# Searching multiple indices, trying to filter out specific values in specific indices

**URL:** <https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128>\
**Category:** Elasticsearch\
**Created:** [December 29, 2015, 9:50pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128 "2015-12-29T21:50:41Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![cminor9](https://avatars.discourse-cdn.com/v4/letter/c/3bc359/32.png) [@cminor9](https://discuss.elastic.co/u/cminor9)\
**Post date:** [December 29, 2015, 9:50pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/1 "2015-12-29T21:50:41Z")

</div>

I need to query several indices, and filter out certain results based on values within each index.

It's forum software, so I want to search in forums, individual posts, and users for a keyword. But I need to filter for specific forums and posts the user has access to.

I am specifying the indices in the URL, like so: [http://hostname](http://hostname):port/forum,post,user/\_search

And then the query is something like:

`POST _search { "query": { "match": { "_all": { "query": "flying house lizard", "fuzziness":"1", "operator":"and" } } } }`

edit: I don't know why the preformatting isn't working for me, sorry about the jumbled query

Anyway, I want to pass in some \_id values for the forum index, and some \_id values for the post index to keep the search within those. Seems like I'd want a filter.

I read this: [https://www.elastic.co/guide/en/elasticsearch/reference/1.4/query-dsl-indices-filter.html](https://www.elastic.co/guide/en/elasticsearch/reference/1.4/query-dsl-indices-filter.html) but find it pretty unhelpful because the context isn't quite clear (which is a problem I seem to be having in general with the documentation).

I've searched the web and this forum and cannot find anything that looks like my problem. What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 29, 2015, 10:56pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/2 "2015-12-29T22:56:31Z")

</div>

Are you on 1.4?

---

<div class="post-metadata">

**Author:** ![cminor9](https://avatars.discourse-cdn.com/v4/letter/c/3bc359/32.png) [@cminor9](https://discuss.elastic.co/u/cminor9)\
**Post date:** [January 4, 2016, 10:43pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/3 "2016-01-04T22:43:27Z")

</div>

Sorry for the delay, mind has been elsewhere for the last few days.

I am using v2.1.0

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 4, 2016, 10:45pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/4 "2016-01-04T22:45:35Z")

</div>

Ok, cause you're looking at 1.4 docs there. You may want to head to [https://www.elastic.co/guide/en/elasticsearch/reference/2.1/query-dsl-indices-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.1/query-dsl-indices-query.html)

---

<div class="post-metadata">

**Author:** ![cminor9](https://avatars.discourse-cdn.com/v4/letter/c/3bc359/32.png) [@cminor9](https://discuss.elastic.co/u/cminor9)\
**Post date:** [January 4, 2016, 10:48pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/5 "2016-01-04T22:48:26Z")

</div>

Right you are, must have followed a link to that. In general I have been looking at 2.1.0 docs. Let me go back and doublecheck that I am following the current docs for this specific thing before proceeding. Thank you for pointing that out.

---

<div class="post-metadata">

**Author:** ![cminor9](https://avatars.discourse-cdn.com/v4/letter/c/3bc359/32.png) [@cminor9](https://discuss.elastic.co/u/cminor9)\
**Post date:** [January 5, 2016, 9:48pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/6 "2016-01-05T21:48:40Z")

</div>

Alright, I read the correct docs. Recall I am trying to search 3 indices, and for each one filter out certain results.

here's what I wrote:

`POST _search { "query": { "indices": { "indices": ["post"], "query": { "term": {"message":"test"} } } } }`

This returns results, of course, but it doesn't seem to be very useful. 1) , it doesn't allow me to specify different fields in each index, and 2) this doesn't really address filtering out specific things.

I want to search across 3 indices, and filter out certain docs from each index based on a field within each index. Is there not a way to do that?

I know ES query DSL doesn't directly translate to SQL, but this should help illustrate what I need:

`  
SELECT \*  
FROM table1  
WHERE table1.col1 = 'value to search for'  
and table1.col2 != 100

UNION

SELECT \*  
FROM table2  
WHERE table2.col1 = 'value to search for'  
and table2.col2 != 1

UNION

SELECT \*  
FROM table3  
WHERE table3.col1 = 'value to search for'  
and table3.col2 != 55  
`

I have been combing though the documentation for weeks now and just can't seem to piece together how to do this.

PS: the preformatted text isn't working on that SQL query. I've edited several times and don't know why it won't work. Sorry for the poor formatting.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 5, 2016, 10:01pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/7 "2016-01-05T22:01:52Z")

</div>

Do all three indices have the same mapping?

---

<div class="post-metadata">

**Author:** ![cminor9](https://avatars.discourse-cdn.com/v4/letter/c/3bc359/32.png) [@cminor9](https://discuss.elastic.co/u/cminor9)\
**Post date:** [January 5, 2016, 10:02pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/8 "2016-01-05T22:02:22Z")

</div>

no, they do not.

---

<div class="post-metadata">

**Author:** ![cminor9](https://avatars.discourse-cdn.com/v4/letter/c/3bc359/32.png) [@cminor9](https://discuss.elastic.co/u/cminor9)\
**Post date:** [January 6, 2016, 5:08pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/9 "2016-01-06T17:08:41Z")

</div>

forgive me for being dense, but does your question imply that you cannot perform this operation against indices with different mappings?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 6, 2016, 7:51pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/10 "2016-01-06T19:51:11Z")

</div>

Basically you cannot do this, any filters will apply to all indices you want to query on.

---

<div class="post-metadata">

**Author:** ![cminor9](https://avatars.discourse-cdn.com/v4/letter/c/3bc359/32.png) [@cminor9](https://discuss.elastic.co/u/cminor9)\
**Post date:** [January 6, 2016, 7:52pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/11 "2016-01-06T19:52:24Z")

</div>

That helps, now I can stop barking up the wrong tree. Thank you.

So there is no way to achieve this using a query (as opposed to filters) either?

---

<div class="post-metadata">

**Author:** ![cminor9](https://avatars.discourse-cdn.com/v4/letter/c/3bc359/32.png) [@cminor9](https://discuss.elastic.co/u/cminor9)\
**Post date:** [January 6, 2016, 7:53pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/12 "2016-01-06T19:53:17Z")

</div>

I guess I mean I don't really care about the method as much as the end product. So if there's another way, I would appreciate being pointed in the right direction.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:26pm UTC](https://discuss.elastic.co/t/searching-multiple-indices-trying-to-filter-out-specific-values-in-specific-indices/38128/13 "2017-07-05T23:26:39Z")

</div>


