# Testing Match query to fail, but returns docs, although they do not match

**URL:** <https://discuss.elastic.co/t/testing-match-query-to-fail-but-returns-docs-although-they-do-not-match/278780>\
**Category:** Elasticsearch\
**Created:** [July 15, 2021, 11:56am UTC](https://discuss.elastic.co/t/testing-match-query-to-fail-but-returns-docs-although-they-do-not-match/278780 "2021-07-15T11:56:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tesh](https://avatars.discourse-cdn.com/v4/letter/t/4bbf92/32.png) [@tesh](https://discuss.elastic.co/u/tesh)\
**Post date:** [July 15, 2021, 11:56am UTC](https://discuss.elastic.co/t/testing-match-query-to-fail-but-returns-docs-although-they-do-not-match/278780/1 "2021-07-15T11:56:18Z")

</div>

Hi Team, first post here and hope you guys can help me stop going round and round! 😉

It's java code using elastic libs/methods

I'm trying to look for a string in a field - eg, ":21:test123blah" and expecting it to fail and hit my error messages, but instead I get some docs back, although none of them have my search string.

If, however, I search for just "test123blah" then it correctly returns the error message I've created indicating no matched records.

The JAVA code I have is:

```auto
matchquerybuilder test = querybuilders
                                              .matchQuery ("fieldarea", ":21:"+testref)
BoolQueryBuilder matchQ = QueryBuilders.boolQuery();
matchQ.must(test);

```

I then send it to matchQ to a searchsourcebuilder.query and set that as the searchrequest.source - all of which is oretty standard I think... The query is with why I can't seem to use the ":21:" as part of the query correctly.

PS, also tried to double escape (//) the ":" chars, still to no avail

Thanks a bill for even looking at this!

Ta,  
T

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 15, 2021, 12:16pm UTC](https://discuss.elastic.co/t/testing-match-query-to-fail-but-returns-docs-although-they-do-not-match/278780/2 "2021-07-15T12:16:15Z")

</div>

In order to understand what happens here, you need to understand how a string like `:21:test..` is depicted into single tokens and how it is stored in the inverted index. This is massively different like a SQL database.

A good place to start is the [Analyze API](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/indices-analyze.html). The Getting Started chapter of the definitive guide to Elasticsearch can also help a lot: [Getting Started | Elasticsearch: The Definitive Guide [2.x] | Elastic](https://www.elastic.co/guide/en/elasticsearch/guide/current/getting-started.html)

---

<div class="post-metadata">

**Author:** ![tesh](https://avatars.discourse-cdn.com/v4/letter/t/4bbf92/32.png) [@tesh](https://discuss.elastic.co/u/tesh)\
**Post date:** [July 15, 2021, 1:16pm UTC](https://discuss.elastic.co/t/testing-match-query-to-fail-but-returns-docs-although-they-do-not-match/278780/3 "2021-07-15T13:16:44Z")

</div>

Thanks Spinscale,

I'll start wading through but you got any pointers as time is against me - ie, I assume it's down to the ":" characters as they are a special character for searching, right? Or is it in effect, returning any hits that has ":", "21" and ":" in the "message" field aswell as the "testref" value?

Ta,  
T

---

<div class="post-metadata">

**Author:** ![tesh](https://avatars.discourse-cdn.com/v4/letter/t/4bbf92/32.png) [@tesh](https://discuss.elastic.co/u/tesh)\
**Post date:** [July 15, 2021, 7:36pm UTC](https://discuss.elastic.co/t/testing-match-query-to-fail-but-returns-docs-although-they-do-not-match/278780/4 "2021-07-15T19:36:30Z")

</div>

Ok, sussed it out myself using another query builder

```auto
MatchPhraseQueryBuilder test = QueryBuilders
.matchPhraseQuery ("fieldarea",":21:"+testref);

```

This seems like it does the trick if you put in a valid "testref" which returns you docs and and a garbage "testref" returning nought.

Ta,  
T

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2021, 7:36pm UTC](https://discuss.elastic.co/t/testing-match-query-to-fail-but-returns-docs-although-they-do-not-match/278780/5 "2021-08-12T19:36:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
