# Should I use Simple Query or Match Query?

**URL:** <https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438>\
**Category:** Elasticsearch\
**Created:** [October 22, 2021, 12:31pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438 "2021-10-22T12:31:40Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [October 22, 2021, 12:31pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438/1 "2021-10-22T12:31:40Z")

</div>

Dear all =)

If I want to search for the following

```auto
host:"10.250.11.11" and custom4:"errors occurred"

```

then [match-query](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-match-query.html) and [simple-query-string](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-simple-query-string-query.html) both looks like possible candidates.

I will end up creating Kibana Rules, and since JSON requires use of `"` it isn't possible to use [query-string](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html).

**Question 1**  
If I attempt Match Query:

```auto
GET _search
{
  "query": {
    "match": {
      "host": {
        "query": "10.250.11.11"
      }
    },
    "match": {
      "custom4": {
        "query": "errors occurred"
      }
    }
  }
}

```

then how can I specify that the two match should be "anded" together?

**Question 2**  
If I attempt Simple Query:

```auto
GET /_search
{
  "query": {
    "simple_query_string" : {
        "query": "\"10.250.11.11\" +\"errors occurred\"",
    }
  }
}

```

How can I specify that the first string is from field `host` and the second is from field `custom4`?

Hugs,  
Sandra =)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 22, 2021, 12:57pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438/2 "2021-10-22T12:57:38Z")

</div>

You can use `bool` queries for that.

---

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [October 22, 2021, 1:12pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438/3 "2021-10-22T13:12:59Z")

</div>

That is super interesting! Thanks =)

So `must` translates to `and` I suppose. What about `or`?

What could I do for the following two?:

```auto
host:"10.250.11.11" OR custom4:"errors occurred"
                    ^^

```

```auto
host:"10.250.11.11" AND (custom4:"errors occurred" OR custom3:"timed out"

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 22, 2021, 2:32pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438/4 "2021-10-22T14:32:35Z")

</div>

Or is `should`.

---

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [October 22, 2021, 3:17pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438/5 "2021-10-22T15:17:13Z")

</div>

Excellent. Thanks.

> **[Boolean query | Elasticsearch Guide \[7.15\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html)**

talks about scores. Should I set something so I only get when there are 100% matches?

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [October 22, 2021, 3:18pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438/6 "2021-10-22T15:18:00Z")

</div>

If you have access to a Kibana instance, you could debug the searches and filters that you specify through the "Inspect" button :

Example Searches:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7a9ffcac9937467ec42a9ecc82ab32c6390a0851.png)

Example Filters:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/1/81eb149a60c3f09e17e7423bed8b388ce35217ee.png)

---

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [October 22, 2021, 4:14pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438/7 "2021-10-22T16:14:25Z")

</div>

Perfect. That is great =)

Do you know if there is a REST API where I can give KQL and get Elastic query back?

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [October 22, 2021, 4:48pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438/8 "2021-10-22T16:48:15Z")

</div>

Not that I'm aware, the only section that shows you both KQL & Query DSL is the Kibana Debiug interface.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2021, 4:49pm UTC](https://discuss.elastic.co/t/should-i-use-simple-query-or-match-query/287438/9 "2021-11-19T16:49:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
