# Searching against runtime mapped fields

**URL:** <https://discuss.elastic.co/t/searching-against-runtime-mapped-fields/361597>\
**Category:** Elasticsearch\
**Tags:** ccs-cross-cluster-search, runtime-fields\
**Created:** [June 17, 2024, 7:30pm UTC](https://discuss.elastic.co/t/searching-against-runtime-mapped-fields/361597 "2024-06-17T19:30:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Schoonover](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_schoonover/32/135347_2.png) [@John\_Schoonover](https://discuss.elastic.co/u/John_Schoonover)\
**Post date:** [June 17, 2024, 7:30pm UTC](https://discuss.elastic.co/t/searching-against-runtime-mapped-fields/361597/1 "2024-06-17T19:30:45Z")

</div>

Hey all!

Long-time user, first-time poster!

I've been trying to figure out a problem we're seeing with some unique search behavior on runtime fields when using CCS.

REF: [Runtime fields in a search request](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime-search-request.html)

When done on a cluster & searched locally on that cluster, all works well.

When done on a search head and searched via CCS, all works well but ONLY for certain query types.

MATCH/REGEX queries on the runtime field work fine. It seems, however, that when using a TERM or WILDCARD query on the runtime field, it rewrites the query to a `match_none` (as evidenced in query slowlogs).

I'm guessing this is some sort of query rewrite to make the query more performant, perhaps checking the field capabilities of the field, finding there's no explicit mapping on the remote cluster, and marking that bool of the term as `match_none: {}`.

This worked fine in v7, however, we're noticing the new behavior after an upgrade to 8.13.x .

Am I missing something? is this "feature, not bug", or is something else going on here?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Ignacio\_Vera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ignacio_vera/32/36674_2.png) [@Ignacio\_Vera](https://discuss.elastic.co/u/Ignacio_Vera)\
**Post date:** [June 19, 2024, 6:54pm UTC](https://discuss.elastic.co/t/searching-against-runtime-mapped-fields/361597/2 "2024-06-19T18:54:32Z")

</div>

Hello,

The description sounds like a legit issue, is it possible to provide a minimal reproduction of the issue?

It would help narrowing it!

Thanks!

---

<div class="post-metadata">

**Author:** ![John\_Schoonover](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_schoonover/32/135347_2.png) [@John\_Schoonover](https://discuss.elastic.co/u/John_Schoonover)\
**Post date:** [October 15, 2024, 6:11pm UTC](https://discuss.elastic.co/t/searching-against-runtime-mapped-fields/361597/3 "2024-10-15T18:11:13Z")

</div>

Sorry for the late response; life is busy 🙂

I'll try to see if I can replicate with a series of sample clusters spun up locally.
