# Searching a field where a url is stored doesn't give any results?

**URL:** https://discuss.elastic.co/t/searching-a-field-where-a-url-is-stored-doesnt-give-any-results/11130
**Category:** Elasticsearch
**Created:** [March 13, 2013, 8:42am UTC](https://discuss.elastic.co/t/searching-a-field-where-a-url-is-stored-doesnt-give-any-results/11130 "2013-03-13T08:42:08Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Vincent1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincent1/32/2436_2.png) [@Vincent1](https://discuss.elastic.co/u/Vincent1)
#### Post date: [March 13, 2013, 8:42am UTC](https://discuss.elastic.co/t/searching-a-field-where-a-url-is-stored-doesnt-give-any-results/11130/1 "2013-03-13T08:42:08Z")

</div>

Hi there,

I'm storing documents where I have a certain field that contains a string  
(sometimes it's a word and sometimes a URL).

However when I'm trying to search for on that field with either:  
query\_string or text it just won't give any results.

Here is a example of my query:  
{"query":{"bool":{"must":[{"query\_string":{"default\_field":"log.@fields.data","query":"[http://website.com/article/id/1234"}}],"must\_not":[],"should":[]}},"from":0,"size":50,"sort":[],"facets](http://website.com/article/id/1234%22%7D%7D%5D,%22must_not%22:%5B%5D,%22should%22:%5B%5D%7D%7D,%22from%22:0,%22size%22:50,%22sort%22:%5B%5D,%22facets)":{}}

When using a wildcard it only matches a query with: '_1234' and not  
'_/article/id/1234'. Is there something I'm missing with slashes?

Vincent

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 13, 2013, 8:59am UTC](https://discuss.elastic.co/t/searching-a-field-where-a-url-is-stored-doesnt-give-any-results/11130/2 "2013-03-13T08:59:03Z")

</div>

Do you use default mapping?  
If so, try this:

curl -XPUT localhost:9200/mytest  
curl -XGET localhost:9200/mytest/\_analyze?pretty -d '[http://website.com/article/id/1234](http://website.com/article/id/1234)'

Here is the output:  
{  
"tokens" : [ {  
"token" : "http",  
"start\_offset" : 0,  
"end\_offset" : 4,  
"type" : "",  
"position" : 1  
}, {  
"token" : "[website.com](http://website.com)",  
"start\_offset" : 7,  
"end\_offset" : 18,  
"type" : "",  
"position" : 2  
}, {  
"token" : "article",  
"start\_offset" : 19,  
"end\_offset" : 26,  
"type" : "",  
"position" : 3  
}, {  
"token" : "id",  
"start\_offset" : 27,  
"end\_offset" : 29,  
"type" : "",  
"position" : 4  
}, {  
"token" : "1234",  
"start\_offset" : 30,  
"end\_offset" : 34,  
"type" : "",  
"position" : 5  
} ]  
}

You can see how your field is broken into tokens.

You should use another analyzer for this field (keyword) or don't analyze at all this field.

--  
David Pilato | Technical Advocate | [Elasticsearch.com](http://Elasticsearch.com)  
@dadoonet | @elasticsearchfr | @scrutmydocs

Le 13 mars 2013 à 09:42, Vincent [vin.de.vos@gmail.com](mailto:vin.de.vos@gmail.com) a écrit :

