# Simple\_query\_string is not matching correctly

**URL:** <https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656>\
**Category:** Elasticsearch\
**Tags:** kql-kibana-query-language, eql-elastic-query-language\
**Created:** [April 10, 2023, 11:58am UTC](https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656 "2023-04-10T11:58:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jilson](https://avatars.discourse-cdn.com/v4/letter/j/5daacb/32.png) [@jilson](https://discuss.elastic.co/u/jilson)\
**Post date:** [April 10, 2023, 11:58am UTC](https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656/1 "2023-04-10T11:58:26Z")

</div>

I am trying the below query using simple\_query\_string to match customer\_id

```auto
GET order-info/_search
{
  "query": {
    "simple_query_string": {
      "query": "1c0298d6-a911-5044-a904-6e848fb05eef",
      "fields": ["customer_id"]
    }
  },
    "sort": [
    {
        "created_date": "desc"
    }
  ],
  "from": 0,
  "size": 200,
  "_source": ["order_no", "customer_id"]
}

```

But this query is also matching this below which has a different customer\_id

```
 {
    "_index" : "order-info",
    "_type" : "_doc",
    "_id" : "MAK1001803",
    "_score" : null,
    "_source" : {
      "order_no" : "MAK1001803",
      "customer_id" : "1c0298d6-a911-5044-a904-6e848fb18vit"
    },
    "sort" : [
      1680574801710
    ]
  },

```

If I use query string this issue is not happening. Can anyone help on why simpe\_query\_string is incorrectly matching this?

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [April 10, 2023, 12:19pm UTC](https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656/2 "2023-04-10T12:19:56Z")

</div>

Hi @jilson

Are you using "default\_operator": "AND" in query string?

I believe you are not declaring an analyzer in the customer\_id field, so elasticsearch by default will apply the "standard" analyzer. This analyzer will generate several tokens for your customer Id ex: [**1c0298d6** , a911, 5044-a904, 6e848fb05eef], note that the token 1c0298d6 exists in doc **1c0298d6** -a911-5044-a904-6e848fb18vit so this document will always be retrieved.

I would use the Term Query for this type of search (the customer id will have to be of the **Keyword** type) or if you want to keep the query string you will have to use the "default\_operator": "AND" because that way you guarantee that all tokens are matched.

---

<div class="post-metadata">

**Author:** ![jilson](https://avatars.discourse-cdn.com/v4/letter/j/5daacb/32.png) [@jilson](https://discuss.elastic.co/u/jilson)\
**Post date:** [April 10, 2023, 1:39pm UTC](https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656/3 "2023-04-10T13:39:03Z")

</div>

Hi @RabBit_BR

yes I am not declaring an analyzer in customer\_id field, I am dumping the whole json into the index for now. I was going for the term query but it was giving no result, I believe due to customer\_id currently being a text field.  
I thought "AND" would be used as default in simple\_query\_string if no operator is provided.  
Thanks for your response!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2023, 1:40pm UTC](https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656/4 "2023-05-08T13:40:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
