# Simple Query on Discover Tab not Working

**URL:** <https://discuss.elastic.co/t/simple-query-on-discover-tab-not-working/68787>\
**Category:** Kibana\
**Created:** [December 12, 2016, 10:39pm UTC](https://discuss.elastic.co/t/simple-query-on-discover-tab-not-working/68787 "2016-12-12T22:39:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![megamax](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@megamax](https://discuss.elastic.co/u/megamax)\
**Post date:** [December 12, 2016, 10:39pm UTC](https://discuss.elastic.co/t/simple-query-on-discover-tab-not-working/68787/1 "2016-12-12T22:39:42Z")

</div>

Newbie question here. I am sure I am missing something but I’m at a loss to understand what. I am trying to filter data on the Discover tab. I have a field called “groupname” with the following definition:

"groupname":{"index":"not\_analyzed","type":"string"}

If I enter a simple query such as “groupname: SMS”, my records are filtered as expected, and SMS is highlighted in my view. But, if I enter the query “groupname: SMS OR STORAGE” or "groupname: SMS STORAGE", I get a mix of records, containing groupname values beyond SMS or STORAGE. Also, SMS is highlighted but STORAGE is not. Note that I am searching for the full value in the same case, and not a substring.

If I employ the same syntax on fields that are analyzed, everything works as expected.  
My understanding was that fields that aren’t analyzed are still searchable. What am I doing wrong?

Thanks in advance.

Mark

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [December 12, 2016, 10:46pm UTC](https://discuss.elastic.co/t/simple-query-on-discover-tab-not-working/68787/2 "2016-12-12T22:46:07Z")

</div>

What's likely happening on analyzed fields is it's parsing out your entire search string and matching on the words "SMS "OR" and "STORAGE" for each field. If the field's not analyzed it will try and match directly, so you'll want to search for these separately. `groupname:SMS OR groupname:STORAGE`.

---

<div class="post-metadata">

**Author:** ![megamax](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@megamax](https://discuss.elastic.co/u/megamax)\
**Post date:** [December 13, 2016, 1:47pm UTC](https://discuss.elastic.co/t/simple-query-on-discover-tab-not-working/68787/3 "2016-12-13T13:47:21Z")

</div>

That worked. Thank you for the explanation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2017, 1:47pm UTC](https://discuss.elastic.co/t/simple-query-on-discover-tab-not-working/68787/4 "2017-01-10T13:47:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
