# Searching from array with OR

**URL:** <https://discuss.elastic.co/t/searching-from-array-with-or/10963>\
**Category:** Elasticsearch\
**Created:** [March 1, 2013, 4:18am UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963 "2013-03-01T04:18:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![moocow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moocow/32/2454_2.png) [@moocow](https://discuss.elastic.co/u/moocow)\
**Post date:** [March 1, 2013, 4:18am UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963/1 "2013-03-01T04:18:23Z")

</div>

hello there, im trying to make a query as simple and obviously as fast as  
possible.

i have a bunch of items indexed in ES with field sid,

i have a an array of sids -\> [1111,2222,3333] and so i want to find all  
items in ES where sid==1111 or sid==22222 or sid==3333 etc.

Previously I have only used query string, but my array of sids is pretty  
massive (500+) so dont want to use query string, what would be the best way  
to find matching items in ES?

Hope that makes sense.  
Cheers  
Lu

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![moocow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moocow/32/2454_2.png) [@moocow](https://discuss.elastic.co/u/moocow)\
**Post date:** [March 1, 2013, 4:22am UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963/2 "2013-03-01T04:22:35Z")

</div>

am looking at this

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

so would this be the right way to go?

{  
"constant\_score" : {  
"filter" : {  
"terms" : {  
"sid" : ["11111", "22222", "3333"],  
"execution" : "bool",  
"\_cache": true  
}  
}  
}  
}

On Friday, 1 March 2013 15:18:23 UTC+11, moocow wrote:

> hello there, im trying to make a query as simple and obviously as fast as  
> possible.
> 
> i have a bunch of items indexed in ES with field sid,
> 
> i have a an array of sids -\> [1111,2222,3333] and so i want to find all  
> items in ES where sid==1111 or sid==22222 or sid==3333 etc.
> 
> Previously I have only used query string, but my array of sids is pretty  
> massive (500+) so dont want to use query string, what would be the best way  
> to find matching items in ES?
> 
> Hope that makes sense.  
> Cheers  
> Lu

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![egaumer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/egaumer/32/2365_2.png) [@egaumer](https://discuss.elastic.co/u/egaumer)\
**Post date:** [March 1, 2013, 4:36am UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963/3 "2013-03-01T04:36:38Z")

</div>

Yes, this will be the fastest approach. You should probably use the default  
execution mode (bitset) and a cache key (if possible) but regardless, this  
approach will handle large arrays very easily.

-Eric

On Thursday, February 28, 2013 11:22:35 PM UTC-5, moocow wrote:

> am looking at this
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/terms-filter.html)
> 
> so would this be the right way to go?
> 
> {  
> "constant\_score" : {  
> "filter" : {  
> "terms" : {  
> "sid" : ["11111", "22222", "3333"],  
> "execution" : "bool",  
> "\_cache": true  
> }  
> }  
> }  
> }
> 
> On Friday, 1 March 2013 15:18:23 UTC+11, moocow wrote:
> 
> > hello there, im trying to make a query as simple and obviously as fast as  
> > possible.
> > 
> > i have a bunch of items indexed in ES with field sid,
> > 
> > i have a an array of sids -\> [1111,2222,3333] and so i want to find all  
> > items in ES where sid==1111 or sid==22222 or sid==3333 etc.
> > 
> > Previously I have only used query string, but my array of sids is pretty  
> > massive (500+) so dont want to use query string, what would be the best way  
> > to find matching items in ES?
> > 
> > Hope that makes sense.  
> > Cheers  
> > Lu

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![moocow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moocow/32/2454_2.png) [@moocow](https://discuss.elastic.co/u/moocow)\
**Post date:** [March 1, 2013, 4:44am UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963/4 "2013-03-01T04:44:24Z")

</div>

Thanks for replying so quickly!

I got the following query working

curl -XGET localhost:9200/users/user/\_search -d '{"query" :  
{  
"terms" : {  
"fb\_id" : ["11111", "2222"],  
"execution" : "bool",  
"\_cache\_key" : "user\_2\_friends"  
}  
}}'

for some reason when I put in the line

"\_cache": true, it gives me a parse error.

