# "Should" is not working in DSL

**URL:** <https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063>\
**Category:** Elasticsearch\
**Created:** [August 11, 2021, 12:43pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063 "2021-08-11T12:43:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![tarekilani](https://avatars.discourse-cdn.com/v4/letter/t/54ee81/32.png) [@tarekilani](https://discuss.elastic.co/u/tarekilani)\
**Post date:** [August 11, 2021, 12:43pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063/1 "2021-08-11T12:43:38Z")

</div>

Hello,

I'm querying elasticsearch using DSL in "dev tools".  
I have the following code :

```auto
"query": {
    "bool" : {
      
      "must": [
          {"range": {
            "@timestamp": {
              "gte": "now-10m/m",
              "lt": "now/m"
            }
          }}
      ],    
      
      
      "must_not": [
        
          
          {"term" : {"dstzone.keyword" : "WAN" }},
          {"term" : {"dst_ip.keyword" : "SOME_IP" }},
          {"term" : {"dst_ip.keyword" : "SOME_IP" }},
          {"term" : {"dst_ip.keyword" : "SOME_IP" }}
          {"wildcard" : {"dst_ip.keyword" : "*.255" }}

      ],
      
      "should": [
        
          {"wildcard" : {"dst_ip.keyword" : "10.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.16.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.17.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.18.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.19.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.20.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.21.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.22.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.23.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.24.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.25.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.26.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.27.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.28.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.29.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.30.*" }},
          {"wildcard" : {"dst_ip.keyword" : "172.31.*" }},
          {"wildcard" : {"dst_ip.keyword" : "192.168.*" }}
        
        ]
    }
  },

```

This code is supposed to return all documents where "dst\_ip" is a private IP but the problem is when i execute this code i get many documents where "dst\_ip" is public.  
Do you have any idea how to fix this ?  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 11, 2021, 12:45pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063/2 "2021-08-11T12:45:44Z")

</div>

Can you show a sample document that is returned that you expect not to be?

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [August 11, 2021, 12:52pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063/3 "2021-08-11T12:52:21Z")

</div>

See [this](https://discuss.elastic.co/t/query-string-not-match-with-should-condions/281038/2)?

---

<div class="post-metadata">

**Author:** ![tarekilani](https://avatars.discourse-cdn.com/v4/letter/t/54ee81/32.png) [@tarekilani](https://discuss.elastic.co/u/tarekilani)\
**Post date:** [August 11, 2021, 1:14pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063/5 "2021-08-11T13:14:51Z")

</div>

I have in my query : bool ==\> must + must\_not + should  
If i will put a bool before the should it will raise a syntax error because it will be a bool in a bool

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [August 11, 2021, 1:16pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063/6 "2021-08-11T13:16:55Z")

</div>

> it will raise a syntax error because it will be a bool in a bool

Bools in bools are fine - you just need the child bool to be put in the right context of the container e.g. as a must or must\_not etc

---

<div class="post-metadata">

**Author:** ![tarekilani](https://avatars.discourse-cdn.com/v4/letter/t/54ee81/32.png) [@tarekilani](https://discuss.elastic.co/u/tarekilani)\
**Post date:** [August 11, 2021, 1:38pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063/7 "2021-08-11T13:38:51Z")

</div>

The problem remains even when i did that i still get unwanted results

---

<div class="post-metadata">

**Author:** ![tarekilani](https://avatars.discourse-cdn.com/v4/letter/t/54ee81/32.png) [@tarekilani](https://discuss.elastic.co/u/tarekilani)\
**Post date:** [August 11, 2021, 1:39pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063/8 "2021-08-11T13:39:35Z")

</div>

```auto
"buckets" : [
        {
          "key" : "192.168.1.3",
          "doc_count" : 461,
          "IP_destination" : {
            "doc_count_error_upper_bound" : 0,
            "sum_other_doc_count" : 0,
            "buckets" : [
              {
                "key" : "192.168.1.20",
                "doc_count" : 278
              },
              {
                "key" : "PUBLIC IP",
                "doc_count" : 45
              },
              {
                "key" : "PUBLIC IP",
                "doc_count" : 37
              },`Preformatted text`

```

---

<div class="post-metadata">

**Author:** ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)\
**Post date:** [August 11, 2021, 1:46pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063/9 "2021-08-11T13:46:16Z")

</div>

I don't know in what way they are "unwanted" but bear in mind that fields can have multiple values.  
The query might match just one of the values but any aggregations on that same field will consider _all_ of the values in those matching docs - not just those that matched the query.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2021, 1:47pm UTC](https://discuss.elastic.co/t/should-is-not-working-in-dsl/281063/10 "2021-09-08T13:47:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
