{"name":"otsFormat"},{"name":"otsCharset"},{"name":"otsLanguage"},{"name":"SCORE"},{"name":"srfDocSnippet"}],"rows":[["WCCPS7\_024401","test1","EBSAttachment","AOK-Public","5/3/16 7:18 AM","","","IDCNULL","","5/3/16 7:19 AM","","","0","24401","","","","","","","","wccuser","","","","0","","DispByContentId","","","","","","N/A","","","","","","wccuser","Application/unknown","","","","","","","","","","","","","5/3/16 7:19 AM","","","","","/cs/groups/aok-public/documents/ebsattachment/czdf/mdi0/~edisp/wccps7\_024401","","","5/3/16 7:19 AM","24801","","","","","","","2cd4124073fed81c624af0101ba28bda16db650fee35cbc8fd629904dead1b09/SHA-256","","wccuser","377","1","","","0","","","archiv.gif","","","","","","","1","","","377","","","","","","0","EBSProfile","Untitled Document","wccuser","","","","","3",""],["WCCPS7\_024202","DLEASE\_RAW\_response","Document","AOK-Public","4/19/16 11:11 AM","","","IDCNULL","","4/19/16 11:11 AM","","","0","24202","","","","","","","","weblogic","","","","0","","DispByContentId","","","","","","N/A","","","","","","weblogic","text/plain","","","","","","","","","","","","","4/19/16 11:11 AM","","","","","/cs/groups/aok-public/documents/document/czdf/mdi0/~edisp/wccps7\_024202.txt","","","4/19/16 11:11 AM","24402","","txt","","","txt","","2e2a98a3af833032d4f2b5ec3a8c62b80edeb13ac417d472744c713e4cae27e5/SHA-256","","weblogic","594","1","","","0","","","ucm\_document.png","","txt","","","","","1","","","594","","","","","","0","","DLEASE\_RAW\_response.txt","weblogic","","","","","3",""]

Have dumped this data to a json file and uploaded it to elastic.

I am unable to create a query which would list items / data based on specific values for each of the fields.  
For eg :

In this data dump , how should I set up a query which will return all items where dDocAuthor is weblogic .

Any inputs will be very helpful .

Thanks,  
Srinath

---

<div class="post-metadata">

**Author:** ![srinathkm](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@srinathkm](https://discuss.elastic.co/u/srinathkm)\
**Post date:** [June 3, 2016, 2:10am UTC](https://discuss.elastic.co/t/search-query-format/51385/2 "2016-06-03T02:10:53Z")

</div>

Hi,

Can some one kindly provide some pointers for this query ?

Thanks,  
Srinath

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 3, 2016, 8:43am UTC](https://discuss.elastic.co/t/search-query-format/51385/3 "2016-06-03T08:43:05Z")

</div>

Elastic works with JSON that is of this form:

```
{
	"fieldName": "value1",
	"fieldName2": "value2"
}

```

Your JSON is unconventional because the field names and values are not paired with each other. You essentially have 2 arrays - one of field names and one of values and elasticsearch is not built to understand that these should be associated in any way.  
You need to provide JSON as in my example where field names are used as the left hand side of a key:value pairing.

---

<div class="post-metadata">

**Author:** ![srinathkm](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@srinathkm](https://discuss.elastic.co/u/srinathkm)\
**Post date:** [June 7, 2016, 3:38am UTC](https://discuss.elastic.co/t/search-query-format/51385/4 "2016-06-07T03:38:33Z")

</div>

Thanks Mark for the confirmation . I thought it was more so related to the format of JSON being created by the external application .

Would elastic have some form of manipulation logic where this json could be interpreted correctly ? Or any other ways that you can think of which can be applied to get this requirement working ?

-Srinath

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [June 7, 2016, 7:53am UTC](https://discuss.elastic.co/t/search-query-format/51385/5 "2016-06-07T07:53:34Z")

</div>

Some basic Python?

```
oldDoc ={
	"fields":["foo", "bar"],
	"values":[1,2]
}
newDoc={}
for idx, field in enumerate( oldDoc["fields"] ):
	newDoc[field] = oldDoc["values"][idx]
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:45pm UTC](https://discuss.elastic.co/t/search-query-format/51385/6 "2017-07-05T22:45:42Z")

</div>


