# Unexpected results when filtering docs in nested field

**URL:** <https://discuss.elastic.co/t/unexpected-results-when-filtering-docs-in-nested-field/304960>\
**Category:** Elasticsearch\
**Created:** [May 17, 2022, 3:32pm UTC](https://discuss.elastic.co/t/unexpected-results-when-filtering-docs-in-nested-field/304960 "2022-05-17T15:32:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![OmarDacca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/omardacca/32/68171_2.png) [@OmarDacca](https://discuss.elastic.co/u/OmarDacca)\
**Post date:** [May 17, 2022, 3:32pm UTC](https://discuss.elastic.co/t/unexpected-results-when-filtering-docs-in-nested-field/304960/1 "2022-05-17T15:32:30Z")

</div>

Hi,

suppose we have the following docs: (index name is test\_index)

```auto
{
    session_id: "123",
    "session_details":[
        {
            "page": "/abc"
        },
        {
            "page": "/xyz"
        }
    ]
}

{
    session_id: "456",
    "session_details":[
        {
            "page": "/abc"
        },
        {
            "page": "/qwe"
        }
    ]
}

```

mappings is like this:

```auto
{
    "session_id" : {
        "type" : "keyword"
    },
    "session_details" : {
        "type" : "nested",
        "properties" : {
          "page" : {
            "type" : "keyword"
          }
        }
    }
}

```

if I run the following query I expect to receive the doc with the session\_id = 123  
but I receive both docs, any explanation ?

```auto
GET test_index/_search?ignore_unavailable=true
{
  "track_total_hits": true,
  "size": 10,
  "query": {
    "bool": {
      "filter": [
        {
          "nested": {
            "path": "session_details",
            "query": {
              "bool": {
                "filter": [
                  {
                    "wildcard": {
                      "session_details.page": "*/abc*"
                    }
                  },
                  {
                    "bool": {
                      "must_not": [
                        {
                          "wildcard": {
                            "session_details.page": "*/xyz*"
                          }
                        }
                      ]
                    }
                  }
                ]
              }
            }
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [May 17, 2022, 4:34pm UTC](https://discuss.elastic.co/t/unexpected-results-when-filtering-docs-in-nested-field/304960/2 "2022-05-17T16:34:00Z")

</div>

Hi!!

This post is a little similar:

> [@Elasticsearch must\_not on all elements in array](https://discuss.elastic.co/t/elasticsearch-must-not-on-all-elements-in-array/138390/5):
>
> Hi, thanks! Abdon this would be ok, but I would need to reindex all the items (which are in millions of large items and takes days). Tamara yours looks easier but how to scripted filters affect performance? If it's a big performance hit it might still be better to reindex my items.

Perhaps the solution is to use a script.

---

<div class="post-metadata">

**Author:** ![OmarDacca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/omardacca/32/68171_2.png) [@OmarDacca](https://discuss.elastic.co/u/OmarDacca)\
**Post date:** [May 17, 2022, 5:06pm UTC](https://discuss.elastic.co/t/unexpected-results-when-filtering-docs-in-nested-field/304960/3 "2022-05-17T17:06:28Z")

</div>

That post was 4 years ago, so many Elastic versions came out during this time.  
painless scripts are not recommended in terms of performance.

I understand that each document in nested field is considered and indexed as separate document. The question is, given the above mappings, is it possible to query a nested field as a regular array or something like that ?

One solution is to change the field type from nested to a regular object like this:

```auto
PUT test_prop
{
  "mappings": {
    "properties": {
      "session_id": {
        "type": "keyword"
      },
      "session_details": {
        "properties": {
          "page": {
            "type": "keyword"
          }
        }
      }
    }
  }
}

```

But this will result in a huge data duplication, also suppose we have another field session\_details: page, path:

```auto
session_details: [
     { page: "xyz", path: "qqq" },
     { page: "jkl", path: "aaa" }
]

```

a query like: page = "xyz" and path != "aaa" will still return the doc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2022, 5:07pm UTC](https://discuss.elastic.co/t/unexpected-results-when-filtering-docs-in-nested-field/304960/4 "2022-06-14T17:07:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