I also tried "cache":"true" but still no luck.

With the \_cache\_key set, will it default to cache=true?

Cheers  
lu

On Friday, 1 March 2013 15:18:23 UTC+11, moocow wrote:

> hello there, im trying to make a query as simple and obviously as fast as  
> possible.
> 
> i have a bunch of items indexed in ES with field sid,
> 
> i have a an array of sids -\> [1111,2222,3333] and so i want to find all  
> items in ES where sid==1111 or sid==22222 or sid==3333 etc.
> 
> Previously I have only used query string, but my array of sids is pretty  
> massive (500+) so dont want to use query string, what would be the best way  
> to find matching items in ES?
> 
> Hope that makes sense.  
> Cheers  
> Lu

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![egaumer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/egaumer/32/2365_2.png) [@egaumer](https://discuss.elastic.co/u/egaumer)\
**Post date:** [March 1, 2013, 4:58am UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963/5 "2013-03-01T04:58:53Z")

</div>

With a mode of bool, each term filter is cached so you wouldn't specify a  
key. If you use the default mode, the whole filter is cached as a single  
entity. Without the cache\_key, the key becomes the filter (so 500 terms in  
your case). When you specify a cache\_key you essentially provide a smaller  
key which saves some memory.

-Eric

On Thursday, February 28, 2013 11:44:24 PM UTC-5, moocow wrote:

> Thanks for replying so quickly!
> 
> I got the following query working
> 
> curl -XGET localhost:9200/users/user/\_search -d '{"query" :  
> {  
> "terms" : {  
> "fb\_id" : ["11111", "2222"],  
> "execution" : "bool",  
> "\_cache\_key" : "user\_2\_friends"  
> }  
> }}'
> 
> for some reason when I put in the line
> 
> "\_cache": true, it gives me a parse error.
> 
> I also tried "cache":"true" but still no luck.
> 
> With the \_cache\_key set, will it default to cache=true?
> 
> Cheers  
> lu
> 
> On Friday, 1 March 2013 15:18:23 UTC+11, moocow wrote:
> 
> > hello there, im trying to make a query as simple and obviously as fast as  
> > possible.
> > 
> > i have a bunch of items indexed in ES with field sid,
> > 
> > i have a an array of sids -\> [1111,2222,3333] and so i want to find all  
> > items in ES where sid==1111 or sid==22222 or sid==3333 etc.
> > 
> > Previously I have only used query string, but my array of sids is pretty  
> > massive (500+) so dont want to use query string, what would be the best way  
> > to find matching items in ES?
> > 
> > Hope that makes sense.  
> > Cheers  
> > Lu

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)\
**Post date:** [March 1, 2013, 12:00pm UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963/6 "2013-03-01T12:00:03Z")

</div>

> curl -XGET localhost:9200/users/user/\_search -d '{"query" :  
> {  
> "terms" : {  
> "fb\_id" : ["11111", "2222"],  
> "execution" : "bool",  
> "\_cache\_key" : "user\_2\_friends"  
> }  
> }}'
> 
> for some reason when I put in the line  
> "\_cache": true, it gives me a parse error.

You can only cache filters, not queries.

You're using the "terms" query, not the "terms" filter. It would be much  
more efficient to use the terms filter, as you pasted in your original  
email:

{  
"constant\_score" : {  
"filter" : {  
"terms" : {  
"sid" : ["11111", "22222", "3333"],  
"execution" : "bool",  
"\_cache": true  
}  
}  
}  
}

clint

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![moocow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moocow/32/2454_2.png) [@moocow](https://discuss.elastic.co/u/moocow)\
**Post date:** [March 2, 2013, 2:06am UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963/7 "2013-03-02T02:06:35Z")

</div>

but when i run this

curl -XGET localhost:9200/users/user/\_search -d '{  
"constant\_score" : {  
"filter" : {  
"terms" : {  
"fb\_id" : ["111", "22222", "3333"],  
"execution" : "bitset",  
"\_cache": true,  
"\_cache\_key":'user\_2\_friends'  
}  
}  
}  
}'

I get

{"error":"SearchPhaseExecutionException[Failed to execute phase [query],  
total failure; shardFailures .....: SearchParseException[[users][3]:  
from[-1],size[-1]: Parse Failure [Failed to parse source [{\n  
"constant\_score" : {\n "filter" : {\n "terms" :  
{\n "fb\_id" : ["111", "22222",  
"3333"],\n "execution" : "bool",  
\n "\_cache\_key":user\_2\_friends\n }\n }\

any ideas?

