# Subfield search question, please

**URL:** <https://discuss.elastic.co/t/subfield-search-question-please/11435>\
**Category:** Elasticsearch\
**Created:** [April 3, 2013, 7:18pm UTC](https://discuss.elastic.co/t/subfield-search-question-please/11435 "2013-04-03T19:18:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tiglath](https://avatars.discourse-cdn.com/v4/letter/t/df705f/32.png) [@Tiglath](https://discuss.elastic.co/u/Tiglath)\
**Post date:** [April 3, 2013, 7:18pm UTC](https://discuss.elastic.co/t/subfield-search-question-please/11435/1 "2013-04-03T19:18:09Z")

</div>

if I index some data like this:

{  
"ip" : "1.1.1.1",  
"reputation" : {  
"score : -3,  
"hacker" : {  
"name" : "BadBoris",  
"city" : "Kiev"  
}  
}

I can use a query string like 'city:Kiev' to get the record, but can I be  
more specific like 'hacker.city:Kiev',  
or even better 'reputation.hacker.city:Kiev'? The dot notation does not  
seem to work. Is there a way, ideally in Lucene syntax, but if not maybe  
DSL?

Many thanks. This forum is a great resource, I hope to provide answers  
some day instead of just questions.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 4, 2013, 7:12am UTC](https://discuss.elastic.co/t/subfield-search-question-please/11435/2 "2013-04-04T07:12:34Z")

</div>

Hey,

have you actually tried reputation.hacker.city:Kiev - it should work just  
fine in your case.  
curl 'localhost:9200/foo/\_search?q=reputation.hacker.city:Kiev'

Another way (using the much nicer query dsl syntax) is:  
curl 'localhost:9200/foo/\_search' -d '{ "query": { "match" : {  
"reputation.hacker.city" : "Kiev" } } }'

Definately take a look at the different type of queries before using the  
DSL.

--Alex

On Wed, Apr 3, 2013 at 9:18 PM, Tiglath [temp6@tiglath.net](mailto:temp6@tiglath.net) wrote:

> if I index some data like this:
> 
> {  
> "ip" : "1.1.1.1",  
> "reputation" : {  
> "score : -3,  
> "hacker" : {  
> "name" : "BadBoris",  
> "city" : "Kiev"  
> }  
> }
> 
> I can use a query string like 'city:Kiev' to get the record, but can I be  
> more specific like 'hacker.city:Kiev',  
> or even better 'reputation.hacker.city:Kiev'? The dot notation does not  
> seem to work. Is there a way, ideally in Lucene syntax, but if not maybe  
> DSL?
> 
> Many thanks. This forum is a great resource, I hope to provide answers  
> some day instead of just questions.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Tiglath](https://avatars.discourse-cdn.com/v4/letter/t/df705f/32.png) [@Tiglath](https://discuss.elastic.co/u/Tiglath)\
**Post date:** [April 8, 2013, 11:44pm UTC](https://discuss.elastic.co/t/subfield-search-question-please/11435/3 "2013-04-08T23:44:57Z")

</div>

Many thanks. You are right. I see now that the reason it did not  
work for me is because reputation was a list of hackers, and it only  
works if the hacker in the search is at the head of the list.

Then... sorry to try your patience....

Is there a way to search subfields using dot notation when one or more  
of the subfields is an array.

For example

"reputation" : [  
{  
"hacker" : {  
"name" : "Beefheart",  
"city" : "Riga",  
"exploits" : ["abc", "123"]  
}  
}  
{  
"hacker" {  
"name" : "BadIrina",  
"city" : "Kiev",  
"exploits" : ["mno", "123"]  
}  
}  
]

A search for 'reputation.hacker.exploits:123' does not work because  
reputation and exploits are arrays.

Thanks

On Apr 4, 3:12 am, Alexander Reelsen [a...@spinscale.de](mailto:a...@spinscale.de) wrote:

> Hey,
> 
> have you actually tried reputation.hacker.city:Kiev - it should work just  
> fine in your case.  
> curl 'localhost:9200/foo/\_search?q=reputation.hacker.city:Kiev'
> 
> Another way (using the much nicer query dsl syntax) is:  
> curl 'localhost:9200/foo/\_search' -d '{ "query": { "match" : {  
> "reputation.hacker.city" : "Kiev" } } }'
> 
> Definately take a look at the different type of queries before using the  
> DSL.
> 
> --Alex
> 
> On Wed, Apr 3, 2013 at 9:18 PM, Tiglath [te...@tiglath.net](mailto:te...@tiglath.net) wrote:
> 
> > if I index some data like this:
> 
> > {  
> > "ip" : "1.1.1.1",  
> > "reputation" : {  
> > "score : -3,  
> > "hacker" : {  
> > "name" : "BadBoris",  
> > "city" : "Kiev"  
> > }  
> > }
> 
> > I can use a query string like 'city:Kiev' to get the record, but can I be  
> > more specific like 'hacker.city:Kiev',  
> > or even better 'reputation.hacker.city:Kiev'? The dot notation does not  
> > seem to work. Is there a way, ideally in Lucene syntax, but if not maybe  
> > DSL?
> 
> > Many thanks. This forum is a great resource, I hope to provide answers  
> > some day instead of just questions.
> 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visithttps://groups.google.com/groups/opt\_out.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 9, 2013, 6:57am UTC](https://discuss.elastic.co/t/subfield-search-question-please/11435/4 "2013-04-09T06:57:03Z")

