# Searching attachment content with ingest attachment plugin ES 5.2

**URL:** <https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617>\
**Category:** Elasticsearch\
**Created:** [February 10, 2017, 8:17am UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617 "2017-02-10T08:17:14Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Divya\_Bhardwaj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divya_bhardwaj/32/15231_2.png) [@Divya\_Bhardwaj](https://discuss.elastic.co/u/Divya_Bhardwaj)\
**Post date:** [February 10, 2017, 8:17am UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617/1 "2017-02-10T08:17:14Z")

</div>

Hi All,

I am facing a issue while searching the attachment data: I have installed the ingest attachment plugin, created the for each processor, "being the attachment as array"; the mapping goes as:

"attachment": {  
"properties": {  
"attachment\_data": {  
"type": "text",  
"store": true,  
"term\_vector": "with\_positions\_offsets"  
},  
"attachment\_id": {  
"type": "text",  
"store": true,  
"term\_vector": "with\_positions\_offsets"  
},  
}  
}

one of the record has data as:

"attachment": {

```
           "content_type": "xyz",
           "language": "it",
           "content": "xyz",
           "attachment_data":"base64 encoded"
           "attachment_id":"xxxxx"

```

}

but when I search "xyz", it gives no record, search is:

"query": {  
"bool" : {  
"must": [{ "query\_string" : {  
"fields": ["\_all"],  
"query": "xyz"  
}}],

I have tried with:

"query": {  
"bool" : {  
"must": [{ "query\_string" : {  
"fields": ["attachment.attachment\_data"],  
"query": "xyz"  
}}],

or even:  
"query": {  
"bool" : {  
"must": [{ "query\_string" : {  
"fields": ["attachment.content"],  
"query": "xyz"  
}}],

but everytime, a "0" result.

any help is appreciated.

Best,  
Divya

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 10, 2017, 11:20am UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617/2 "2017-02-10T11:20:45Z")

</div>

Please format your code using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

If you provide a full recreation script it can be easier to help.

---

<div class="post-metadata">

**Author:** ![Divya\_Bhardwaj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divya_bhardwaj/32/15231_2.png) [@Divya\_Bhardwaj](https://discuss.elastic.co/u/Divya_Bhardwaj)\
**Post date:** [February 10, 2017, 11:46am UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617/3 "2017-02-10T11:46:38Z")

</div>

\</\>"attachment": {

```
       "content_type": "xyz",
       "language": "it",
       "content": "xyz",
       "attachment_data":"base64 encoded"
       "attachment_id":"xxxxx"

```

}\</\>

but when I search "xyz", it gives no record, search is:

\</\>"query": {  
"bool" : {  
"must": [{ "query\_string" : {  
"fields": ["\_all"],  
"query": "xyz"  
}}],\</\>

I have tried with:

\</\>"query": {  
"bool" : {  
"must": [{ "query\_string" : {  
"fields": ["attachment.attachment\_data"],  
"query": "xyz"  
}}],\</\>

or even:  
\</\>"query": {  
"bool" : {  
"must": [{ "query\_string" : {  
"fields": ["attachment.content"],  
"query": "xyz"  
}}],\</\>

Appreciate your help

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 10, 2017, 8:41pm UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617/4 "2017-02-10T20:41:29Z")

</div>

Did you read my answer?

---

<div class="post-metadata">

**Author:** ![Divya\_Bhardwaj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divya_bhardwaj/32/15231_2.png) [@Divya\_Bhardwaj](https://discuss.elastic.co/u/Divya_Bhardwaj)\
**Post date:** [February 13, 2017, 9:20am UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617/5 "2017-02-13T09:20:58Z")

</div>

the mapping is:

```auto
               "attachment": {
                  "properties": {
                     "attachment_data": {
                        "type": "text",
                        "store": true,
                        "term_vector": "with_positions_offsets",
                        "fielddata": true
                     },
                     "attachment_id": {
                        "type": "text",
                        "store": true,
                        "term_vector": "with_positions_offsets"
                     },

```

Ingest attachment plugin was used, processor and pipeline has been created as:

```auto
"processors": [
         {
            "foreach": {
               "field": "attachment",
               "processor": {
                  "attachment": {
                     "target_field": "_ingest._value.attachment",
                     "field": "_ingest._value.attachment_data"
                  }
               }
            }
 

```

I am not able to search the content, though it can be seen when /\_search is used, but unable to search in match query with attachment.attachment.data field. my search is:

```auto
  "query": {
    "match": {
      "attachment.attachment.content":"word"
    }
  }

```

apologies for inconvenience in the format.

Best,  
Divya

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 13, 2017, 11:40am UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617/6 "2017-02-13T11:40:49Z")

</div>

> If you provide a full recreation script it can be easier to help.

How can I replay what you are doing without a script?

As explained in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21), provide something like:

```auto
DELETE index
PUT index/type/1
{
  "foo": "bar"
}
GET index/type/_search
{
  "query": {
    "match": {
      "foo": "bar"
    }
  }
}

```

Please try with the minimal settings/mappings/content...  
If this forum rejects your post because of the number of characters, you can post your full script on [gist.github.com](http://gist.github.com) and paste the link here.

---

<div class="post-metadata">

**Author:** ![Divya\_Bhardwaj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divya_bhardwaj/32/15231_2.png) [@Divya\_Bhardwaj](https://discuss.elastic.co/u/Divya_Bhardwaj)\
**Post date:** [February 13, 2017, 12:06pm UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617/7 "2017-02-13T12:06:54Z")

</div>

Thanks David for the consistent acknowledgement to my problem.  
But my issue comes out to be related to:

[https://www.elastic.co/guide/en/elasticsearch/plugins/master/ingest-attachment-with-arrays.html](https://www.elastic.co/guide/en/elasticsearch/plugins/master/ingest-attachment-with-arrays.html)

I am unable to search any time inside content of the attachment which is decoded.

``  
"attachments" : [  
{  
"filename" : "ipsum.txt",  
"data" : "dGhpcyBpcwpqdXN0IHNvbWUgdGV4dAo=",  
"attachment" : {  
"content\_type" : "text/plain; charset=ISO-8859-1",  
"language" : "en",  
"content" :

## "this is\njust some text",

"content\_length" : 24  
}  
}  
``

I cannot use match query to search the "just" keyword.

though filename in the same is searchable with "attachments.filename"

Please let me know if this helps in understanding the use-case.

Best,  
Divya

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 13, 2017, 2:56pm UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617/8 "2017-02-13T14:56:19Z")

</div>

Why did you open a new discussion? Can you remove it?

Can you please provide a full script I can use to reproduce locally your problem?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2017, 2:56pm UTC](https://discuss.elastic.co/t/searching-attachment-content-with-ingest-attachment-plugin-es-5-2/74617/9 "2017-03-13T14:56:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
