# Should in filtered query

**URL:** <https://discuss.elastic.co/t/should-in-filtered-query/70918>\
**Category:** Elasticsearch\
**Created:** [January 9, 2017, 6:31am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918 "2017-01-09T06:31:52Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [January 9, 2017, 6:31am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/1 "2017-01-09T06:31:52Z")

</div>

A mentioned in the docs I replaced by

```auto
GET smsc_logs-2017.01.09/_search
{
  "query": {
    "bool": {
      "should": [
        {
          "wildcard": {
            "path": "/home/GEMS/ES/CDR/Delivery/SMSCDR_DEL_ATTEMPT_16051810*.log"
          }
        }
      ],
      "filter": {
        "bool": {
          "must": [
            {
              "term": {
                "RecordType": "DelAck"
              }
            }
          ]
        }
      }
    }
  }
}

```

my previous version query is

```auto
GET _search
{
  "query": {
    "filtered": {
      "query": {
        "should": [{
          "path": "/home/GEMS/ES/CDR/Delivery/SMSCDR_DEL_ATTEMPT_16051810*.log"
        }]
      },
      "filter": {
        "bool": {
          "must": [
            {
              "term": {
                "RecordType": "DelAck"
              }
            }
          ]
        }
      }
    }
  }
}

```

I replaced my filtered query with bool. Its working with must but not working with should in the bool (filtered) query. Is it a bug or am I understanding wrongly??/

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 9, 2017, 7:16am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/2 "2017-01-09T07:16:22Z")

</div>

I doubt the old query ever worked as you'd expect.

This is not a query AFAIK:

```auto
{
  "path": "/home/GEMS/ES/CDR/Delivery/SMSCDR_DEL_ATTEMPT_16051810*.log"
}

```

That said I'd write the query like this (simplify the bool part which is not needed actually).

```auto
GET smsc_logs-2017.01.09/_search
{
  "query": {
    "bool": {
      "should": [
        {
          "wildcard": {
            "path": "/home/GEMS/ES/CDR/Delivery/SMSCDR_DEL_ATTEMPT_16051810*.log"
          }
        }
      ],
      "filter": {
         "term": {
            "RecordType": "DelAck"
         }
      }
    }
  }
}

```

But here I think your problem is more on the wildcard part. What is your mapping for field `path`?

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [January 9, 2017, 8:42am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/3 "2017-01-09T08:42:15Z")

</div>

My `path` mapping is a `keyword` (non-analysed string).

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/076fbd7e8b3167710527998b7ee33e5525b3b7fa.JPG)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 9, 2017, 8:44am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/4 "2017-01-09T08:44:40Z")

</div>

Can you reproduce it with a simple script?

Note that in initial version you were searching in all indices and now you are only searching in `smsc_logs-2017.01.09`.

A full simple recreation script would be helpful to have a better understanding of what you are doing exactly.

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [January 9, 2017, 9:09am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/5 "2017-01-09T09:09:10Z")

</div>

Its a test setup and we have only one indices. Its same to search in all indices or in `smsc_logs-2017.01.09`.

```
[root@localhost Delivery]# cut -d "|" -f 10 SMSCDR_DEL_ATTEMPT_16051810*.log | grep "DelAck" | wc -l
15857
[root@localhost Delivery]# cut -d "|" -f 10 SMSCDR_DEL_ATTEMPT_* | grep "DelAck" | wc -l
349366

```

When I uses must in the bool (filtered) its returning the correct result. But when I uses should its not considering the path condition and returing all `DelAck` as mentioned below.

I am thinking both should have the same result. Is it right or wrong???

```
GET smsc_logs-2017.01.09/_search
{
  "query": {
    "bool": {
      "should": [
        {
          "wildcard": {
            "path": "/home/GEMS/ES/CDR/Delivery/SMSCDR_DEL_ATTEMPT_16051810*.log"
          }
        }
      ],
      "filter": {
         "term": {
            "RecordType": "DelAck"
         }
      }
    }
  }
}

```

Gives:

```
{
  "took": 16,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "failed": 0
  },
  "hits": {
    "total": 349366,
    "max_score": 1,
    "hits": [
      {

```

But

```
GET smsc_logs-2017.01.09/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "wildcard": {
            "path": "/home/GEMS/ES/CDR/Delivery/SMSCDR_DEL_ATTEMPT_16051810*.log"
          }
        }
      ],
      "filter": {
         "term": {
            "RecordType": "DelAck"
         }
      }
    }
  }
}

```

Gives

```
{
  "took": 12,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "failed": 0
  },
  "hits": {
    "total": 15857,
    "max_score": 1,
    "hits": [
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 9, 2017, 9:32am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/6 "2017-01-09T09:32:21Z")

</div>

Please format your code using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will make your post more readable.

I'm editing your post.

I think it's correct because `should` is not mandatory here as you have another condition which is the `filter` part.

So if `should` clause match, you will have a better score than without.

I'd put both in filter in that case. Like:

```auto
GET smsc_logs-2017.01.09/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "wildcard": {
            "path": "/home/GEMS/ES/CDR/Delivery/SMSCDR_DEL_ATTEMPT_16051810*.log"
          }
        },{
          "term": {
            "RecordType": "DelAck"
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [January 9, 2017, 9:44am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/7 "2017-01-09T09:44:36Z")

</div>

Sorry about the quotes. By my before readings I understand that the `filtered and filter` have the better performance than the simple bool query. If I change my query as you mentioned how the heap and performance will effect???

If I have multiple `path` variables I need to do `should` (or) operation on that. Then how the query will change in that scenario???

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 9, 2017, 7:30pm UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/8 "2017-01-09T19:30:55Z")

</div>

May be a [https://www.elastic.co/guide/en/elasticsearch/reference/5.1/query-dsl-constant-score-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.1/query-dsl-constant-score-query.html) would help to wrap your query.

So I'd write something like (pseudo code not tested):

```auto
GET smsc_logs-2017.01.09/_search
{
  "query": {
    "bool": {
      "should": [
        {
          "constant_score": {
            "wildcard": {
              "path": "/home/GEMS/ES/CDR/Delivery/PATH1*.log"
            }
          }
        },{
          "constant_score": {
            "wildcard": {
              "path": "/home/GEMS/ES/CDR/Delivery/PATH2*.log"
            }
          }
        }
      ],
      "filter": [
        {
          "term": {
            "RecordType": "DelAck"
          }
        }
      ]
    }
  }
}

```

May be that would work.

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [January 10, 2017, 5:09am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/9 "2017-01-10T05:09:26Z")

</div>

Its showing an error of

```
{
  "error": {
    "root_cause": [
      {
        "type": "parsing_exception",
        "reason": "[constant_score] query does not support [wildcard]",
        "line": 7,
        "col": 35
      }
    ],
    "type": "parsing_exception",
    "reason": "[constant_score] query does not support [wildcard]",
    "line": 7,
    "col": 35
  },
  "status": 400
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2017, 5:09am UTC](https://discuss.elastic.co/t/should-in-filtered-query/70918/10 "2017-02-07T05:09:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