</div>

Hey,

not sure where your problem is, the search works for me

curl -X PUT localhost:9200/foo/bar/1 -d '{  
"reputation" : [  
{  
"hacker" : {  
"name" : "Beefheart",  
"city" : "Riga",  
"exploits" : ["abc", "123"]  
}  
},  
{  
"hacker" : {  
"name" : "BadIrina",  
"city" : "Kiev",  
"exploits" : ["mno", "123"]  
}  
}  
]  
}  
'

curl 'localhost:9200/foo/\_search?q=reputation.hacker.exploits:123'

Searching either for mno, abc or 123 returns the document as expected.  
Maybe you fiddled around with your mapping while trying out stuff. It might  
make sense to delete the whole index and reindex all your data in order to  
be sure. More about mapping:

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Also it might make sense, if you read about nested documents. If you index  
data above, you can search for reputation.hacker.city=Riga and  
reputation.hacker.name=BadIrina and you would get back this document.  
Nested documents behave correct in this case. Check it out at

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Also note, that your have to use the query DSL really and cannot use the  
simple search (using the lucene query syntax) as above when you use nested  
documents.

On Tue, Apr 9, 2013 at 1:44 AM, Tiglath [temp6@tiglath.net](mailto:temp6@tiglath.net) wrote:

> Many thanks. You are right. I see now that the reason it did not  
> work for me is because reputation was a list of hackers, and it only  
> works if the hacker in the search is at the head of the list.
> 
> Then... sorry to try your patience....
> 
> Is there a way to search subfields using dot notation when one or more  
> of the subfields is an array.
> 
> For example
> 
> "reputation" : [  
> {  
> "hacker" : {  
> "name" : "Beefheart",  
> "city" : "Riga",  
> "exploits" : ["abc", "123"]  
> }  
> }  
> {  
> "hacker" {  
> "name" : "BadIrina",  
> "city" : "Kiev",  
> "exploits" : ["mno", "123"]  
> }  
> }  
> ]
> 
> A search for 'reputation.hacker.exploits:123' does not work because  
> reputation and exploits are arrays.
> 
> Thanks
> 
> On Apr 4, 3:12 am, Alexander Reelsen [a...@spinscale.de](mailto:a...@spinscale.de) wrote:
> 
> > Hey,
> > 
> > have you actually tried reputation.hacker.city:Kiev - it should work just  
> > fine in your case.  
> > curl 'localhost:9200/foo/\_search?q=reputation.hacker.city:Kiev'
> > 
> > Another way (using the much nicer query dsl syntax) is:  
> > curl 'localhost:9200/foo/\_search' -d '{ "query": { "match" : {  
> > "reputation.hacker.city" : "Kiev" } } }'
> > 
> > Definately take a look at the different type of queries before using the  
> > DSL.
> > 
> > --Alex
> > 
> > On Wed, Apr 3, 2013 at 9:18 PM, Tiglath [te...@tiglath.net](mailto:te...@tiglath.net) wrote:
> > 
> > > if I index some data like this:
> > 
> > > {  
> > > "ip" : "1.1.1.1",  
> > > "reputation" : {  
> > > "score : -3,  
> > > "hacker" : {  
> > > "name" : "BadBoris",  
> > > "city" : "Kiev"  
> > > }  
> > > }
> > 
> > > I can use a query string like 'city:Kiev' to get the record, but can I  
> > > be  
> > > more specific like 'hacker.city:Kiev',  
> > > or even better 'reputation.hacker.city:Kiev'? The dot notation does  
> > > not  
> > > seem to work. Is there a way, ideally in Lucene syntax, but if not  
> > > maybe  
> > > DSL?
> > 
> > > Many thanks. This forum is a great resource, I hope to provide answers  
> > > some day instead of just questions.
> > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups  
> > > "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an  
> > > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > For more options, visithttps://groups.google.com/groups/opt\_out.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:42am UTC](https://discuss.elastic.co/t/subfield-search-question-please/11435/5 "2017-07-06T02:42:08Z")

</div>


