# Unable to query for exact term

**URL:** <https://discuss.elastic.co/t/unable-to-query-for-exact-term/318215>\
**Category:** Elasticsearch\
**Created:** [November 4, 2022, 8:05pm UTC](https://discuss.elastic.co/t/unable-to-query-for-exact-term/318215 "2022-11-04T20:05:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 4, 2022, 8:05pm UTC](https://discuss.elastic.co/t/unable-to-query-for-exact-term/318215/1 "2022-11-04T20:05:27Z")

</div>

I'm still new to working with elasticsearch queries. I find that my query is returning too many results despite my attempts to request specific results. For example, if I run this query:

```auto
GET /test-index/_search
{
"query": {
        "bool": {
          "must": [
           {
             "match": {
               "rule_id": "bfa2dff0-59f7-11ed-8dbb-df926a4ffacd"
             }
           }
        ]
      }
  }
}

```

Then I get these results:

```auto
{
  "took": 0,
  "timed_out": false,
  "_shards": {
    "total": 1,
    "successful": 1,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 94,
      "relation": "eq"
    },
    "max_score": null,
    "hits": [
      {
        "_index": "test-index",
        "_id": "Dik7RIQBiMkQXuxZ_lQL",
        "_score": null,
        "_source": {
          "alert_id": "apm.error_rate_node-app-1_production",
          "rule_id": "5f52bbe0-5c75-11ed-ab47-2517decffbca",
          "reason": "Error count is 158 in the last 1 min for node-app-1. Alert when > 25.",
          "service_name": "node-app-1",
          "date": "2022-11-04T20:01:30.576Z"
        },
        "sort": [
          1667592090576
        ]
      },
      {
        "_index": "test-index",
        "_id": "aSk7RIQBiMkQXuxZTlBN",
        "_score": null,
        "_source": {
          "alert_id": "apm.transaction_error_rate_node-app-1_request_production",
          "rule_id": "bfa2dff0-59f7-11ed-8dbb-df926a4ffacd",
          "reason": "Failed transactions is 50% in the last 1 min for node-app-1. Alert when > 2.0%.",
          "service_name": "node-app-1",
          "date": "2022-11-04T20:00:43.384Z"
        },
        "sort": [
          1667592043384
        ]
      },
...etc...

```

Notice that one of the results has `rule_id === "5f52bbe0-5c75-11ed-ab47-2517decffbca"`...which is not a result I want to appear. I've been reading other people's questions, and I think maybe this has something to do with analyzers or strings being tokenized? And some people suggested something about mappings?

Here's my mapping:

```auto
{
  "mappings": {
    "properties": {
      "alert_id": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "date": {
        "type": "date"
      },
      "reason": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "rule_id": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "service_name": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      }
    }
  }
}

```

Can anyone point me in the right direction on how to query for results that have `rule_id === "bfa2dff0-59f7-11ed-8dbb-df926a4ffacd"`?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 4, 2022, 9:08pm UTC](https://discuss.elastic.co/t/unable-to-query-for-exact-term/318215/2 "2022-11-04T21:08:51Z")

</div>

Hi @learningelastic

Think you should read a blog about the difference between `keyword` and `text` such as this blog

> **[Elasticsearch: Text vs. Keyword](https://codecurated.com/blog/elasticsearch-text-vs-keyword/)**
>
> Many people that have just started learning Elasticsearch often confuse the Text and Keyword field data type. The difference between them is simple, but very crucial.

Then you should decide how you want to store and search those fields.

If you only _ **ever** _ want to search with exact match then store as `keyword` and do a `terms` search.

If you want to tokenize (break up the string both on store and search) and do partial matches then use `text` to store and `match` to search

If you want both... store with the default mapping and do

`term` search on `rule_id.keword`

or

`match` on `rule_id`

really important concepts to understand if you want to use.

> **[Field data types | Elasticsearch Guide \[8.5\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-types.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2022, 9:09pm UTC](https://discuss.elastic.co/t/unable-to-query-for-exact-term/318215/3 "2022-12-02T21:09:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
