# Simple query, unexpected result

**URL:** <https://discuss.elastic.co/t/simple-query-unexpected-result/11028>\
**Category:** Elasticsearch\
**Created:** [March 6, 2013, 3:00am UTC](https://discuss.elastic.co/t/simple-query-unexpected-result/11028 "2013-03-06T03:00:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Binh\_Ly](https://avatars.discourse-cdn.com/v4/letter/b/ce7236/32.png) [@Binh\_Ly](https://discuss.elastic.co/u/Binh_Ly)\
**Post date:** [March 6, 2013, 3:00am UTC](https://discuss.elastic.co/t/simple-query-unexpected-result/11028/1 "2013-03-06T03:00:38Z")

</div>

Hey all,

I'm using ES 0.20.5 and noticed this behavior.

1. Create simple index:

POST [http://localhost:9200/foo/foo/1](http://localhost:9200/foo/foo/1)  
{  
"name": "John Doe"  
}

1. Create simple query:

POST [http://localhost:9200/\_search](http://localhost:9200/_search)  
{  
"query": {  
"query\_string": {  
"query": "NOT(name:Jane)"  
}  
}  
}

And I get back the above document. Good.

1. Then I modify above query slightly:

POST [http://localhost:9200/\_search](http://localhost:9200/_search)  
{  
"query": {  
"query\_string": {  
"query": "NOT(name:Jane) OR name:zzz"  
}  
}  
}

And I get no results. Is there something about ES/Lucene that I am just not  
understanding?

This one works though and returns the document correctly.

{  
"query": {  
"bool": {  
"should": [  
{  
"query\_string": {  
"query": "NOT(name:Jane)"  
}  
},  
{  
"query\_string": {  
"query": "name:zzz"  
}  
}  
]  
}  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![ppearcy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppearcy/32/980_2.png) [@ppearcy](https://discuss.elastic.co/u/ppearcy)\
**Post date:** [March 6, 2013, 6:15am UTC](https://discuss.elastic.co/t/simple-query-unexpected-result/11028/2 "2013-03-06T06:15:14Z")

</div>

This should work:  
(NOT(name:Jane)) OR name:zzz

Here's an older discussion on it:  
[http://elasticsearch-users.115913.n3.nabble.com/ES-s-handling-of-negative-queries-td1122757.html](http://elasticsearch-users.115913.n3.nabble.com/ES-s-handling-of-negative-queries-td1122757.html)

> <https://github.com/elastic/elasticsearch/issues/320>
>
> Here are the details:
> May want to consider adding logic in the case of non-neste…d negatives
> in OR clauses.
> 
> For example
> indexid:"test" OR -indexid:"test"
> \-\>
> indexid:"test" OR (-indexid:"test" AND \_:\_)
> 
> Right now, with ES when doing query generation from a syntax tree with
> this, I am adding grouping around negative OR clauses to accommodate.
> 
> So:
> indexid:"test" OR -indexid:"test"
> \-\>
> indexid:"test" OR (-indexid:"test")
> 
> Which I believe ES then interprets as:
> indexid:"test" OR (-indexid:"test" AND \_:\_) 
> 
> A few more details are here:
> http://groups.google.com/a/elasticsearch.com/group/users/browse\_thread/thread/9e80a32a3e8827f1/5e48ef4c9f596b16#5e48ef4c9f596b16
> 
> I would consider this a low priority request. 
> 
> Thanks!

Best Regards,  
Paul

On Tuesday, March 5, 2013 8:00:38 PM UTC-7, Ben wrote:

> Hey all,
> 
> I'm using ES 0.20.5 and noticed this behavior.
> 
> 1. Create simple index:
> 
> POST [http://localhost:9200/foo/foo/1](http://localhost:9200/foo/foo/1)  
> {  
> "name": "John Doe"  
> }
> 
> 1. Create simple query:
> 
> POST [http://localhost:9200/\_search](http://localhost:9200/_search)  
> {  
> "query": {  
> "query\_string": {  
> "query": "NOT(name:Jane)"  
> }  
> }  
> }
> 
> And I get back the above document. Good.
> 
> 1. Then I modify above query slightly:
> 
> POST [http://localhost:9200/\_search](http://localhost:9200/_search)  
> {  
> "query": {  
> "query\_string": {  
> "query": "NOT(name:Jane) OR name:zzz"  
> }  
> }  
> }
> 
> And I get no results. Is there something about ES/Lucene that I am just  
> not understanding?
> 
> This one works though and returns the document correctly.
> 
> {  
> "query": {  
> "bool": {  
> "should": [  
> {  
> "query\_string": {  
> "query": "NOT(name:Jane)"  
> }  
> },  
> {  
> "query\_string": {  
> "query": "name:zzz"  
> }  
> }  
> ]  
> }  
> }  
> }

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Binh\_Ly](https://avatars.discourse-cdn.com/v4/letter/b/ce7236/32.png) [@Binh\_Ly](https://discuss.elastic.co/u/Binh_Ly)\
**Post date:** [March 6, 2013, 1:02pm UTC](https://discuss.elastic.co/t/simple-query-unexpected-result/11028/3 "2013-03-06T13:02:49Z")

</div>

Paul, thank you very much! Good to know there is a workaround!

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)\
**Post date:** [March 6, 2013, 6:42pm UTC](https://discuss.elastic.co/t/simple-query-unexpected-result/11028/4 "2013-03-06T18:42:07Z")

</div>

You may want to have a read of this, which explains why + and - should be  
preferred over AND/OR/NOT:

[http://searchhub.org/2011/12/28/why-not-and-or-and-not/](http://searchhub.org/2011/12/28/why-not-and-or-and-not/)

clint

On Wed, Mar 6, 2013 at 2:02 PM, Ben [binh@hibalo.com](mailto:binh@hibalo.com) wrote:

> Paul, thank you very much! Good to know there is a workaround!
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:47am UTC](https://discuss.elastic.co/t/simple-query-unexpected-result/11028/5 "2017-07-06T02:47:59Z")

</div>


