# TermFilter and TermQuery is not Working with not analysed field

**URL:** <https://discuss.elastic.co/t/termfilter-and-termquery-is-not-working-with-not-analysed-field/53696>\
**Category:** Elasticsearch\
**Created:** [June 22, 2016, 5:53pm UTC](https://discuss.elastic.co/t/termfilter-and-termquery-is-not-working-with-not-analysed-field/53696 "2016-06-22T17:53:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![moni15moni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moni15moni/32/42311_2.png) [@moni15moni](https://discuss.elastic.co/u/moni15moni)\
**Post date:** [June 22, 2016, 5:53pm UTC](https://discuss.elastic.co/t/termfilter-and-termquery-is-not-working-with-not-analysed-field/53696/1 "2016-06-22T17:53:47Z")

</div>

Hi

I am using elasticsearch1.7.2 version,  
The signature field which i am storing is not\_analyzed while index creation is as follows  
Column name is : signature  
"signature" : { "type" : "string","index" : "not\_analyzed","fielddata": {"format": "doc\_values"}}  
In the column the value is stored seems  
String signature="PROTOCOL-DNS TMG Firewall Client long host entry exploit attempt "

I am trying to fetch the signature value using the following options as follows

query.must(QueryBuilders.termQuery("signature",signature));  
andFilterBuilder.add(FilterBuilders.termFilter("signature",QueryParser.escape(signature)));  
andFilterBuilder.add(FilterBuilders.termFilter("signature",signature));  
It wont give the results using above,

The only way i am geeting the results with the following approach,  
query.must(QueryBuilders.wildcardQuery("signature","_"+signature+"_"));

Is i did anything wrong with the above query formation.Please suggest.

Thanks  
Moni

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [June 22, 2016, 6:10pm UTC](https://discuss.elastic.co/t/termfilter-and-termquery-is-not-working-with-not-analysed-field/53696/2 "2016-06-22T18:10:30Z")

</div>

`term` queries should work fine for analyzed fields. If wildcards work with surrounding `+`s maybe you have leading or trailing stuff in the signature? Like a trailing white space or something.

---

<div class="post-metadata">

**Author:** ![moni15moni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moni15moni/32/42311_2.png) [@moni15moni](https://discuss.elastic.co/u/moni15moni)\
**Post date:** [June 23, 2016, 1:43am UTC](https://discuss.elastic.co/t/termfilter-and-termquery-is-not-working-with-not-analysed-field/53696/3 "2016-06-23T01:43:11Z")

</div>

Hi Nik,

Thanks!

You are right ,Some strings have a trailing spaces which cause the result.

Is there any possible to check against whitespaces in the queries.  
For not analysed fields which queries are the opt ?

Thanks Again

Moni

---

<div class="post-metadata">

**Author:** ![moni15moni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moni15moni/32/42311_2.png) [@moni15moni](https://discuss.elastic.co/u/moni15moni)\
**Post date:** [June 23, 2016, 10:37am UTC](https://discuss.elastic.co/t/termfilter-and-termquery-is-not-working-with-not-analysed-field/53696/4 "2016-06-23T10:37:02Z")

</div>

Found like a another one, I am storing the value is like "PROTOCOL-DNS TMG Firewall Client long host entry exploit attempt" in analysed filed.

When i am queried to the particular field in term query with the exact value , I am not getting the results.

But if i am passed the values by lowercase it's returns the result,  
i have to pass lowercase always or any other alternatives.

Thanks  
Moni

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:41pm UTC](https://discuss.elastic.co/t/termfilter-and-termquery-is-not-working-with-not-analysed-field/53696/5 "2017-07-05T22:41:10Z")

</div>