> Hi there,
> 
> I'm storing documents where I have a certain field that contains a string (sometimes it's a word and sometimes a URL).
> 
> However when I'm trying to search for on that field with either: query\_string or text it just won't give any results.
> 
> Here is a example of my query: {"query":{"bool":{"must":[{"query\_string":{"default\_field":"log.@fields.data","query":"[http://website.com/article/id/1234"}}],"must\_not":[],"should":[]}},"from":0,"size":50,"sort":[],"facets](http://website.com/article/id/1234%22%7D%7D%5D,%22must_not%22:%5B%5D,%22should%22:%5B%5D%7D%7D,%22from%22:0,%22size%22:50,%22sort%22:%5B%5D,%22facets)":{}}
> 
> When using a wildcard it only matches a query with: '_1234' and not '_/article/id/1234'. Is there something I'm missing with slashes?
> 
> Vincent
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![Vincent1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincent1/32/2436_2.png) [@Vincent1](https://discuss.elastic.co/u/Vincent1)
#### Post date: [March 13, 2013, 11:02am UTC](https://discuss.elastic.co/t/searching-a-field-where-a-url-is-stored-doesnt-give-any-results/11130/3 "2013-03-13T11:02:45Z")

</div>

Hi David,

thank you for the information, this explains a lot!

I'm using Logstash to annotate fields from my log files. I haven't yet  
found a way to alter the default Logstash mapping but perhaps I can find  
some options to exclude certain fields for this analysis though so I can  
just store the data as it is.

Vincent

Op woensdag 13 maart 2013 09:59:03 UTC+1 schreef David Pilato het volgende:

> Do you use default mapping?  
> If so, try this:
> 
> curl -XPUT localhost:9200/mytest  
> curl -XGET localhost:9200/mytest/\_analyze?pretty -d '  
> [http://website.com/article/id/1234](http://website.com/article/id/1234)'
> 
> Here is the output:  
> {  
> "tokens" : [ {  
> "token" : "http",  
> "start\_offset" : 0,  
> "end\_offset" : 4,  
> "type" : "",  
> "position" : 1  
> }, {  
> "token" : "[website.com](http://website.com)",  
> "start\_offset" : 7,  
> "end\_offset" : 18,  
> "type" : "",  
> "position" : 2  
> }, {  
> "token" : "article",  
> "start\_offset" : 19,  
> "end\_offset" : 26,  
> "type" : "",  
> "position" : 3  
> }, {  
> "token" : "id",  
> "start\_offset" : 27,  
> "end\_offset" : 29,  
> "type" : "",  
> "position" : 4  
> }, {  
> "token" : "1234",  
> "start\_offset" : 30,  
> "end\_offset" : 34,  
> "type" : "",  
> "position" : 5  
> } ]  
> }
> 
> You can see how your field is broken into tokens.
> 
> You should use another analyzer for this field (keyword) or don't analyze  
> at all this field.
> 
> --  
> _David Pilato_ | _Technical Advocate_ | _[Elasticsearch.com](http://Elasticsearch.com)_  
> @dadoonet [https://twitter.com/dadoonet](https://twitter.com/dadoonet) | @elasticsearchfr[https://twitter.com/elasticsearchfr](https://twitter.com/elasticsearchfr)  
> | @scrutmydocs [https://twitter.com/scrutmydocs](https://twitter.com/scrutmydocs)
> 
> Le 13 mars 2013 à 09:42, Vincent \<[vin.d...@gmail.com](mailto:vin.d...@gmail.com) \<javascript:\>\> a  
> écrit :
> 
> Hi there,
> 
> I'm storing documents where I have a certain field that contains a string  
> (sometimes it's a word and sometimes a URL).
> 
> However when I'm trying to search for on that field with either:  
> query\_string or text it just won't give any results.
> 
> Here is a example of my query:  
> {"query":{"bool":{"must":[{"query\_string":{"default\_field":"log.@fields.data","query":"  
> [http://website.com/article/id/1234](http://website.com/article/id/1234)  
> "}}],"must\_not":,"should":}},"from":0,"size":50,"sort":,"facets":{}}
> 
> When using a wildcard it only matches a query with: '_1234' and not  
> '_/article/id/1234'. Is there something I'm missing with slashes?
> 
> Vincent
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 2:46am UTC](https://discuss.elastic.co/t/searching-a-field-where-a-url-is-stored-doesnt-give-any-results/11130/4 "2017-07-06T02:46:47Z")

</div>