Cheers  
Lu

On Friday, 1 March 2013 23:00:03 UTC+11, Clinton Gormley wrote:

> > curl -XGET localhost:9200/users/user/\_search -d '{"query" :  
> > {  
> > "terms" : {  
> > "fb\_id" : ["11111", "2222"],  
> > "execution" : "bool",  
> > "\_cache\_key" : "user\_2\_friends"  
> > }  
> > }}'
> > 
> > for some reason when I put in the line  
> > "\_cache": true, it gives me a parse error.
> 
> You can only cache filters, not queries.
> 
> You're using the "terms" query, not the "terms" filter. It would be much  
> more efficient to use the terms filter, as you pasted in your original  
> email:
> 
> {  
> "constant\_score" : {  
> "filter" : {  
> "terms" : {  
> "sid" : ["11111", "22222", "3333"],  
> "execution" : "bool",  
> "\_cache": true  
> }  
> }  
> }  
> }
> 
> clint

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![moocow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moocow/32/2454_2.png) [@moocow](https://discuss.elastic.co/u/moocow)\
**Post date:** [March 2, 2013, 2:24am UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963/8 "2013-03-02T02:24:29Z")

</div>

okay i think i have it,

it was complaining about \u so I retyped the entire thing and put the query  
at the start ( didnt realise you have to always have query as root?)

curl -XGET localhost:9200/users/user/\_search?pretty=true -d '{"query":  
{"constant\_score":{ "filter": {"terms":{"fb\_id":["1111"]}} }}}'

On Saturday, 2 March 2013 13:06:35 UTC+11, moocow wrote:

> but when i run this
> 
> curl -XGET localhost:9200/users/user/\_search -d '{  
> "constant\_score" : {  
> "filter" : {  
> "terms" : {  
> "fb\_id" : ["111", "22222", "3333"],  
> "execution" : "bitset",  
> "\_cache": true,  
> "\_cache\_key":'user\_2\_friends'  
> }  
> }  
> }  
> }'
> 
> I get
> 
> {"error":"SearchPhaseExecutionException[Failed to execute phase [query],  
> total failure; shardFailures .....: SearchParseException[[users][3]:  
> from[-1],size[-1]: Parse Failure [Failed to parse source [{\n  
> "constant\_score" : {\n "filter" : {\n "terms" :  
> {\n "fb\_id" : ["111", "22222",  
> "3333"],\n "execution" : "bool",  
> \n "\_cache\_key":user\_2\_friends\n }\n }\
> 
> any ideas?
> 
> Cheers  
> Lu
> 
> On Friday, 1 March 2013 23:00:03 UTC+11, Clinton Gormley wrote:
> 
> > > curl -XGET localhost:9200/users/user/\_search -d '{"query" :  
> > > {  
> > > "terms" : {  
> > > "fb\_id" : ["11111", "2222"],  
> > > "execution" : "bool",  
> > > "\_cache\_key" : "user\_2\_friends"  
> > > }  
> > > }}'
> > > 
> > > for some reason when I put in the line  
> > > "\_cache": true, it gives me a parse error.
> > 
> > You can only cache filters, not queries.
> > 
> > You're using the "terms" query, not the "terms" filter. It would be much  
> > more efficient to use the terms filter, as you pasted in your original  
> > email:
> > 
> > {  
> > "constant\_score" : {  
> > "filter" : {  
> > "terms" : {  
> > "sid" : ["11111", "22222", "3333"],  
> > "execution" : "bool",  
> > "\_cache": true  
> > }  
> > }  
> > }  
> > }
> > 
> > clint

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:48am UTC](https://discuss.elastic.co/t/searching-from-array-with-or/10963/9 "2017-07-06T02:48:46Z")

</div>


